Sierra's Poppy Protocol Gives AI Agents Legitimate Identity, Ending Human Impersonation

Sierra released the Poppy protocol with major partners, enabling AI agents to authenticate via OAuth and operate with granular permissions via a /.well-known/poppy.json file, replacing the need for agents to mimic human behavior; the draft includes five permission levels, single-session continuity, and open Apache 2.0 licensing, though community debates remain about governance and revocation.

AI Engineering
AI Engineering
AI Engineering
Sierra's Poppy Protocol Gives AI Agents Legitimate Identity, Ending Human Impersonation

Why Poppy Is Needed

Currently, when users ask AI agents to book hotels, process returns, or change flights, the agent must log into the company's website and click around like a human. Companies face a dilemma: either block agent access entirely or allow agents to fully impersonate users with identical permissions. Both approaches are awkward.

Poppy solves this by giving agents a legitimate identity so companies know "this is a specific user's agent, authorized to do these tasks" — no impersonation or adversarial tactics required.

How Poppy Works

The core mechanism is straightforward. A company places a /.well-known/poppy.json file on its site that tells agents how to connect, authenticate, and which interfaces are available. The user logs in via OAuth on the company's page and then authorizes the agent for specific actions.

The protocol defines five permission tiers, from total block to full takeover:

Blocked — agents prohibited

Search rooms — read-only viewing allowed

See reservations — user-specific details visible after login

Book a room — actions permitted after user approval

Full access — agent fully represents the user

The middle three tiers are new; companies choose which level to expose, and users grant authorization per their needs.

One Session Across All Surfaces

An agent logs in once and can reuse the same session across the company's website, API, and even the company's own AI agent. For example, a user might first ask about a return policy as a guest, then log in to initiate a return, and finally confirm the refund — all in a continuous flow. The company sees the complete path instead of fragmented fragments.

Interface support includes OpenAPI, MCP, and ordinary web pages. Companies may expose only web pages, add APIs, or deploy their own agents; there is no mandatory requirement.

Community Debates

Reaction has been mixed. Some praise the direction: companies finally know they are dealing with an agent rather than a pretend human. Others raise concerns:

Although Poppy is an open protocol, will Sierra keep critical parts proprietary?

A developer reported a pull request closed without explanation.

Questions remain about authentication methods beyond OAuth and whether revocation can sync across all partner companies.

These points are not fully addressed in the draft. Sierra plans design workshops and a reference implementation over the next month.

Is It Worth Watching?

For users, Poppy means AI agents can perform specific tasks without handing over passwords, with revocable permissions at any time. For companies, it offers a standardized way to identify and control AI agents instead of reacting passively.

The partner list already includes payment and retail giants (Stripe, Shopify, Walmart, Mastercard, Visa) and the leading agent player OpenAI. The protocol is Apache 2.0 licensed, with code and documentation publicly available.

The draft is published at personalagentprotocol.org (http://personalagentprotocol.org). Whether it becomes an industry standard depends on the next few months of iteration and adoption.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

AI AgentsIndustry StandardsOAuthApache 2.0Agent AuthenticationSierraPersonal Agent ProtocolPoppy Protocol
AI Engineering
Written by

AI Engineering

Focused on cutting‑edge product and technology information and practical experience sharing in the AI field (large models, MLOps/LLMOps, AI application development, AI infrastructure).

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.