# The Personal Agent Protocol, read by people who list agent tools (slim) > Sierra, Meta and partners published the first draft of the Personal Agent Protocol on 9 October 2026. What it specifies, what it leaves open, how it sits next to MCP, x402, AP2 and ACP, and who gains from it. - Full: https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.md (~1,850 tokens) · this version ~1,130 tokens · JSON https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft.json · canonical https://www.anchorterminal.com/blog/personal-agent-protocol-first-draft - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-10 ## What was announced On 6 October 2026 Sierra announced the Personal Agent Protocol with Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart [[1]](#ref-1). Sierra's aim, in its own words, is that "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do" [[1]](#ref-1). - 0.1: draft version, and "any part of it can change" - 3: ways to sign in an agent (direct, device and mediated) - 2: scopes of its own, read and write, plus whatever the company adds - 0: lines on payments, which are listed as future work The draft on 10 October 2026 ## What the draft specifies The spec calls itself Poppy, and a company publishes a `/.well-known/poppy.json` that says how to start a session and sign in. - **Who the agent is.** Each personal agent has a `client_id` that is an HTTPS URL returning its metadata, with its keys at a `jwks_uri`. It proves itself with signed client assertions. A company can keep allowlists and blocklists and rate-limit per agent. How an agent gets registered is "outside this specification". - **Who the user is.** The user's identifier is "opaque and different at each Company, so Companies can't match Users with each other". That's a good default. - **What it may do.** Signing in grants `poppy:read` and `poppy:write`, plus scopes the company defines, and "the Company MUST NOT grant scopes beyond those requested". The user can revoke, and revoking signs out every session made with that token. - **How they talk.** JSON over HTTPS, with streaming over server-sent events. A message carries text, data or context. Companies can also expose their APIs through MCP or OpenAPI, which the spec references [[2]](#ref-2). - **Confirming actions.** An optional Operations extension has the agent confirm an action before the company carries it out, at most once. The draft is honest that this approval is "a trust-based claim" the company can't verify [[4]](#ref-4). Almost all of it is OAuth. ## What it leaves open The draft's open topics page [[3]](#ref-3) lists payments, how a company reaches an agent when no request is open, attachments beyond text and data, and how companies register agents. Data minimisation is a SHOULD ("Personal Agents SHOULD share only what the task needs"), not a MUST [[2]](#ref-2). ## Where it sits next to what we list Personal Agent Protocol answers who the agent is and what it may do. - [x402](/tools/x402) pays per request over HTTP 402, with no account. - [AP2](/tools/ap2) is Google's protocol for authorising agent payments, now under the FIDO Alliance [[7]](#ref-7). - [ACP](/tools/acp) is OpenAI and Stripe's checkout specification. Stripe co-wrote ACP [[7]](#ref-7), and The Next Web reports Stripe and Shopify are also on Visa's agent protocol [[6]](#ref-6), so the payments extension is the one to watch. ## Who gains Sierra builds customer-service agents for companies [[8]](#ref-8), which is the company side of every conversation this protocol describes. The draft is open for comments on the site now. ## References Read on 10 October 2026. Quotes are as published. [1] Sierra, Introducing Personal Agent Protocol, 6 October 2026. Source for the announcement, the launch partners, Sierra's aim, the three ways a company can answer and the next steps. [2] Personal Agent Protocol, draft 0.1 specification, 9 October 2026. Source for Poppy, agent and user identity, scopes, revocation, sign-in, transport, the OAuth references and data minimisation. [3] Personal Agent Protocol, Open topics. [4] Personal Agent Protocol, Operations extension v1. Source for confirmed operations, at most once, and approval being a trust-based claim. [5] Personal Agent Protocol, Licence. [6] The Next Web, Sierra announces Personal Agent Protocol. [7] Anchor Terminal, the AP2 and ACP listings. [8] TechCrunch, Bret Taylor's Sierra reaches $100M ARR in under two years, 21 November 2025. Source for what Sierra sells. --- - Older: [The Log, issue 1: decide, declare, depart](https://www.anchorterminal.com/blog/the-log/issue-1-decide-declare-depart.md) - All posts: https://www.anchorterminal.com/blog/index.md