Let your customers' AI assistants in. Safely.

The Personal Agent Protocol is a new, open protocol for how an AI assistant finds a company's front door. Then the assistant proves who it is, and uses a person's account only within what that person approved.

Type its domain, like example.com.

Type a domain to check, like example.com.

That doesn't look like a domain. Type just the company's domain, like example.com.

That has a space or a hidden character in it. Type the domain again, like example.com.

That looks like an email address. Type only the part after the @, like example.com.

Only web addresses work here. Type the company's domain, like example.com.

Check the address, it looks like a typo near the start. Type just the domain, like example.com.

That's an ending many sites share, not one site. Type the full domain, like example.co.uk.

That looks like an IP address. Type the company's domain, like example.com.

That points at your own computer. Type a public domain, like example.com.

Leave out the colon and the number after it. Type just the domain, like example.com.

Leave out the colon and anything after it. Type just the domain, like example.com.

Leave out everything after the domain. The checker looks at the whole site, so example.com is enough.

The problem

Your customers' assistants already use your site the way people do: loading pages, clicking through forms, and when that fails, calling your support line. It's slow, and the task often fails.

The idea

The Personal Agent Protocol (PAP for short, which its spec calls Poppy) gives those assistants a standard front door. Your site publishes one public file that says where assistants should go, and your sign-in server confirms the file is yours.

Each assistant proves who it is and gets a short-lived key. The key is tied to a secret only that assistant holds, so a copy is no use to anyone else. When a task needs the customer's account, the customer signs in, usually on your own page, and approves what the assistant may do. The key then covers only that. Think of a valet key.

One exception: MCP, a common way to connect tools to assistants, can't check that secret. So a key made for an MCP server works at that one server only.

What changes

When people sign in on your own page, they never give their password to an assistant. You keep your own login, your own rules, and a record of what each assistant may do. People can disconnect an assistant from their account settings.

Assistants get one way in that is the same on every PAP site. Each company still decides which assistants it lets in.

How it works, in three steps

123poppy.jsonView ordersTrack orderChange card
  1. Step 1: Find the door

    A public file at a fixed address on the company's site tells assistants where to go.

  2. Step 2: Get a key

    The assistant proves who it is and gets a short-lived key tied to a secret it holds. To reach an account, the person signs in, usually on the company's own page.

  3. Step 3: Act within the key

    Each API call carries the key and, except at MCP servers, fresh proof of the secret. The company checks them, and allows account actions only within what the person approved.