We're building toward a financial platform you can reach through the agent you choose.
When Meta and Sierra announced Personal Agent Protocol (Poppy), they brought together companies including Stripe, Shopify, Walmart, and Rocket to help develop it. The idea was straightforward: give personal agents a standard way to work with businesses on a customer's behalf. Their original announcement laid out the effort.
Then the group widened. When Sierra published the draft, Cloudflare, OpenAI, Plaid, Visa, Mastercard, Bank of America, and other companies joined as design partners. Sierra's draft announcement includes the full list and describes their role in shaping the protocol.
That breadth caught our attention. An agent connection has to work for the company building the assistant and the business serving the customer. Bringing both into the design process gives the standard a better chance of addressing the problems each actually faces.
We've now shipped X1's first Poppy integration. It's live in a private pilot that we've tested with our own client and a QA member account. The client can read that member's existing estate-review status through MCP, after the member signs in and grants permission.
It's a small first use case. The reason we're building it is bigger: you shouldn't have to move your financial history every time you find a better assistant.
Financial apps usually ask you to come to them. You sign in, find the right page, and work through whatever interface the company has built.
A personal agent changes where that interaction can start. You ask the assistant you already use, and it connects to the business that has the information or can do the work. The business still serves you, even when the conversation begins somewhere else.
For X1, that raises a useful question. If someone can choose their own interface, what makes the financial platform underneath worth keeping?
We think the answer is the household record and the work it supports. An assistant can help you ask a question. It still needs a dependable account of what's on file, what has been reviewed, and what someone has approved. Those aren't interchangeable, especially when family members and professionals have different responsibilities.
Moving the conversation to another assistant shouldn't erase those distinctions. It shouldn't require you to upload the same documents again or explain your household from scratch.
That's the direction we want for X1. Use the assistant that works for you. Let X1 supply the financial context and enforce the permissions that go with it.
It's easy to imagine every financial platform building a separate connection for every personal agent. It's harder to see why a customer would want that arrangement. Each new assistant would mean another integration to wait for, another access model to understand, and another connection for the platform to maintain.
Poppy offers a common starting point. A business publishes how an agent can find it and what it offers. The agent identifies itself, and the customer signs in with the business to approve access. The protocol overview explains how that relationship can extend across APIs, websites, and conversations with a company's own agent.
Poppy builds on standards such as OAuth, MCP, and OpenAPI. X1 already has an MCP surface, so we can extend a service we have rather than start over. The protocol defines a session that connects one person to one company through one agent. The draft specification sets out those building blocks.
That still leaves plenty of work for the platform. An agent's credential doesn't settle whether a person can read a particular record today. X1 has to check current access. And when someone disconnects an agent, that decision has to take effect even if its credential hasn't expired.
Our first Poppy integration lets an admitted agent request permission to read the member's estate-review status. The member signs in on X1 and approves that access. The agent can then make the read through MCP, and the member can disconnect it from X1.
The permission covers that existing status. It doesn't authorize a new analysis, a document upload, or a change to the household record.
We've tested the production connection with an X1-controlled client and an existing QA member account. That covered consent, refreshing access, reconnecting, and rejecting requests beyond the permitted read. We also checked that disconnecting the agent stopped further reads with an unexpired credential and prevented it from refreshing access.
The test account didn't have a saved estate review, and X1 returned that state. We've verified the connection and its controls. Testing a real personal-agent developer's client against a customer workflow is the next step.
Poppy gives a personal agent a way to connect to X1 with the member's permission. X1 supplies the household record and checks access to it. Eve remains our runtime for agent work that needs to continue beyond a single exchange.
Today, the Poppy pilot reaches the estate-review status through MCP. Connecting Poppy conversations to Eve will need its own implementation and testing, as will any path that lets an outside agent propose an action.
Poppy is still draft 0.1, so we'll keep testing against the specification as it develops. We're starting with a limited read and working toward a real client integration before opening up more.
If you're building a personal agent and want to test this connection with X1, get in touch. We want your users to be able to bring their financial context with them, whichever assistant they choose.