Draft 0.1 published · checked Oct 10, 2026

Poppy:
what's announced,
what's still missing.

Poppy (Personal Agent Protocol) is an open standard Sierra and Meta announced on October 6, 2026. It sets out how your AI agent signs in to a business and acts for you. You choose what access to grant. The business chooses the route. Draft 0.1 is public and still evolving.

poppy.md is an independent tracker, not affiliated with Sierra, Meta or the partners. We log every partner, date and claim with its source, and we'll annotate v0.1 the day it ships.

Announced
Oct 6
Oct 6 launch orgs
10
Auth
OAuth
One Personal Agent Protocol visit Four steps based on draft 0.1, published October 9, 2026. 1 Discover: the agent fetches /.well-known/poppy.json to find sign-in methods and routes. 2 Guest: no sign-in needed to check stock or ask about returns. 3 Sign in with OAuth, only if the task needs the account, on the company page or with credentials already set up with the agent. 4 The customer chooses read-only or write access. All four are one OAuth session that carries across channels. One Poppy visit Discovery, sign-in and one session across company interfaces. 1 Discover AGENT Starts on the company’s website and finds what’s offered and how to connect. 2 Guest AGENT No sign-in needed to check stock or ask about a returns policy. 3 Sign in CUSTOMER Only if the task needs the account. OAuth, on the company’s page or with credentials already set up with the agent. 4 Pick access CUSTOMER The customer decides how far the agent can go: Read-only Write One OAuth session, across channels A question asked before sign-in and an order change made after it count as the same visit. Source: Poppy draft 0.1, Oct 9, 2026. Diagram: poppy.md (independent).
R / W
Access

The customer picks access

Read-only or write. That’s the whole menu for now; finer limits are on the "later" list.

OAuth
Session

Sessions run on OAuth

Sign in on the company’s own page, or use credentials already set up with the agent. A guest visit is fine for stock checks.

3
Routes

The business picks the route

Its website, an API such as MCP or OpenAPI, or its own agent when the job needs a conversation.

Fact sheet

Poppy in ten lines

Everything here comes from Sierra's post or named coverage. If it isn't sourced, it isn't on the list. Checked Oct 10, 2026.

How we got here: the timeline
Name
Poppy (Personal Agent Protocol)
Announced
October 6, 2026, at Sierra Summit, San Francisco
Created by
Sierra (Bret Taylor, Clay Bavor) and Meta
What it covers
How a personal AI agent signs in to a business and what it may do there
Auth
OAuth sessions; guest or signed in
Access levels
Read-only or write, chosen by the customer
Routes
Company website, APIs (MCP, OpenAPI), or the company’s own agent
Spec
Draft 0.1 published October 9, 2026 · Apache 2.0
Not covered yet
Payments, push notifications, finer permissions
Not named as partners
Anthropic, Google, Amazon
Draft 0.1

How the Personal Agent Protocol works

You, your agent and the company share one visit. The draft now defines discovery, sign-in, sessions and the routes companies can offer.

01
WEB

Discover on the site

The agent finds what the company offers and how to reach it. A guest session can check stock or a returns policy.

GUEST
02
OAUTH

You choose access

If the task needs your account, you sign in. You decide read-only or write. The visit stays the same.

CONSENT
03
ROUTE

The company picks a route

Website pages, an API such as MCP or OpenAPI, or the company’s own agent.

DONE

Draft 0.1 defines the details

Draft 0.1 specifies discovery at /.well-known/poppy.json, OAuth sign-in, session tokens and the API and conversation routes. It can still change before a stable release.

See the architecture
October 6 launch lists

Two announcements, two partner lists

Sierra and Meta didn't publish the same names. Seven appear on both. Instinct is only on Sierra's list; NiCE and Decagon are only on Meta's.

CompanyRoleSierra postMeta post
SierraCo-creator
MetaCo-creator
GenesysLaunch partner
Rocket CompaniesLaunch partner
ShopifyLaunch partner
StripeLaunch partner
WalmartLaunch partner
InstinctLaunch partner
NiCEPartner
DecagonWorking group

Not named on the October 6 lists: Anthropic, Google, Amazon. Meta's list as reported by CMSWire.

Questions people keep asking

Is the Poppy specification published?+

Yes. Draft 0.1 was published on October 9, 2026 under Apache 2.0. It is subject to change before a stable release.

Are OpenAI, Anthropic, Google or Amazon part of Poppy?+

OpenAI joined as a design partner on October 9, 2026. Anthropic, Google and Amazon are not named in the partner announcements.

Does Poppy handle payments?+

Not in the announced first version. Payment extensions, letting an agent buy without sharing card details, are listed as a possible later step.

Does Poppy replace MCP?+

No. The announcement names MCP and OpenAPI as API routes a company can offer inside a Poppy session.

Draft 0.1 published · October 9, 2026

Building for agents before the spec lands?

Don't code against guessed endpoints. Start with what's actually been announced, and check the tracker. We'll publish an annotated read of v0.1 the day it goes live.