If you run a retailer, bank or insurer, the Personal Agent Protocol gives you two decisions this quarter and nothing to build yet. Decide which door outside AI agents use to reach you, and what a guest agent versus a signed-in agent may read or change on a customer's account. Meta and Sierra announced the protocol on October 6, 2026 with Walmart, Shopify, Stripe, Rocket, Genesys and Instinct as partners. The v0.1 specification is due "later this month." As of launch, no specification, licence or governing body has been published, and OpenAI, Anthropic, Amazon and Google are not on the partner list.
This quarter's work is a policy document, and the code can wait for a published text.
What the Personal Agent Protocol Actually Defines
The Personal Agent Protocol (PAP) is a proposed open standard for how a consumer's AI agent authenticates with a business and what it is allowed to do once it gets in. According to Sierra's announcement, it runs on OAuth, the same authorization standard behind "sign in with" buttons, and it lets the company choose the route an agent takes:
- Your website. The agent navigates ordinary web pages.
- Your APIs. The agent calls interfaces you expose through MCP or OpenAPI.
- Your own agent. The outside agent talks to the agent you already run, for tasks that need your side of the conversation.
Access comes in tiers. A guest agent can check availability or read a policy without signing in. A signed-in agent works against the customer's account, and the customer decides whether it gets read-only or write access. Sessions carry across channels, so context survives the moment a guest becomes a signed-in user.
Bret Taylor, Sierra's co-founder and OpenAI's board chair, compared it to signing in to websites with Google or Facebook credentials. "It is kind of chaos until such a standard exists," he said.
Payments, push notifications and finer-grained permissions are listed as future extensions outside v0.1, so the first spec covers identity and coarse read/write scope only. An agent using it cannot pay you.
Why Meta Needed It: Amazon Shut the Other Door
PAP is Meta's answer to the dispute that started three weeks before the launch. Meta released its Muse consumer agent on September 8, and Amazon blocked it from shopping on Amazon.com on September 20, 12 days later. Amazon said Meta gave no notice that Muse would access the store, that the agent did not identify itself while browsing, and that it appeared to capture and store customer credentials. Meta answered that "Muse has no visibility into people's passwords or payment methods" because credentials go into secure storage and are inserted into the browser without the agent seeing them. Nobody has independently verified either claim. We covered the legal side of that fight in Amazon Blocks Meta's Muse Agent Where the Perplexity Ruling Stops.
Muse reached the top of Apple's US free iPhone chart by September 18, according to the same report. That is the strongest argument for taking PAP seriously: the agent your customers are installing needs a sanctioned way in, and the alternative is a browser in a cloud VM typing your customers' passwords into your login page. Every business Muse touches without a protocol faces the same question Amazon answered with a block.
PAP turns the credential fight into an OAuth consent screen. The customer signs in on your page, grants a scope, and you see an agent arriving as an agent. That fixes Amazon's first two complaints, notice and self-identification, by design.
Four Standards Now Compete for the Same Front Door
PAP joins three standards that already cover overlapping ground, and most of its partners sit in at least one of them.
| Standard | Backers | Published | What it covers |
|---|---|---|---|
| Personal Agent Protocol | Meta, Sierra, Walmart, Shopify, Stripe, Genesys, Rocket, Instinct | Announced Oct 6, 2026; no spec yet | Agent sign-in via OAuth, channel choice, guest vs signed-in, read vs write |
| Universal Commerce Protocol (UCP) | Google, Shopify; council adds Amazon, Meta, Microsoft, Salesforce, Stripe | Jan 11, 2026 | Discovery, cart, checkout, post-purchase |
| Agentic Commerce Protocol (ACP) | OpenAI, Stripe | Sept 29, 2025 | Checkout inside the agent, scoped payment tokens |
| Trusted Agent Protocol (TAP) | Visa, Cloudflare | Oct 14, 2025 | Signed agent identity, consumer recognition, payment data |
Google and Shopify launched UCP at NRF in January with Etsy, Wayfair, Target and Walmart as co-developers, and it already works alongside MCP, A2A and Google's AP2 payments protocol. On April 24, Amazon, Meta, Microsoft, Salesforce and Stripe joined the UCP Tech Council, taking it to ten seats. Meta, Shopify and Stripe are therefore inside both UCP's governing body and PAP's partner list, and Walmart co-developed UCP. We wrote up that council expansion in Google UCP Beats OpenAI Protocol: Microsoft, Amazon, Meta Adopt.
OpenAI and Stripe released ACP in September 2025 to power Instant Checkout in ChatGPT. Its central piece is the Shared Payment Token, which is scoped to a specific merchant and cart total so the agent never holds the card. Visa's Trusted Agent Protocol does something closer to PAP's identity job: an approved agent signs its requests with HTTP Message Signatures, aligned with Web Bot Auth, and passes agent intent, consumer recognition and payment data to the merchant. Microsoft, Shopify, Stripe and Worldpay are among the companies Visa lists as early contributors. Web Bot Auth itself is built on IETF RFC 9421, so it already has standards-track footing that PAP does not.
The overlap tells you something about vendor behaviour. Stripe and Shopify, the two companies most of your checkout runs through, are involved in every one of these efforts. They are hedging, and a business that backs PAP alone ends up betting against the companies that move its money.
