Blog · 10 October 2026

The Personal Agent Protocol, read by people who list agent tools

Sierra and Meta published the first draft of the Personal Agent Protocol this week. It answers who an agent is and who it speaks for. It doesn't answer how that agent pays, yet.

What was announced

On 6 October 2026 Sierra announced the Personal Agent Protocol with Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart [1]. On 9 October the first draft went up at personalagentprotocol.org [2].

Sierra's aim, in its own words, is that "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do" [1]. A personal agent is the one that works for you (books the table, chases the refund, changes the flight). The company on the other side wants to know it's talking to an agent and who that agent represents. Today it mostly guesses, from a browser fingerprint or a scraped session.

0.1draft version, and "any part of it can change"
3ways to sign in an agent (direct, device and mediated)
2scopes of its own, read and write, plus whatever the company adds
0lines on payments, which are listed as future work
The draft on 10 October 2026

What the draft specifies

The spec calls itself Poppy, and a company publishes a /.well-known/poppy.json that says how to start a session and sign in. The pieces, from the draft [2]:

  • Who the agent is. Each personal agent has a client_id that is an HTTPS URL returning its metadata, with its keys at a jwks_uri. It proves itself with signed client assertions. A company can keep allowlists and blocklists and rate-limit per agent. How an agent gets registered is "outside this specification".
  • Who the user is. The user's identifier is "opaque and different at each Company, so Companies can't match Users with each other". That's a good default.
  • What it may do. Signing in grants poppy:read and poppy:write, plus scopes the company defines, and "the Company MUST NOT grant scopes beyond those requested". The user can revoke, and revoking signs out every session made with that token.
  • How they talk. JSON over HTTPS, with streaming over server-sent events. A message carries text, data or context. Companies can also expose their APIs through MCP or OpenAPI, which the spec references [2].
  • Confirming actions. An optional Operations extension has the agent confirm an action before the company carries it out, at most once. The draft is honest that this approval is "a trust-based claim" the company can't verify [4].

Almost all of it is OAuth. The reference list is a page of OAuth RFCs, including DPoP for binding tokens to a key. I think that's the right call. Companies already run OAuth, and a protocol that reuses it gets adopted.

What it leaves open

The draft's open topics page [3] lists payments, how a company reaches an agent when no request is open, attachments beyond text and data, and how companies register agents. It doesn't name who governs changes. The spec and docs are Apache-2.0, though the names and logo aren't covered by that licence [5].

Data minimisation is a SHOULD ("Personal Agents SHOULD share only what the task needs"), not a MUST [2]. If the protocol is meant to give consumers control, that's the line I'd tighten first.

Where it sits next to what we list

Personal Agent Protocol answers who the agent is and what it may do. The payment protocols we grade answer how it pays.

  • x402 pays per request over HTTP 402, with no account.
  • AP2 is Google's protocol for authorising agent payments, now under the FIDO Alliance [7].
  • ACP is OpenAI and Stripe's checkout specification.

Stripe co-wrote ACP [7], and The Next Web reports Stripe and Shopify are also on Visa's agent protocol [6], so the payments extension is the one to watch. A personal agent that can prove who it works for and then pay through x402, AP2 or ACP is the whole loop. Today you'd assemble it from three specifications.

Who gains

Sierra builds customer-service agents for companies [8], which is the company side of every conversation this protocol describes. Sierra's post gives a company three ways to answer a personal agent (its website, its APIs, or its own agent) [1], and the draft lets the company decide which personal agents to let in [2]. That's a reasonable design and also a good market for whoever sells the company's agent. Meta, whose assistant lives inside WhatsApp, Instagram and Messenger, is on the personal-agent side. Same pattern as decision models. Whoever stands in the middle of the conversation sees it.

The draft is open for comments on the site now. Sierra's post promises design workshops and a reference implementation next [1]. We'll list it in the directory once there's an implementation an agent can use. We'll grade it like the payment protocols, and say what changes between drafts on Sunsets.

References

Read on 10 October 2026. Quotes are as published.

  1. [1]Sierra, Introducing Personal Agent Protocol, 6 October 2026. Source for the announcement, the launch partners, Sierra's aim, the three ways a company can answer and the next steps. sierra.ai
  2. [2]Personal Agent Protocol, draft 0.1 specification, 9 October 2026. Source for Poppy, agent and user identity, scopes, revocation, sign-in, transport, the OAuth references and data minimisation. personalagentprotocol.org
  3. [3]Personal Agent Protocol, Open topics. Source for payments, notifications, attachments and registration being undecided. personalagentprotocol.org
  4. [4]Personal Agent Protocol, Operations extension v1. Source for confirmed operations, at most once, and approval being a trust-based claim. personalagentprotocol.org
  5. [5]Personal Agent Protocol, Licence. Source for Apache-2.0 on the spec and docs, without the names and logo. personalagentprotocol.org
  6. [6]The Next Web, Sierra announces Personal Agent Protocol. Source for Stripe and Shopify being on Visa's agent protocol. thenextweb.com
  7. [7]Anchor Terminal, the AP2 and ACP listings. Source for AP2's move to the FIDO Alliance and ACP's authors, each with the pages it was graded from. anchorterminal.com
  8. [8]TechCrunch, Bret Taylor's Sierra reaches $100M ARR in under two years, 21 November 2025. Source for what Sierra sells. techcrunch.com

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.