Last checked against sources:

How the Personal Agent Protocol works

A PAP visit starts on the company's website. The agent can stay a guest or the customer signs in through OAuth and picks read-only or write. Then the company decides how the agent finishes the job: its website, its APIs or its own agent.

Spec not published. Sierra and Meta plan to publish v0.1 later in October 2026. This page describes the model in the October 6 announcement. It does not invent endpoints, scope names, or token rules that the spec has not defined.

One visit

Three parties share the visit: the customer, their personal agent, and the company. The session is built on OAuth.

One Personal Agent Protocol visit Four steps from the October 6, 2026 announcement. 1 Discover: the personal agent starts on the company website and finds what is offered and how to connect. 2 Guest: no sign-in needed to check stock or ask about returns. 3 Sign in with OAuth, only if the task needs the account, on the company page or with credentials already set up with the agent. 4 The customer chooses read-only or write access. All four are one OAuth session that carries across channels. One PAP visit Four steps, one session. As described in the October 6, 2026 announcement. 1 Discover AGENT Starts on the company’s website and finds what’s offered and how to connect. 2 Guest AGENT No sign-in needed to check stock or ask about a returns policy. 3 Sign in CUSTOMER Only if the task needs the account. OAuth, on the company’s page or with credentials already set up with the agent. 4 Pick access CUSTOMER The customer decides how far the agent can go: Read-only Write One OAuth session, across channels A question asked before sign-in and an order change made after it count as the same visit. Source: Sierra, “Introducing Personal Agent Protocol”, Oct 6, 2026. Diagram: pap.md (independent).
One visit, four steps, one OAuth session. PNG

1. Discover

The agent finds, on the company's website, what the company offers and how to reach it. The announcement does not name a discovery file or URL.

2. Start a session

The agent begins a session for the user. It can start as a guest. That can be enough to check product availability or ask about a returns policy.

When the task needs the customer's account, the customer signs in on the company's page or uses credentials already set up with the personal agent.

3. Choose access

The customer stays in control and decides whether the agent has:

  • Read-only access
  • Write access

Limits on specific actions are a later idea, not part of the announced v0.1 model.

4. Keep one visit

The OAuth session carries across channels. A question asked before sign-in and an order change made afterward are part of the same visit.

Three routes

After the session exists, the agent uses whichever route the company believes will offer the best customer experience. The company decides what it makes available.

The company picks the route A personal agent with read-only or write access reaches the company. The company decides what agents may do and offers one of three routes named in the announcement: its regular website, its APIs on MCP or OpenAPI, or its own agent for tasks that need a conversation, like a warranty claim. The company picks the route Three routes named in the announcement. The company offers the one it thinks serves the customer best. Personal agent Acts for the customer, with the access they granted. Read-only or write Company Sets what agents may do and which routes exist. Website The company’s regular web pages. APIs The two standards the announcement names: MCP OpenAPI The company’s own agent For tasks that need a conversation, like a warranty claim. Not in the first version: payments, push notifications and finer permissions are listed as possible later steps. Source: Sierra, “Introducing Personal Agent Protocol”, Oct 6, 2026. Diagram: pap.md (independent).
Website, APIs or the company’s own agent. The company decides which it offers. PNG

Website

The agent navigates the company's regular web pages.

APIs

The agent connects through interfaces built on standards such as MCP andOpenAPI. Those are the two standards the announcement names.

Company agent

The agent works through the company's own agent when the task needs conversation. The announcement's example is a warranty claim.

What each party gets

PartyDecidesGets
CustomerWhat access the agent receivesA faster way to finish the task
CompanyParameters and which routes existVisibility into an agent acting for a customer
Agent builderHow the agent uses the offered routesOne consistent way to connect

Planned, not in the first cut

Sierra and Meta described these as possible next steps, alongside the v0.1 spec, design workshops, and a reference implementation:

  • More detailed permissions — customers and companies set limits on specific actions
  • Push notifications — a company tells the agent when a flight is delayed or an order ships
  • Payment extensions — the agent completes a purchase without sharing credit card information

Next

Sources

  1. Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source

pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.