PAP vs MCP: does the Personal Agent Protocol replace MCP?
Short answer: no. The PAP announcement names MCP as one of the ways a business can let an agent in. They sit on different floors of the same building.
| PAP | MCP | |
|---|---|---|
| Question it answers | Who is this agent acting for, and what may it do? | What tools and data can this AI app use? |
| Created by | Sierra and Meta, with partners | Anthropic |
| Spec status | Not published (v0.1 due Oct 2026) | Published |
| Auth | OAuth session chosen by the customer | OAuth-based authorization for remote servers |
| Relationship | Names MCP as an allowed API route | Doesn’t reference PAP |
| First public | Oct 6, 2026 | Nov 2024 |
What each one does
MCP, which Anthropic introduced in November 2024, is a way for an AI application to call tools and read data through a server. It says nothing about which customer the agent represents. That was never its job.
PAP starts one step earlier. Before any tool gets called, a business wants to know that this is a personal agent, which customer sent it, and whether that customer allowed reading or writing. The October 6 post describes exactly that: an OAuth session, guest or signed in, read-only or write.
Where they meet
Sierra lists three routes a company can offer once a session exists: its website, its APIs ("such as MCP and OpenAPI") and its own agent. So an MCP server is a valid destination inside a PAP visit.
The part nobody can answer yet is the handoff. MCP has its own authorization rules for remote servers, built on OAuth. PAP is also built on OAuth. Whether the PAP session token simply becomes the MCP credential, or something sits in between, is the kind of detail v0.1 has to settle.
Our read
If you already run an MCP server for your product, you’re not starting from zero. What you probably don’t have is the consent piece: a way for a customer to say "this agent may read my orders but not change them" and for your server to honour it. That’s the gap PAP is aiming at.
Quick answers
Does PAP replace MCP?
No. The PAP announcement lists MCP as one of the API standards a business can expose to a personal agent.
Do I need an MCP server to support PAP?
No. A company can also offer its regular website or its own agent. MCP and OpenAPI are the two API options named so far.
Is Anthropic part of PAP?
Not as of October 8, 2026. Anthropic isn’t on either partner list.
Other comparisons
- All agent protocols in one table
- PAP vs A2A (Agent2Agent)
- PAP vs UCP (Universal Commerce Protocol)
- PAP vs ACP (Agentic Commerce Protocol)
- PAP vs TAP (Trusted Agent Protocol)
- PAP vs PACT (Personal Agent Consent & Trust Protocol)
Sources
- Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- Model Context Protocol · modelcontextprotocol.io · primary source
- Meta joins with group of companies to tame 'chaos' of doing business with AI bots · CNBC, Oct 6, 2026
pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.