Update (2026-10-07): Rechecked the launch sources and 2026-10-07 coverage, removed unsupported protocol details, and kept only documented behavior.
Personal Agent Protocol (PAP) is an open standard from Sierra and Meta for letting an AI agent interact with a business through one OAuth-backed session. Sierra announced it on 2026-10-06 with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. The v0.1 specification is planned for later in October 2026, so runnable details are not published.
Key facts about Personal Agent Protocol
- Sierra's 2026-10-06 announcement names Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart as industry partners and says anyone can implement the protocol.
- Sierra says it plans to publish the v0.1 specification later in October 2026, then host design workshops and publish a reference implementation.
- The Next Web reported on 2026-10-07 that sessions use OAuth, can start as a guest, and can move to customer-approved read-only or write access after sign-in.
- Sierra describes one session crossing channels: a guest question and an authenticated order change remain part of the same visit.
- Sierra lists payment extensions and push notifications as future possibilities, not as published v0.1 features.
- Meta Muse's payment flow is separate: the user approves a Stripe Link spend request, and the agent does not receive the user's underlying card details.
How does Personal Agent Protocol connect an agent to a business?
Personal Agent Protocol starts on a business website. The agent discovers what the company offers and begins a session for the user. A guest session can handle questions about product availability or returns. When account access is needed, the customer signs in on the company's page or uses credentials already configured with the personal agent. Sierra's announcement describes this flow.
The customer chooses whether the personal agent gets read-only or write access. The business separately sets the actions and connection methods it allows. Sierra summarizes the split this way:
"Consumers decide what access to give their personal agents, and companies set parameters for what those agents can do."
The OAuth session carries across the interaction. The business can route the personal agent through one of three paths:
- Website navigation: the agent uses the business's regular pages and forms.
- Structured APIs: the agent connects through interfaces built on standards such as MCP and OpenAPI. For nearby browser and CLI examples, see WebMCP reaches the browser agent. A remote MCP reaches the CLI..
- Company agent: the personal agent works through the business's own conversational agent for a task such as a warranty claim.
The company decides which path it exposes. PAP's proposed session gives the customer and business separate control over access and permitted actions.
What can a Personal Agent Protocol session do before the October 2026 v0.1 specification?
As of 2026-10-07, developers can read the proposed flow but cannot build against a published PAP v0.1 endpoint. Sierra still described the specification and reference implementation as future releases, and The Next Web's 2026-10-07 report also described v0.1 as due later in October 2026.
In practical terms, PAP is a design for a permissioned business session, not a stable developer API available on 2026-10-07. The website, API, and company-agent routes describe how a participating business may handle a request. They do not provide a published set of PAP endpoints that an outside developer can call on 2026-10-07.
Payments are also outside the published v0.1 scope. Sierra describes payment support as a future extension. That differs from the Meta Muse purchase path documented on 2026-10-06: the related payment report says Muse gets a user-approved Link spend request, then uses a one-time card or Link Pay Token without exposing the user's normal card number to the agent. Push notifications for events such as flight delays or shipped orders are also future possibilities in Sierra's announcement.
How does Personal Agent Protocol compare with payment and request standards?
Personal Agent Protocol covers customer-agent authorization and business routing. The neighboring standards below cover narrower parts of the interaction.
Standard | Layer | Status on 2026-10-07 |
|---|---|---|
Personal Agent Protocol | OAuth-backed customer session across a website, APIs, or a company agent | v0.1 planned for later in October 2026 |
Visa Trusted Agent Protocol | Agent-assisted checkout and payment connections | The Next Web reported in June 2026 that Visa connected it to ChatGPT and that Microsoft, Stripe, Shopify, and Worldpay had joined |
Web Bot Auth | Signed HTTP requests and a published key directory | Request identity, not customer permission; see the Web Bot Auth explainer |
The Visa comparison needs a narrow reading. Stripe and Shopify appear in both efforts, but the sources describe different jobs. PAP proposes a session that starts with discovery and authorization. Visa's protocol is about agent-assisted commerce and payment. Web Bot Auth addresses whether a request matches a published signing key. It does not establish that the agent represents a consenting customer. See A Web Bot Auth signature names a key directory, not a person you should auto-publish for that boundary.
The useful mental model on 2026-10-07 is simple. PAP is an announced framework for permissioned business sessions, not a published developer API and not a payment rail. The details that matter most, including token exchange, action limits, and payment authorization, remain open until the v0.1 specification is published.
Sources
- Introducing Personal Agent Protocol (read 2026-10-07)
- Sierra announces Personal Agent Protocol, an open standard for personal AI agents (read 2026-10-07)
- Meta and Sierra Propose AI Agent Rules: Customers Grant Access, Businesses Set Limits (read 2026-10-07)
- How Meta Muse and Stripe Link handle autonomous purchases (read 2026-10-07)
- How AI agents sign HTTP requests with Web Bot Auth (read 2026-10-07)
- A Web Bot Auth signature names a key directory, not a person you should auto-publish (read 2026-10-07)
- WebMCP reaches the browser agent. A remote MCP reaches the CLI. (read 2026-10-07)
Last verified: 2026-10-07.