Who's behind Poppy? Where the industry stands on the Personal Agent Protocol

Personal AI assistants are learning to book for people. Before they can deal with a business directly, though, they need a common way to do it. That means a way to show who they're acting for, to sign in properly and to know what the business allows.

In October 2026 Meta and Sierra, with a group of partners, proposed one: the Personal Agent Protocol. Its backers call it Poppy, and the file at its centre is named poppy.json. This post covers what Poppy is, who has said what about it, and what it means for you if you run a small local business.

Short version: the standard is a draft, it has big names behind it, and almost no websites use it yet.

What Poppy is, in plain terms

A business that supports Poppy puts a small file on its website at a fixed address:

yourbusiness.com/.well-known/poppy.json

The sign-in part is built on OAuth, the same kind of technology behind "Log in with Google" buttons. The draft offers a few ways to sign in. In some, the customer signs in on the business's own page. In one, called "mediated" sign-in, the assistant passes the customer's login details to the business for them. The draft also lets a business list its services as MCP or OpenAPI interfaces. Both are common ways of describing what software can do so that other software can use it.

The draft spec is published at personalagentprotocol.org. It calls itself draft version 0.1 and warns that any part of it can change before a stable version, including in ways that break things built on it. It's released under the Apache 2.0 open-source licence. The page doesn't name individual authors or set out who will make decisions about it in future.

Who announced it

Meta and Sierra, on 6 October 2026. Sierra is a company that builds AI customer-service agents. Meta announced the protocol alongside Sierra as an open standard that anyone can implement. Meta called the post a preview of its work and said a working group of partners would finish building it. Meta links the protocol to its own personal assistant, Muse. On the same day Sierra's co-founders Bret Taylor and Clay Bavor published their own launch post.

The two launch posts named slightly different partners, as CMSWire noticed:

Sierra's 9 October post adds NiCE to its list of launch partners, so the one remaining difference is Decagon, which only Meta names. Decagon, which also builds AI customer-service agents, announced a related trust and consent standard of its own, called PACT, on the same day, and according to Object Edge says it is joining the Poppy working group.

Sierra's launch post includes statements from several partners. Tony Bates, Chairman and CEO of Genesys, said:

"Brands need a trusted way to know who an AI agent represents…"

Stripe's Head of Payments, Kevin Miller, said people who send an agent expect the same service they'd get if they came themselves. Shopify's VP of Product, Mani Fazeli, framed it as a chance for merchants to help with product questions, purchases and returns. (These statements come from Sierra's post; we've paraphrased them.)

Sierra's launch post also floats ideas for later extensions that aren't in the first draft: payments (letting an assistant pay without sharing card details), finer-grained permissions, and notifications, for example telling an assistant when an order ships.

The draft and a much longer list of partners

On 9 October 2026, Sierra published the first draft and named 35 more "design partners". These are companies that will take part in the design process and give feedback. They include:

Sierra's post lists the rest. It also promises a "reference implementation" (working sample code for developers) within about a month. We haven't seen one published yet.

Being a design partner means a company has agreed to help shape the draft. It doesn't mean the company has built anything with it or committed to using it.

Who hasn't said anything (yet)

The sceptics and the "yes, but" voices

The criticism we found so far comes from industry newsletters and trade blogs rather than major news outlets. It's mostly "this is unfinished" rather than "this is a bad idea".

How Poppy fits with other AI standards

Poppy isn't the only proposed standard. Here's how the others relate, as far as we can tell.

Several big companies, notably Shopify and Stripe, have signed up to more than one of these efforts. Nobody has said which ones will win, or whether they'll merge.

Is anyone actually using it?

Not really, not yet. On 11 October 2026 we checked the main websites of some launch and design partners: Meta, Sierra, Walmart, Shopify, Stripe, Genesys, NiCE, Target, Cloudflare, Zapier and OpenAI. None of them had a poppy.json file at that address (Meta's site returned an error page). The only live one we found was a developer demo (poppy-receiver.roundtrip.workers.dev) for a sample shop.

That's normal for a standard announced on 6 October and still a draft. It also means there's no rush.

What this means for a small business

To be honest, nothing changes for you this week. Today's AI assistants can't use Poppy to book your dog-grooming slot or your mobile nail appointment, and the standard may change before they can.

What has changed is the direction. Some of the biggest names in tech, payments and retail have signed up to help shape one shared way for personal AI assistants to deal with businesses. If it sticks, being "readable" by AI assistants could start to matter the way being on Google Maps did.

Here's a sensible approach for now. Make sure your basic details (what you do, where you work, how to reach you) are clear and up to date online. Keep an eye on the standard as it develops, and don't pay anyone who promises "AI bookings" today.

If you'd like to see where your website stands, the free checker at ivyatyours.com reads your site, looks for a poppy.json file and compares what it finds with the draft spec.

Sources

Primary sources:

Commentary and coverage:

Our own check (11 October 2026): we requested /.well-known/poppy.json from each site named in "Is anyone actually using it?" above.