An open protocol for every company and every personal agent.
Personal agents can discover participating companies, sign users in, and get things done through APIs, web pages, and company agents. Companies decide how to empower agents and what they can do.
Creating choice and control
People already hand everyday tasks to personal agents, and many of those tasks end at a company. Today it is all or nothing: the company blocks the agent, or the agent signs in as the person and can do anything they can. As agents do more, both sides waste more effort on this, with companies trying to detect agents and agents trying to avoid detection. That doesn't serve anyone, and we don't think it can last.
We think everyone is better off with more choices between those two extremes. So we built Personal Agent Protocol, or “Poppy” for short: a shared way for companies to decide what agents can do, and for people to decide what their agent can do for them.
- BlockedNo agents allowed.
Search roomsAny agent
See reservationsAfter the user signs in
Book a roomWith the user's approval- Full accessThe agent acts as the user.
Built for everyone
Any company can take part, whether it offers a website, APIs, an MCP server, or its own agent. Users bring the personal agent of their choice.
Users
More done with their own agent
- Get more done with their personal agent at every company that supports the protocol.
- Sign in directly and control permissions: users sign in on the company's own page and choose whether their personal agent can view their account, make changes, or both.
- Get things done faster when their personal agent can work with the company directly instead of clicking through its website.
Personal agents
Faster, simpler access
- More efficient access through the company's APIs or a conversation with its agent, instead of navigating web pages.
- One standard protocol across every participating company, so each new company works the same way.
- Sign-in support even when the user can't share their credentials with the agent: they sign in on the company's own page.
Companies
Insight and control
- Start with what they have: publish a website, APIs, or agent, and add more over time.
- Understand customer behavior across channels, since each session follows the user through the company's APIs, website, and agent conversations.
- Control what agents can and can't do: which personal agents to allow, how users sign in, and whether agents can view accounts or make changes.
The building blocks
Personal Agent Protocol covers the complete interface between a personal agent and a company: how the agent finds the company, who it acts for, what it is allowed to do, and how it gets work done through APIs, web pages, or a conversation with the company's agent. A company publishes once, and any personal agent can work with it. The protocol builds on widely used open standards, so teams can implement it with libraries and tools that already exist.
Getting connected
How a personal agent finds a company and gets access for one user.
Discovery
A document at /.well-known/poppy.json identifies the organization and says how to start sessions and sign in, along with the APIs and company agent it offers.
Standard sign-in
The user signs in on the company's own page through standard OAuth and chooses what access to grant. If the company allows it, the personal agent can also sign in for the user with the credentials the company asks for, such as an email and password.
One session across interfaces
One session covers API calls, conversations, and web browsing. APIs and conversations use a short-lived session token, a signed JWT. Signing in gives the personal agent lasting access, within the scopes the company allows for that sign-in type, until the user or the company revokes it.
Working together
How the personal agent and the company interact once connected.
A spectrum of interfaces
Companies choose what to offer: OpenAPI, MCP, or web pages, alongside an optional company agent. Each API keeps its own schema.
Web page access
A personal agent can browse the company's website in the same session. The agent's browser proves which session it belongs to, and the company sets its own cookie, so it recognizes the user and applies their sign-in permissions on each page.
Conversations
The personal agent can talk with the company for the user, or let the user talk with it directly, using text plus structured data. Both sides say whether a person or an AI is speaking, so conversations can adapt to who's participating.
Extensions
Discovery, identity, APIs, and conversations are all open to extension. Companies and industries can build on them to add things like payments, push notifications, or interactive elements.
Three everyday tasks
Each company chooses the interface that fits the task. Follow one task through Atlas, the user's personal agent, and see what the company exposes behind it.
Atlas finds Manzanita's company agent, asks about a return, and has the user sign in when Manzanita needs to see the order.
Finding Manzanita
The user wants to return a jacket. Atlas reads poppy.json, a file Manzanita publishes on its website, to learn how to reach Manzanita's own agent.
GET https://manzanitasupply.example/.well-known/poppy.json HTTP/1.1 200 OK Content-Type: application/json { "protocol_version": "0.1", "organization": { "name": "Manzanita Supply", "domain": "manzanitasupply.example" }, "auth": { "issuer": "https://auth.manzanitasupply.example", "direct": { "scopes": ["poppy:read", "poppy:write"] } }, "agent": { "protocols": [ { "type": "poppy", "endpoint": "https://api.manzanitasupply.example/poppy/conversations" } ] } }
GET https://auth.manzanitasupply.example/.well-known/oauth-authorization-server HTTP/1.1 200 OK Content-Type: application/json { "issuer": "https://auth.manzanitasupply.example", "token_endpoint": "https://auth.manzanitasupply.example/oauth/token", "revocation_endpoint": "https://auth.manzanitasupply.example/oauth/revoke", "authorization_endpoint": "https://auth.manzanitasupply.example/oauth/authorize", "poppy_domains": ["manzanitasupply.example"] } // Atlas checks that issuer matches auth.issuer and that // poppy_domains includes manzanitasupply.example.
Bring your company or personal agent onto Personal Agent Protocol
Companies start with a poppy.json file, their session and sign-in endpoints, and whichever interfaces they want personal agents to use.