Skip to content
Poppy Protocol: Build a Personal Agent Client — ContentBuffer guide

Poppy Protocol: Build a Personal Agent Client

K
Kodetra Technologies··13 min read Advanced

Summary

Meta and Sierra's draft agent standard, in Python: discovery, DPoP sessions, and replay tests.

On October 6, Sierra announced the Personal Agent Protocol with Meta, Shopify, Stripe, Walmart, Genesys and others. It goes by the name Poppy, and the draft spec went up on October 9 with 35 more design partners, including OpenAI, PayPal, Mastercard and Visa. The idea is simple to state: a personal AI agent (your assistant, acting for you) should be able to walk up to a company, prove who it is, get the user's permission, and then use the company's website, API or support agent without pretending to be a human in a browser.

Most of the coverage so far is high level. The spec itself (Draft 0.1, at personalagentprotocol.org/docs/spec) is concrete: a discovery file, an issuer check, a JWT bearer grant, and DPoP-bound tokens. In this guide you will implement the agent side of that handshake in about 90 lines of Python, run it against a local mock company, and then try to break it with a replayed request and a stolen token. Everything below was run before it was written down.

Keep reading — it's free

Enter your email to keep reading — plus the best of AI & tech, daily. Free, forever.

Also get
or

Already a member? Sign in

Comments

Subscribe to join the conversation...

Be the first to comment