The key idea
Poppy replaces "block the agent or let it log in as you" with a middle ground. The company publishes what agents may do, the person chooses what their agent may do for them, and both are enforced with standard OAuth.
People already hand everyday jobs to AI agents: return this jacket, move my flight, find out why my internet keeps dropping. Most of those jobs end at a company’s website. Until now the company had two options. It could block the agent, or it could let the agent sign in with the person’s password and do anything they can.
The Personal Agent Protocol, called Poppy for short (and sometimes PAP), is an open protocol that adds the steps in between. Draft 0.1 was published at personalagentprotocol.org in October 2026 under the Apache 2.0 licence.
The problem it solves
Agents that pass as the user are hard to tell apart from people, so companies spend effort detecting them and agents spend effort avoiding detection. Once an agent is signed in as you, nothing limits it.
Poppy lets each side choose a point on a scale instead:
| What the company allows | Example |
|---|---|
| Any agent, signed out | Search hotel rooms, read the returns policy |
| After the user signs in | See their reservations or orders |
| With the user’s approval | Book a room, buy a ticket |
| Not at all | Agents get nothing |
The person chooses too. When they sign in through their agent, they can let it view their account, make changes, or both.
The three parties
- The user: the person the agent acts for.
- The personal agent: software acting for that one user, such as an assistant app.
- The company: any business that implements the protocol. It might offer a website, APIs, an MCP server, its own agent, or any mix.
How it works in five steps
1. Discovery. The company publishes a JSON file at /.well-known/poppy.json. It names the company, points to its OAuth server, lists the ways users can sign in, and lists the interfaces agents can use: the website, OpenAPI or MCP APIs, and the company’s own agent. See How to write your poppy.json.
2. A session, before anyone signs in. The agent identifies itself with a URL that hosts its name, logo and public keys. It asks the company’s token endpoint for a short-lived Session Token for one user. The company sees which agent is asking, and an ID for the user that stays the same over time but is different at every company and contains no personal information.
3. Sign-in, only when the task needs the account. The user signs in on the company’s own page (standard OAuth), or with a link and code on any device, or, if the company allows it, the agent signs in with credentials the user gave it. The user approves some or all of the requested scopes: poppy:read to view the account, poppy:write to make changes, plus any the company defines. The agent gets a long-lived Account Token so it can start signed-in sessions later without asking again.
4. Doing the work. In the same session the agent can call the company’s APIs, browse its website (the agent’s browser joins the session and the company sets its own cookie), or talk to the company’s agent through a simple conversation API. Each message says whether a person or an AI wrote it, and either side can bring in a human.
5. Signing out. The agent revokes its Account Token, or the user disconnects it from their account settings. Sessions carry on signed out.
Tokens are bound to a key only the agent holds (DPoP), so a copied token is useless on its own.
What is new, and what is not
Most of Poppy is standards companies already run: OAuth 2.0 with PKCE and device flow, JWT bearer assertions, DPoP, token revocation, OpenAPI and MCP. The protocol adds:
- the
poppy.jsondiscovery file and thepoppy_domainsfield in OAuth metadata, which ties a domain to its OAuth server; - a
session_idthat ties signed-out and signed-in activity together across APIs, browsing and conversations; - the browser-session endpoint that lets an agent’s browser join a session;
- mediated sign-in, a small non-OAuth flow for agents that sign in with the user’s credentials;
- the conversation API between the personal agent and the company’s agent;
- an optional operations extension, where the company proposes an action with exact terms, the user approves that version, and it runs at most once.
What it does not cover yet
The draft lists payments, push notifications (for example when an order ships hours later) and attachments such as receipts and return labels as open topics. Every part may still change before a stable version.
What companies should do now
Start small. Publishing poppy.json with only your website makes you discoverable today. Then wire up your OAuth server so users can connect their agent, and add an MCP server or your company agent when you can. The compliance checklist lists every requirement in order, and the checker tells you which ones your domain already meets.
Free Poppy checker
See what your domain needs for the Personal Agent Protocol, one step at a time.
Check your domainWritten against Personal Agent Protocol (Poppy, PAP) draft 0.1, which may change. Flow is not affiliated with the protocol's authors.