Poppy · PAP · Personal Agent Protocol draft 0.1

Is your site ready for Poppy, the Personal Agent Protocol?

The Personal Agent Protocol, or Poppy, lets people's AI agents find your company, sign them in with the access they choose, and get things done through your APIs, website or own agent. Check your domain and see exactly what's missing.

Reads only public documents and sends no credentials. Nothing is stored.

What the checker looks at

Everything an agent sees before it signs in.

It reads your public documents and sends the requests any personal agent sends first, with no credentials. Each problem comes with what to change and why agents need it.

Discovery

  • /.well-known/poppy.json is served over https, as JSON
  • protocol_version, organization and a domain that matches yours
  • At least one interface: web, apis or agent
  • auth, sign-in types and scopes are well formed
  • Extensions are named and versioned

OAuth server

  • RFC 8414 metadata at your issuer, with the same issuer
  • poppy_domains vouches for your domain
  • Token and revocation endpoints, plus sign-in endpoints for the types you offer
  • Agent keys, the JWT bearer grant, PKCE and DPoP are advertised
  • The token endpoint answers like an OAuth server

Interfaces

  • OpenAPI descriptions load and say how tokens are sent
  • MCP servers require a token and point to your issuer
  • The conversation endpoint refuses requests without a Session Token
  • The browser-session endpoint refuses bad assertions and sets no cookie

Four levels

Get on Poppy one step at a time.

The protocol is built for progressive adoption: start with a discovery file and your website, then add sign-in, APIs and your own agent.

  1. 0

    Not on Poppy yet

    No poppy.json. Personal agents treat you as an ordinary website, or are blocked.

  2. 1

    Discoverable

    Agents can find you and browse signed out. Users cannot connect their account yet.

  3. 2

    Sessions and sign-in wired

    Your OAuth server vouches for your domain and answers agents. Fix the interfaces next.

  4. 3

    Ready, from the outside

    Everything a signed-out agent can see is right. Test sessions, DPoP and sign-in with a real agent before announcing.

FAQ

Questions about Poppy.

What is the Personal Agent Protocol?

The Personal Agent Protocol, called Poppy for short, is an open protocol for how a personal AI agent acting for one person works with a company: how it finds the company, starts a session, signs the person in with the access they choose, and uses the company’s APIs, website or own agent. Draft 0.1 was published in October 2026 under the Apache 2.0 licence.

Is PAP the same as Poppy?

Yes. The protocol calls itself the Personal Agent Protocol, or Poppy for short. Some people shorten it to PAP.

What is the least a company needs to do?

Publish /.well-known/poppy.json. With only a web entry, agents know you are there and browse your site signed out. To let users sign in through their agent, you also need an OAuth server that lists your domain in poppy_domains, accepts agents’ signed requests and issues DPoP-bound session tokens.

What does this checker test?

Everything a personal agent can see before signing in: your poppy.json, your OAuth server’s metadata, whether your token endpoint answers like an OAuth server, and whether your conversation, MCP and browser-session endpoints refuse requests without a session token. It does not sign in, start sessions or send DPoP proofs.

Does the checker store anything or sign in to my site?

No. It reads public documents and sends requests with no credentials, the same ones any personal agent would send first. Results are not stored. Checks are rate limited per visitor and per domain.

Do I need an MCP server or an API to take part?

No. A company can start with only its website, only APIs, or only its own agent. Agents prefer APIs and company agents because they are faster than clicking through pages, so adding one later makes you easier to work with.

Is the protocol stable?

Not yet. It is draft 0.1, and its authors say any part may change before a stable version, including in ways that are not backward compatible. Build against it, but expect to update.

Is this an official tool?

No. Flow built it independently to help companies get ready. It is not affiliated with the protocol’s authors. The specification at personalagentprotocol.org is the source of truth.

Your company agent

Personal agents will want to talk to someone at your company.

Flow builds agents that answer your customers on chat and act through your own APIs. Talk to us about putting yours where personal agents can reach it.

An independent tool by Flow, not affiliated with the Personal Agent Protocol's authors. The specification is the source of truth; it is a draft and may change.