Contact

Meta and Sierra Unveil Personal Agent Protocol: An OAuth-Based Standard for How Businesses Recognize and Welcome Personal AI Agents

How Meta and Sierra's Personal Agent Protocol (PAP) works: OAuth sessions, user-granted read or write access, and three entry points through websites, APIs and business agents. How it differs from UCP and ACP, and what e-commerce merchants can prepare now.

Meta and Sierra Unveil Personal Agent Protocol: An OAuth-Based Standard for How Businesses Recognize and Welcome Personal AI Agents

Key Takeaways

  1. On October 6, 2026, Meta and Sierra announced Personal Agent Protocol (PAP), an open standard for how personal AI agents interact with businesses. An OAuth session shows that the agent acts for a specific person, the user chooses read-only or write access, and the business decides whether to respond through its website, APIs or its own agent
  2. The backdrop is Amazon blocking Meta's Muse for not identifying itself, and six major banks calling for principles on transparency and safety. Unlike UCP and ACP, which define how purchases and payments flow, PAP covers the earlier layer of whom an agent represents and what it may do
  3. The v0.1 specification is due later in October, and Amazon, OpenAI and Anthropic are not participating. While the spec is pending, the practical move for merchants is to separate the tasks they will open to agents from those they will not, and to take stock of their customer login and APIs

A Standard for Signing In, Not Just Checking Out

Until now, standards for AI agents have mostly focused on the purchase flow and on how payment details are passed along. What Meta and Sierra have put forward sits one step earlier: a way to tell a business whom an agent represents and what it is allowed to do.

According to Sierra's announcement, Personal Agent Protocol (PAP) is an open standard that defines how personal agents interact with businesses. It is designed to handle authentication, empower consumers and give companies visibility into what personal agents do through their websites, APIs or company agents. Sierra says it is open for anyone to implement.

The effort is led by Sierra co-founder Bret Taylor, the former co-CEO of Salesforce, who is also chairman of OpenAI. He told CNBC that companies will be able to tell a personal agent from an actual person, and that there will be chaos until such a standard exists. Taylor compared it to logging into other sites with Facebook credentials, a technology he worked on as Facebook's tech chief.

The partner list differs slightly depending on who is announcing it. Sierra's blog names Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. Meta's business announcement names Genesys, NiCE, Decagon, Rocket, Shopify, Stripe and Walmart. On Meta's side, both its consumer agent Muse and its Meta Business Agent are involved.

How It Works: Start as a Guest, Let the User Set Permissions

The PAP flow begins when an agent visits a company's website. There it discovers what the company offers and how to reach it, and then starts a "session" on its user's behalf.

The agent can begin as a guest. Sierra says that is enough to check product availability or ask about a returns policy. When a task requires access to a customer's account, such as changing an order, the customer can sign in on the company's page or use credentials already set up with their personal agent. The customer decides whether the agent gets read-only or write access.

The session is built on OAuth, a widely used way to grant limited access to another service without handing over a password. In PAP, the session carries across channels, so a question asked before sign-in and an order change made afterward count as the same visit from the company's point of view.

Once the session is open, the company chooses how the agent gets the job done. There are three entry points.

  • Website: the agent navigates the company's regular web pages
  • APIs: the agent connects through interfaces built on standards such as MCP and OpenAPI
  • Company agent: tasks that need a conversation, such as a warranty claim, are handled with the company's own AI agent

MCP (Model Context Protocol) is a common standard for connecting AI to external tools, and OpenAPI is a standard format for describing APIs. Both already exist. What PAP adds is a shared front door that carries identity and permissions.

According to Meta, businesses will be able to point agents to a preferred path, along the lines of "use this connector for order tracking, check this source for inventory." Rather than letting agents find their way by trial and error, the business sets the route.

Why Now: Amazon's Block and the Banks' Demands

PAP is also Meta's answer to a pressing problem. Muse grew quickly after its September 8 launch, passing 3 million weekly users and 5 million downloads, according to Social Media Today. Then on September 20, Amazon blocked Muse from shopping on its site. According to GeekWire, Amazon objected that the agent did not identify itself while browsing and appeared to store customer credentials. We covered that dispute in detail in our article on Muse, Shop Pay and Amazon's block.

In its announcement, Meta acknowledged the concerns of businesses that block agents: load spikes, abuse, liability, and whether they can keep the customer relationship. It then argued that Muse acts only when a person asks it to, and that a person who is turned away experiences it as being unable to do business with that company. Turning away a personal agent means turning away the customer behind it, as Meta puts it.

Meta also published the norms Muse follows when browsing. It applies two tests: whether one honest person doing this by hand would do it this way and at this scale, and whether the system would still function if every agent did the same. It also seeks explicit user approval before signing in or making a purchase.

