News · Poppy · Personal Agent Protocol draft 0.1

Poppy, the Personal Agent Protocol, is here. What companies should do this week

The Personal Agent Protocol, Poppy for short (PAP), gives AI agents a proper way to work with companies. What launched, why it matters, and the three things to do first.

The key idea

Customers' AI agents are already at your door. Poppy, the Personal Agent Protocol, lets you decide what they can do, instead of blocking them or letting them log in as the customer. Publishing one small file is a useful first step.

What launched

In October 2026 the Personal Agent Protocol, called Poppy for short and also written PAP, published its first draft (0.1) at personalagentprotocol.org, under the Apache 2.0 licence. It is an open protocol for one thing: how a person’s AI agent works with a company on that person’s behalf.

It covers the whole trip. The agent finds the company through a small file, /.well-known/poppy.json. It starts a session before anyone signs in. When a task needs the customer’s account, the customer signs in on the company’s own page and chooses what the agent may do: view, change, or both. Then the agent uses the company’s APIs, its website or its own support agent to get the job done. Our explainer walks through each piece.

Why it matters

People already ask agents to return a jacket, move a flight or chase a refund, and many of those jobs end at a company’s website. Today that goes one of two ways. The company blocks the agent, and the customer is stuck. Or the agent signs in with the customer’s password and can do anything they can, with nothing the company or the customer can limit.

Poppy adds the steps in between. A company can let any agent search its catalogue, let signed-in agents see orders, and ask for the customer’s approval before anything costs money. The customer can let their agent look but not touch. Every request says which agent sent it and for whom, so the company can tell an agent from a person and offer it a better path than clicking through pages.

It is built on standards most companies already run: OAuth, JWTs, DPoP, OpenAPI and MCP. Most of the work is putting them together the way the protocol describes.

Three things to do first

  1. See where you stand. Run your domain through the free Poppy checker. It reads what an agent would read and walks you through what is missing, one step at a time.
  2. Publish poppy.json. Even a file that only lists your website makes you discoverable: agents know you take part and can browse your site properly. How to write your poppy.json has starter files.
  3. Find out how your sign-in fits. Poppy’s sign-in runs on OAuth. If your customers sign in through Auth0, Okta, Cognito, Firebase, Clerk, Keycloak or your own code, the full guide has a plan for each. For most companies it is a small service in front of the login they already have.

What to watch

This is a draft, and its authors say any part may change before a stable version. Payments, push notifications and attachments such as receipts and return labels are listed as open topics. Start with discovery and sign-in, which are the least likely to move, and keep an eye on the specification. The compliance checklist lists every requirement as it stands today.

Free Poppy checker

See what your domain needs for the Personal Agent Protocol, one step at a time.

Check your domain

Written against Personal Agent Protocol (Poppy, PAP) draft 0.1, which may change. Flow is not affiliated with the protocol's authors.