The Personal Agent Protocol was written for consumers. Here's the B2B case, and what we built.

The Personal Agent Protocol was written for consumers. Here's the B2B case, and what we built.
On October 9, Sierra and Meta published the first draft of the Personal Agent Protocol, a proposed open standard for how a person's AI agent works with a company. Stripe, Shopify and Walmart were named at the announcement three days earlier. The draft arrived with 35 more design partners, OpenAI, Visa, Okta and Cloudflare among them.
Read the examples and you'd file it under retail and customer support. A jacket that isn't warm enough. Internet that keeps dropping. A flight delayed overnight.
We read the spec looking for B2B, and found it in a single sentence. Salespeak now supports that part of the protocol. This post covers what that part is, what you get from it, and where the draft still falls short for anyone selling to businesses.
The sentence that matters for B2B
Under the protocol, every session starts signed out. The agent hasn't logged in to anything, and the person it works for has no account with the company. Most of the draft is about what happens next: signing in, granting read or write access, changing a booking.
But the signed-out state isn't just a waiting room. The spec says:
"With a signed-out token, the Company Agent can answer general questions."
Now picture who asks general questions of a company they have no account with. In B2B, that's a buyer doing vendor research. Their agent wants to know your pricing model, whether you're SOC 2 Type II certified, what you integrate with, how long implementation takes. It may be asking four other vendors the same things in the same hour.
Until this draft there was no standard way for that agent to ask a company directly. It read your website and guessed. The protocol gives it a file to fetch at /.well-known/poppy.json and, if you publish one, an agent of yours to talk to.
You won't see the buyer
This is the detail that should change how a marketing team plans.
The agent has to identify itself. Every request is signed, so you always know which assistant is asking. The person behind it is a different story. You get an ID for them that is stable, so you can tell a returning visitor, and opaque, so you can't tell who it is. The spec is strict about this: the ID can't be derived from an email address, a phone number or a name, and it's different at every company, so two vendors can't compare notes.
There's no form in this flow, and no visitor identification tool has anything to work with. That's by design, and we think it's the right design. But it means the question "who was that?" has no answer.
The question you can still do something about is "what did we tell them?"
One session, three places your answers live
In the full protocol, a single session can cover a company's website, its APIs and its agent. A buyer's agent could ask your agent about pricing, then open your pricing page inside the same task.
If those disagree, a person might never notice. An agent comparing them side by side will. We've logged more than 10 million AI agent visits to our customers' websites, so we know agents are already reading those pages. A stale number on one of them has always been a risk. A protocol that hands the agent a second source to check it against makes the risk easier to trip.
So before you open another way in, make sure the answers behind it agree with each other.
What Salespeak supports today
We built the signed-out path. Nothing more than that, and we'd rather say so plainly.
- salespeak.ai publishes a discovery file. You can fetch it:
curl -s https://salespeak.ai/.well-known/poppy.json - A personal agent that speaks the protocol can start a signed-out session and ask our company agent questions.
- The answers come from the same company context that runs our website agent. There isn't a second knowledge base to maintain, which is the point.
- Customers can switch it on for their own company, so their agent is discoverable on their own domain.
- You get a record of which agents showed up and what they asked.
That last one deserves a second look. When you can't see the buyer, the questions are the only signal you get. Which assistants are asking about you, and what they wanted to know that you couldn't answer, is the closest thing to intent data this flow produces.
The technical details, with working requests, are on our agent endpoint page. If the term is new to you, we wrote a plain definition of the Personal Agent Protocol.
What we don't support, and what to expect
We don't support user sign-in, account access, browser sessions, or listing APIs in the discovery file. Those parts of the protocol belong with a company's own login system, and for vendor research they aren't needed.
It's also early, in three ways.
The draft is version 0.1, and it says any part of it can change in ways that break compatibility. We built it expecting to rebuild pieces.
Being a design partner isn't the same as shipping support. OpenAI is helping shape the draft. That doesn't mean ChatGPT speaks the protocol today. Until the big assistants do, traffic over it will be small. We aren't promising otherwise.
And the existing ways in still matter more right now. Agents reach companies through their websites and through MCP far more than through anything published this month. This is one more door, not a replacement for the others.
What the draft is missing for B2B
The protocol models one person, one agent, one account. That fits a shopper. It doesn't fit a purchase where the agent works for an employer, or for six people on a buying committee who each have their own assistant.
There's no way in the draft for an agent to say "I'm acting for a company" or "this evaluation belongs to a team." The draft's own list of open topics names payments, push notifications and attachments. Buying on behalf of an organization isn't on it.
We think it should be, and we're sending that feedback to the protocol team. If you sell to businesses and have a view, send yours too. The draft is open for comment and the people writing it have asked for it.
What to do this week
- Fetch
/.well-known/poppy.jsonon your own domain. You'll get a 404. That's what a personal agent gets too. - Write down the five questions a buyer asks before they ever talk to you. Check the answers on your website, in your docs and in your sales deck. Count how many places disagree.
- If you're a Salespeak customer and want your agent discoverable, tell us. It takes one redirect on your domain and we switch it on.
Step two is worth doing whether or not this protocol wins. The agents are already asking.
Omer Gotlieb is cofounder and CEO of Salespeak. Salespeak keeps your company's GTM context accurate and current, so every AI agent that works for or evaluates your business gets the same version. See how AI Agent Relations works.
You might also like
We analyzed 10 million AI visits to B2B websites. The optimized pages got 26x more.