The other driver is the banks. On September 22, ASB, Bank of America, Capital One, Commonwealth Bank of Australia, ING and NatWest published a paper setting out principles for agentic commerce. Its five pillars are transparency, safety, privacy and data, choice, and interoperability (The Paypers). SiliconANGLE reads PAP as a response to that call.

How It Differs From UCP and ACP

There are already several standards for agents. Lining them up shows which layer PAP covers.

StandardLed byWhat it mainly definesRole from the merchant's side
Personal Agent Protocol (PAP)Meta, SierraWhom a personal agent represents and what it may do. OAuth sessions, and whether the business responds via website, API or its own agentRecognize customers' agents and decide which actions and entry points to allow
UCP (Universal Commerce Protocol)Google (with Shopify and others)The purchase flow itself: product search, cart and checkoutShow products and take orders inside AI surfaces
ACP (Agentic Commerce Protocol)OpenAI, StripeCheckout inside AI apps and the handoff of payment credentialsAccept orders from ChatGPT and similar apps
AP2 (Agent Payments Protocol)GoogleProof of the payment instructions (mandates) a user gives an agentConfirm that the user approved the payment
Visa TAP, Mastercard Agent PayVisa, MastercardSignatures that identify agents and payment tokens issued for agentsVerify legitimate agents and the validity of payments

UCP and ACP define the steps from choosing a product to buying it. AP2 and the card networks' frameworks confirm that a payment reflects the user's intent. PAP, by contrast, deals with access to the customer account itself, covering not only purchases but returns, support questions and order changes. News site Forkast likewise describes PAP as an interaction layer that sits above the settlement layer, leaving the payment itself to existing rails.

Because the layers differ, PAP does not necessarily compete with existing standards. Meta joined the UCP technical council in April. There is overlap, though. Visa's TAP (Trusted Agent Protocol) is also designed to help merchants recognize legitimate agents. Sierra also lists payments extensions that would let an agent complete a purchase without sharing card details as a possible next step. If PAP moves into payments, the division of roles with existing standards will come up again. For a map of all the layers, see our protocol comparison.

Who Is Missing, and What Is Still Undecided

The biggest gap, which the proponents' messaging glosses over, is that Amazon, OpenAI and Anthropic are not participating. According to CNBC, Taylor expects OpenAI and Anthropic to take part and said he would be "really disappointed" if competitors did not use it. Forkast argues that without these three, the standard's universal reach remains aspirational.

There is movement inside the coalition, too. Decagon, named in Meta's announcement, unveiled its own protocol, PACT (Personal Agent Consent & Trust), on October 1, five days before PAP, to let a person's agent act on their behalf. The goals are close, and it is not yet clear which approach will win out.

The specification itself is still to come. Sierra plans to publish the v0.1 specification later in October, host design workshops with interested parties and release a reference implementation for developers. Governance, licensing, membership terms, costs and the timing of Muse support have not been disclosed. Meta describes the announcement as a preview: the core parts are designed, and the details will be worked out in a working group.

Concerns about Muse itself also remain. SiliconANGLE points to reporting by 404 Media that Meta rushed to fix serious vulnerabilities just before launch. Building a standard and earning trust for the agents that use it are separate problems.

Even so, partners have high expectations. Genesys Chairman and CEO Tony Bates put it this way.

Brands need a trusted way to know who an AI agent represents, what it's authorized to do, its intent, and how to work with it securely.

What E-commerce Merchants Can Prepare Now

PAP is an attempt to offer a path other than blocking every agent or letting all of them through: the merchant sets the terms on which agents are welcomed. Even before the spec is out, there is work merchants can do.

Start by sorting tasks. Some can be answered for a guest, such as checking stock, tracking a shipment or explaining the returns policy. Others require the customer's account and write access, such as changing an order, filing a return or pausing a subscription. PAP's design assumes these are treated separately. Mapping which of your tasks fall into which group lets you decide permission scopes quickly once the spec lands.

Next, review your customer login and APIs. Because PAP uses OAuth, merchants whose customer accounts already support OAuth or OpenID Connect can build on what they have. Whether you can expose order lookups and inventory through APIs, or offer them via MCP, also shapes which entry points you can choose.

Customer service is worth a look as well. Because the third entry point is a company agent, contact center vendors such as Genesys are among the partners. Making your FAQs and return policies easy for AI to answer accurately will pay off whichever standard spreads.

Finally, make sure you can measure agent traffic and orders separately. Browser tags may not fire on orders placed through Muse, and seeing which agent did what on whose behalf is at the heart of what PAP promises.

Muse is currently available in the US, and its timing for Japan has not been disclosed.

Conclusion

PAP shows that standard-setting for AI agents has widened from how agents buy to whom they represent when they arrive. Meta and Sierra say they want shared rails anyone can use, like email, but if Amazon and OpenAI stay off, those rails will only connect part of the market.

The next things to watch are the contents of the v0.1 spec due in October and how far the partner list grows. Whether merchants get to set the terms for accepting agents will become clearer over the next few months.