Where PAP Is Weaker Than It Looks
The case against building now rests on three gaps, each of them stated by the sponsors or by close readers of the launch.
There is nothing to implement. The v0.1 text is not out, there is no reference implementation yet (Sierra has promised one, along with design workshops), and there is no licence. Until a licence and governing body exist, "open" is a stated intention.
The ownership question is open. One skeptical analysis puts it bluntly: "Whoever writes the lock decides who walks through it." The same piece proposes a test: by January 2027, a non-Meta consumer agent should complete authorized transactions with businesses that are not Sierra customers, with no sponsor-controlled registry and no allowlist. That is a sensible bar for your own adoption decision too.
The coalition is narrow. OpenAI and Anthropic, whose assistants your customers also use, are absent. Taylor said he expected them to take part and would be "really disappointed" if they did not, but neither has signed on. The Next Web noted that no European retailers, banks or payment companies are named; Stripe, with headquarters in San Francisco and Dublin, is the only partner with a European base.
The steel-man for moving early is real, though. Sierra already sells customer-service agents to consumer businesses, and Meta controls the most-installed new consumer agent. If PAP ships a usable v0.1 and Sierra customers get it as a switch in their existing deployment, the cost of joining could be close to zero for those companies. For everyone else, the decisions below are the same whichever standard wins.
The Decision That Survives Any Standard: Your Permission Tiers
Every one of these protocols needs the same answer from you: what an unauthenticated agent may see, what a signed-in agent may read, and what it may change. Write that matrix now and it ports to PAP, UCP or TAP with little rework. This is the same least-privilege design problem we covered in Agent Authorization: Standing Privilege Is the Whole Problem, pointed outward at your customers' agents instead of inward at your own.
A workable first cut for a retailer or bank:
- Guest, read. Store hours, stock, return policy, published rates, product specs. Mostly data you already publish to search engines, so the risk is low.
- Signed-in, read. Order status, order history, balances, appointment times. This tier is where a credential-scraping agent causes harm today, so moving it behind OAuth with a scoped token is a security improvement.
- Signed-in, write, reversible. Start a return, reschedule a delivery or appointment, update a notification preference. Each action can be undone and logged.
- Signed-in, write, irreversible. Purchases, transfers, address changes, beneficiary changes. Keep this closed until payments arrive in a later PAP version, and even then require a step-up confirmation from the human. Our human-in-the-loop buyer's guide covers which approval designs actually get read.
The channel choice follows from the matrix. Guest reads work fine on your website. Signed-in reads and reversible writes belong on an API, which you can expose over MCP or OpenAPI and which gives you per-call logs. Anything that needs judgment, such as a disputed charge or an exception to a return window, goes to your own agent, where your policies and your escalation path already live.
That last route lands on the contact centre. CMSWire points out that when an agent cannot finish a task on the web it falls back to calling the support line or opening a chat, which is why Genesys Cloud joined. Genesys CEO Tony Bates said brands need "a trusted way to know who an AI agent represents, what it's authorized to do, its intent, and how to work with it securely." If your contact centre cannot currently tell an agent caller from a human one, that gap exists with or without PAP.
What to Do Before the v0.1 Spec Ships
This Week:
- Pull last month's traffic and login logs and count sessions from known agent infrastructure, including cloud VM ranges and signed Web Bot Auth requests. You need a baseline before you set a policy.
- Ask your digital, security and contact-centre leads one question in writing: if Muse, ChatGPT or Gemini arrived as a signed-in agent tomorrow, which tier from the list above would we allow?
This Month:
- Write the four-tier permission matrix for your top ten customer tasks, with an owner for each tier. Get legal to sign off on tier 4 staying closed.
- Map which of your vendors already sit in which standard. If your commerce platform is Shopify and your processor is Stripe, you will likely get UCP, ACP and PAP support through them without building anything yourself.
- If you are a Sierra customer, ask your account team for the v0.1 date, the licence it will ship under and whether PAP support will carry extra cost.
Before You Build:
- Read the v0.1 text when it lands and check three things: a published licence, a governing body that Meta and Sierra do not control alone, and at least one non-Meta agent committed to implementing it.
- Build the API tier first, on OAuth scopes that map to your matrix. That work transfers to whichever protocol wins. Treat a PAP-specific integration as a thin adapter on top.
The Bottom Line
The last time consumer identity fragmented like this, a handful of social login buttons fought over the same sign-in page, and the companies that came out cleanest were the ones that had a clean internal account model and treated each button as an adapter. Agent access is following the same path, with four specs and overlapping coalitions instead of three buttons. PAP may become the sign-in layer, or UCP may absorb its job, since Meta already sits on that council. Your permission matrix and your OAuth scopes are useful either way.
Write the four tiers this month, and wait for a licence before you write PAP code.
Continue Reading
- Amazon Blocks Meta's Muse Agent Where the Perplexity Ruling Stops
- Google UCP Beats OpenAI Protocol: Microsoft, Amazon, Meta Adopt
- Agent Authorization: Standing Privilege Is the Whole Problem
- Okta vs Entra Agent ID vs SailPoint: Two Issue, One Governs
- Visa's 4-Protocol Bet: AI Agents and the $5T Market
- OpenAI's Hosted Browser Agent Asks Once Per Site, Not Per Purchase
