{
  "data": {
    "faq": null,
    "kicker": "Blog · 10 October 2026",
    "lede": "Sierra and Meta published the first draft of the Personal Agent Protocol this week. It answers who an agent is and who it speaks for. It doesn't answer how that agent pays, yet."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft",
    "json": "https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.md",
    "slim": "https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.min.md"
  },
  "markdown": "## What was announced\n\nOn 6 October 2026 Sierra announced the Personal Agent Protocol with Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart [[1]](#ref-1). On 9 October the first draft went up at personalagentprotocol.org [[2]](#ref-2).\n\nSierra's aim, in its own words, is that \"consumers decide what access to give their personal agents, and companies set parameters for what those agents can do\" [[1]](#ref-1). A personal agent is the one that works for you (books the table, chases the refund, changes the flight). The company on the other side wants to know it's talking to an agent and who that agent represents. Today it mostly guesses, from a browser fingerprint or a scraped session.\n\n- 0.1: draft version, and \"any part of it can change\"\n- 3: ways to sign in an agent (direct, device and mediated)\n- 2: scopes of its own, read and write, plus whatever the company adds\n- 0: lines on payments, which are listed as future work\n\nThe draft on 10 October 2026\n\n## What the draft specifies\n\nThe spec calls itself Poppy, and a company publishes a `/.well-known/poppy.json` that says how to start a session and sign in. The pieces, from the draft [[2]](#ref-2):\n\n- **Who the agent is.** Each personal agent has a `client_id` that is an HTTPS URL returning its metadata, with its keys at a `jwks_uri`. It proves itself with signed client assertions. A company can keep allowlists and blocklists and rate-limit per agent. How an agent gets registered is \"outside this specification\".\n- **Who the user is.** The user's identifier is \"opaque and different at each Company, so Companies can't match Users with each other\". That's a good default.\n- **What it may do.** Signing in grants `poppy:read` and `poppy:write`, plus scopes the company defines, and \"the Company MUST NOT grant scopes beyond those requested\". The user can revoke, and revoking signs out every session made with that token.\n- **How they talk.** JSON over HTTPS, with streaming over server-sent events. A message carries text, data or context. Companies can also expose their APIs through MCP or OpenAPI, which the spec references [[2]](#ref-2).\n- **Confirming actions.** An optional Operations extension has the agent confirm an action before the company carries it out, at most once. The draft is honest that this approval is \"a trust-based claim\" the company can't verify [[4]](#ref-4).\n\nAlmost all of it is OAuth. The reference list is a page of OAuth RFCs, including DPoP for binding tokens to a key. I think that's the right call. Companies already run OAuth, and a protocol that reuses it gets adopted.\n\n## What it leaves open\n\nThe draft's open topics page [[3]](#ref-3) lists payments, how a company reaches an agent when no request is open, attachments beyond text and data, and how companies register agents. It doesn't name who governs changes. The spec and docs are Apache-2.0, though the names and logo aren't covered by that licence [[5]](#ref-5).\n\nData minimisation is a SHOULD (\"Personal Agents SHOULD share only what the task needs\"), not a MUST [[2]](#ref-2). If the protocol is meant to give consumers control, that's the line I'd tighten first.\n\n## Where it sits next to what we list\n\nPersonal Agent Protocol answers who the agent is and what it may do. The payment protocols we grade answer how it pays.\n\n- [x402](/tools/x402) pays per request over HTTP 402, with no account.\n- [AP2](/tools/ap2) is Google's protocol for authorising agent payments, now under the FIDO Alliance [[7]](#ref-7).\n- [ACP](/tools/acp) is OpenAI and Stripe's checkout specification.