Definition
Why It Matters
Today an AI agent has two ways to deal with a company. It gets blocked, or it logs in as the person and can do anything that person can. The Personal Agent Protocol adds the steps in between. A company can let any agent look things up, let a signed-in agent see an account, and require the person's approval before anything changes.
The draft's examples are consumer tasks: return a jacket, rebook a flight. The part that matters for B2B is smaller. Every session starts signed out, and the draft says the company's agent can answer general questions in that state. A buyer's agent asking a vendor about pricing or security, before any account exists, is exactly that case.
Two details change how a marketing team should think about it. First, the agent must identify itself, but the buyer does not. The company sees which agent is asking and a stable ID that carries no personal information and is different at every company. There is no form to fill and no visitor to identify. Second, one session can cover the website, the APIs, and the company's agent. If those give different answers, the buyer's agent sees the disagreement in a single task.
So the thing a company controls is the quality and consistency of its answers. That is the problem Salespeak.ai works on: keeping a company's GTM context accurate and current, so every agent gets the same version. Salespeak supports signed-out conversations over the Personal Agent Protocol (draft 0.1): a buyer's agent can ask a company's agent questions with no sign-in, and customers can make their agent discoverable on their own domain. See how it works on salespeak.ai.
How It Works
Draft 0.1 defines five building blocks, plus a way to extend them.
1. Discovery. The company publishes a file at /.well-known/poppy.json. It names the company and lists what it offers: sign-in options, APIs, a website endpoint, and a company agent. A company can offer any one of these and add more later.
2. Sessions and identity. The agent publishes its own identity document and signs every request. The company always knows which agent is calling. A session starts signed out. The person can then sign in on the company's own page and choose what the agent may do. The draft defines two broad permissions, read and write, and companies can define narrower ones.
3. APIs. The company can list OpenAPI descriptions and MCP servers. The agent calls them with a short-lived session token.
4. Web browsing. The agent's browser can join the same session, so the website applies the same permissions as the APIs.
5. Conversations. The agent can talk with the company's agent in text plus structured data. Every message says whether a person or an AI wrote it. Either side can bring in a human.
The draft reuses existing standards (OAuth 2.0, JWTs, DPoP, OpenAPI, MCP) and is published under the Apache 2.0 license. Its own list of open topics names payments, push notifications, and attachments as not yet covered.
Example
This is an illustration of the B2B case, not a customer story.
A head of security at a 400-person software company asks her assistant to shortlist three email security vendors that are SOC 2 Type II certified and integrate with Microsoft 365. Her agent fetches each vendor's poppy.json, starts a signed-out session, and asks each vendor's agent the same four questions.
Each vendor sees the name of the assistant and an anonymous ID. None of them learns her name or her employer. Two vendors answer with current certification dates and a pricing range. The third has no discovery file, so her agent reads its website and finds a pricing page that contradicts a PDF. The shortlist she sees ranks the third vendor last, and nobody at that vendor knows the evaluation happened.
Common Mistakes
- Reading it as a retail standard only. The examples are consumer, but signed-out questions to a company agent describe B2B vendor research as written.
- Treating a draft as finished. Version 0.1 says any part can change in ways that break compatibility. Build against it with that in mind.
- Assuming a design partner already supports it. The partner list describes who is shaping the draft. It says nothing about which assistants send traffic over it today.
- Expecting to identify the buyer. The user ID is opaque by design and may not be derived from an email, a phone number, or a name. Plan to earn the conversation, not to capture a lead.
- Publishing an agent that disagrees with the website. One session can reach both. Fix the answers before opening another way in.
Frequently Asked Questions
The Personal Agent Protocol, also called Poppy, is a draft open standard for how a person's AI agent works with a company. A company publishes one file that says how agents can reach it and what they may do. The agent identifies itself on every request, and the person decides whether it can view their account, change it, or neither. Sierra and Meta published draft version 0.1 on October 9, 2026.
Sierra and Meta developed the draft. It was announced on October 6, 2026 with Genesys, Instinct, NiCE, Rocket, Shopify, Stripe, and Walmart. On October 9, Sierra named 35 more design partners, including OpenAI, Visa, Mastercard, Cloudflare, Okta, and Zendesk. Being a design partner means taking part in the design process. It does not mean a product already supports the protocol.
The draft is written around consumer tasks, but one part fits B2B as written. Every session starts signed out, and the draft says a company's agent can answer general questions in that state. That is what a buyer's agent does when it researches a vendor. What the draft does not have yet is a way for an agent to say it acts for an employer or a buying team.
MCP defines how an agent calls tools on a server. The Personal Agent Protocol sits around that: how the agent finds the company, proves which agent it is, represents one specific person, and gets permission. A company can list an MCP server inside its Personal Agent Protocol discovery file as one of the ways agents can work with it.