Personal Agent Protocol is an OAuth session, but its v0.1 specification is not published

PAP uses one OAuth session across web, API, and company-agent routes, but its v0.1 specification and payment extensions are not published.

Update (2026-10-07): Rechecked the launch sources and 2026-10-07 coverage, removed unsupported protocol details, and kept only documented behavior.

Personal Agent Protocol (PAP) is an open standard from Sierra and Meta for letting an AI agent interact with a business through one OAuth-backed session. Sierra announced it on 2026-10-06 with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. The v0.1 specification is planned for later in October 2026, so runnable details are not published.

Key facts about Personal Agent Protocol

How does Personal Agent Protocol connect an agent to a business?

Personal Agent Protocol starts on a business website. The agent discovers what the company offers and begins a session for the user. A guest session can handle questions about product availability or returns. When account access is needed, the customer signs in on the company's page or uses credentials already configured with the personal agent. Sierra's announcement describes this flow.

The customer chooses whether the personal agent gets read-only or write access. The business separately sets the actions and connection methods it allows. Sierra summarizes the split this way:

"Consumers decide what access to give their personal agents, and companies set parameters for what those agents can do."

The OAuth session carries across the interaction. The business can route the personal agent through one of three paths:

  1. Website navigation: the agent uses the business's regular pages and forms.
  2. Structured APIs: the agent connects through interfaces built on standards such as MCP and OpenAPI. For nearby browser and CLI examples, see WebMCP reaches the browser agent. A remote MCP reaches the CLI..
  3. Company agent: the personal agent works through the business's own conversational agent for a task such as a warranty claim.

The company decides which path it exposes. PAP's proposed session gives the customer and business separate control over access and permitted actions.

What can a Personal Agent Protocol session do before the October 2026 v0.1 specification?

As of 2026-10-07, developers can read the proposed flow but cannot build against a published PAP v0.1 endpoint. Sierra still described the specification and reference implementation as future releases, and The Next Web's 2026-10-07 report also described v0.1 as due later in October 2026.

In practical terms, PAP is a design for a permissioned business session, not a stable developer API available on 2026-10-07. The website, API, and company-agent routes describe how a participating business may handle a request. They do not provide a published set of PAP endpoints that an outside developer can call on 2026-10-07.

Payments are also outside the published v0.1 scope. Sierra describes payment support as a future extension. That differs from the Meta Muse purchase path documented on 2026-10-06: the related payment report says Muse gets a user-approved Link spend request, then uses a one-time card or Link Pay Token without exposing the user's normal card number to the agent. Push notifications for events such as flight delays or shipped orders are also future possibilities in Sierra's announcement.

How does Personal Agent Protocol compare with payment and request standards?

Personal Agent Protocol covers customer-agent authorization and business routing. The neighboring standards below cover narrower parts of the interaction.

Standard

Layer

Status on 2026-10-07

Personal Agent Protocol

OAuth-backed customer session across a website, APIs, or a company agent

v0.1 planned for later in October 2026

Visa Trusted Agent Protocol

Agent-assisted checkout and payment connections

The Next Web reported in June 2026 that Visa connected it to ChatGPT and that Microsoft, Stripe, Shopify, and Worldpay had joined

Web Bot Auth

Signed HTTP requests and a published key directory

Request identity, not customer permission; see the Web Bot Auth explainer

The Visa comparison needs a narrow reading. Stripe and Shopify appear in both efforts, but the sources describe different jobs. PAP proposes a session that starts with discovery and authorization. Visa's protocol is about agent-assisted commerce and payment. Web Bot Auth addresses whether a request matches a published signing key. It does not establish that the agent represents a consenting customer. See A Web Bot Auth signature names a key directory, not a person you should auto-publish for that boundary.

The useful mental model on 2026-10-07 is simple. PAP is an announced framework for permissioned business sessions, not a published developer API and not a payment rail. The details that matter most, including token exchange, action limits, and payment authorization, remain open until the v0.1 specification is published.

Sources

Last verified: 2026-10-07.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.