\n\nStripe co-wrote ACP [[7]](#ref-7), and The Next Web reports Stripe and Shopify are also on Visa's agent protocol [[6]](#ref-6), so the payments extension is the one to watch. A personal agent that can prove who it works for and then pay through x402, AP2 or ACP is the whole loop. Today you'd assemble it from three specifications.\n\n## Who gains\n\nSierra builds customer-service agents for companies [[8]](#ref-8), which is the company side of every conversation this protocol describes. Sierra's post gives a company three ways to answer a personal agent (its website, its APIs, or its own agent) [[1]](#ref-1), and the draft lets the company decide which personal agents to let in [[2]](#ref-2). That's a reasonable design and also a good market for whoever sells the company's agent. Meta, whose assistant lives inside WhatsApp, Instagram and Messenger, is on the personal-agent side. Same pattern as decision models. Whoever stands in the middle of the conversation sees it.\n\nThe draft is open for comments on the site now. Sierra's post promises design workshops and a reference implementation next [[1]](#ref-1). We'll list it in the directory once there's an implementation an agent can use. We'll grade it like the payment protocols, and say what changes between drafts on [Sunsets](/sunsets/).\n\n## References\n\nRead on 10 October 2026. Quotes are as published.\n\n[1] Sierra, Introducing Personal Agent Protocol, 6 October 2026. Source for the announcement, the launch partners, Sierra's aim, the three ways a company can answer and the next steps. https://sierra.ai/blog/introducing-personal-agent-protocol\n\n[2] Personal Agent Protocol, draft 0.1 specification, 9 October 2026. Source for Poppy, agent and user identity, scopes, revocation, sign-in, transport, the OAuth references and data minimisation. https://personalagentprotocol.org/docs/spec\n\n[3] Personal Agent Protocol, Open topics. Source for payments, notifications, attachments and registration being undecided. https://personalagentprotocol.org/docs/open-topics\n\n[4] Personal Agent Protocol, Operations extension v1. Source for confirmed operations, at most once, and approval being a trust-based claim. https://personalagentprotocol.org/docs/extensions/operations\n\n[5] Personal Agent Protocol, Licence. Source for Apache-2.0 on the spec and docs, without the names and logo. https://personalagentprotocol.org/license\n\n[6] The Next Web, Sierra announces Personal Agent Protocol. Source for Stripe and Shopify being on Visa's agent protocol. https://thenextweb.com/news/personal-agent-protocol-sierra-meta\n\n[7] Anchor Terminal, the AP2 and ACP listings. Source for AP2's move to the FIDO Alliance and ACP's authors, each with the pages it was graded from. https://www.anchorterminal.com/categories/checkout-protocols\n\n[8] TechCrunch, Bret Taylor's Sierra reaches $100M ARR in under two years, 21 November 2025. Source for what Sierra sells. https://techcrunch.com/2025/11/21/bret-taylors-sierra-reaches-100m-arr-in-under-two-years/\n\n---\n\n- Older: [The Log, issue 1: decide, declare, depart](https://www.anchorterminal.com/blog/the-log/issue-1-decide-declare-depart.md)\n- All posts: https://www.anchorterminal.com/blog/index.md\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Blog",
        "url": "https://www.anchorterminal.com/blog/"
      },
      {
        "name": "Personal Agent Protocol",
        "url": ""
      }
    ],
    "description": "Sierra, Meta and partners published the first draft of the Personal Agent Protocol on 9 October 2026. What it specifies, what it leaves open, how it sits next to MCP, x402, AP2 and ACP, and who gains from it.",
    "facts": [
      "Vlad Cealicu",
      "10 October 2026"
    ],
    "h1": "The Personal Agent Protocol, read by people who list agent tools",
    "image": "https://www.anchorterminal.com/assets/og/blog-personal-agent-protocol.png",
    "path": "/blog/personal-agent-protocol-first-draft",
    "published": "2026-10-10",
    "section": "blog",
    "title": "Personal Agent Protocol draft 0.1, what it covers and leaves open | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-10",
    "url": "https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft"
  },
  "tokens": {
    "markdown": 1850,
    "slim": 1130
  },
  "version": 1
}
