Poppy · PAP · Personal Agent Protocol draft 0.1
Is your site ready for Poppy, the Personal Agent Protocol?
The Personal Agent Protocol, or Poppy, lets people's AI agents find your company, sign them in with the access they choose, and get things done through your APIs, website or own agent. Check your domain and see exactly what's missing.
Reads only public documents and sends no credentials. Nothing is stored.
What the checker looks at
Everything an agent sees before it signs in.
It reads your public documents and sends the requests any personal agent sends first, with no credentials. Each problem comes with what to change and why agents need it.
Discovery
- /.well-known/poppy.json is served over https, as JSON
- protocol_version, organization and a domain that matches yours
- At least one interface: web, apis or agent
- auth, sign-in types and scopes are well formed
- Extensions are named and versioned
OAuth server
- RFC 8414 metadata at your issuer, with the same issuer
- poppy_domains vouches for your domain
- Token and revocation endpoints, plus sign-in endpoints for the types you offer
- Agent keys, the JWT bearer grant, PKCE and DPoP are advertised
- The token endpoint answers like an OAuth server
Interfaces
- OpenAPI descriptions load and say how tokens are sent
- MCP servers require a token and point to your issuer
- The conversation endpoint refuses requests without a Session Token
- The browser-session endpoint refuses bad assertions and sets no cookie
Four levels
Get on Poppy one step at a time.
The protocol is built for progressive adoption: start with a discovery file and your website, then add sign-in, APIs and your own agent.
- 0
Not on Poppy yet
No poppy.json. Personal agents treat you as an ordinary website, or are blocked.
- 1
Discoverable
Agents can find you and browse signed out. Users cannot connect their account yet.
- 2
Sessions and sign-in wired
Your OAuth server vouches for your domain and answers agents. Fix the interfaces next.
- 3
Ready, from the outside
Everything a signed-out agent can see is right. Test sessions, DPoP and sign-in with a real agent before announcing.
Guides
How to get on the Personal Agent Protocol.
Plain-English guides to draft 0.1, written for the people who will build it.
Get on Poppy: the full Personal Agent Protocol guide
Every step from no poppy.json to agent-ready, with a plan for Auth0, Okta, Cognito, Firebase, Clerk, Keycloak or your own login.
Read the guide DiscoveryHow to write your poppy.json
Every field of the Poppy discovery file, three starter files and the mistakes agents reject.
Read the guide Sign-inSet up your OAuth server for Poppy
Metadata, poppy_domains, agent keys, the session grant and DPoP, and what to do if your provider lacks them.
Read the guide ChecklistThe Poppy (PAP) compliance checklist
Every requirement of the Personal Agent Protocol for companies, grouped by what you are building, in the order to do it.
Read the guideQuestions about Poppy.
What is the Personal Agent Protocol?
The Personal Agent Protocol, called Poppy for short, is an open protocol for how a personal AI agent acting for one person works with a company: how it finds the company, starts a session, signs the person in with the access they choose, and uses the company’s APIs, website or own agent. Draft 0.1 was published in October 2026 under the Apache 2.0 licence.
Is PAP the same as Poppy?
Yes. The protocol calls itself the Personal Agent Protocol, or Poppy for short. Some people shorten it to PAP.
What is the least a company needs to do?
Publish /.well-known/poppy.json. With only a web entry, agents know you are there and browse your site signed out. To let users sign in through their agent, you also need an OAuth server that lists your domain in poppy_domains, accepts agents’ signed requests and issues DPoP-bound session tokens.
What does this checker test?
Everything a personal agent can see before signing in: your poppy.json, your OAuth server’s metadata, whether your token endpoint answers like an OAuth server, and whether your conversation, MCP and browser-session endpoints refuse requests without a session token. It does not sign in, start sessions or send DPoP proofs.
Does the checker store anything or sign in to my site?
No. It reads public documents and sends requests with no credentials, the same ones any personal agent would send first. Results are not stored. Checks are rate limited per visitor and per domain.
Do I need an MCP server or an API to take part?
No. A company can start with only its website, only APIs, or only its own agent. Agents prefer APIs and company agents because they are faster than clicking through pages, so adding one later makes you easier to work with.
Is the protocol stable?
Not yet. It is draft 0.1, and its authors say any part may change before a stable version, including in ways that are not backward compatible. Build against it, but expect to update.
Is this an official tool?
No. Flow built it independently to help companies get ready. It is not affiliated with the protocol’s authors. The specification at personalagentprotocol.org is the source of truth.
Your company agent
Personal agents will want to talk to someone at your company.
Flow builds agents that answer your customers on chat and act through your own APIs. Talk to us about putting yours where personal agents can reach it.
An independent tool by Flow, not affiliated with the Personal Agent Protocol's authors. The specification is the source of truth; it is a draft and may change.