# Personal Agent Protocol Glossary: PACT, MCP, UCP, ACP, TAP

> Plain definitions for Personal Agent Protocol terms (guest session, read-only, write, routes) and the related agent protocols: PACT, MCP, A2A, UCP, ACP, TAP, Web Bot Auth.

Source: https://pap.md/docs/glossary.html

Last checked against sources: Oct 8, 2026

# Glossary

Definitions follow the Sierra and Meta announcement of October 6, 2026. The v0.1 specification is not published yet, so this glossary does not invent endpoint paths or scope names.

## Core concepts

### PAP (Personal Agent Protocol)

An open standard Sierra and Meta are developing with industry partners. It defines how personal agents interact with businesses: authentication, what consumers allow, and what companies can see agents do through websites, APIs, or company agents. Anyone can implement it.

### Personal agent

An AI agent that acts for a person. The announcement's examples of tasks include scheduling appointments, booking flights, and shopping for insurance. Meta's Muse is the consumer agent discussed alongside the launch.

### Muse

Meta's personal agent, launched September 8, 2026. Amazon blocked it from Amazon.com on September 20. It's the agent most of the PAP coverage is really about.

### Company agent

An agent operated by the company. A personal agent can use it for tasks that need conversation, such as a warranty claim.

## Session and access

### Discovery

The personal agent starts on the company's website and finds what the company offers and how to reach it. A specific discovery URL has not been published.

### Guest

A session that has not signed in to the customer account. It may be enough to check product availability or ask about a returns policy.

### OAuth

The established standard PAP uses to authorize access. The customer signs in on the company's page or uses credentials already set up with the personal agent.

### Read-only access

The customer can grant the agent access that does not change the account. Named scopes such as `orders:read` are not in the announcement.

### Write access

The customer can grant the agent access that can change the account. The announcement's example of a later action in the same visit is an order change.

### Session

The OAuth visit between the agent and the company. It carries across channels, so a question before sign-in and a change afterward belong to the same visit.

## Routes

### Route

A way the company lets the personal agent finish the task. The company chooses the route it believes is best for the customer.

- **Website:** the company's regular web pages
- **APIs:** interfaces on standards such as MCP and OpenAPI
- **Company agent:** conversational tasks, such as a warranty claim

### OpenAPI

A standard way to describe an HTTP API. The other API standard the announcement names.

## Related protocols

### MCP (Model Context Protocol)

Anthropic's protocol for AI apps to call tools and read data through servers. PAP names it as one of the API routes a company can offer, so it doesn't replace MCP.[PAP vs MCP →](/compare/pap-vs-mcp)

### A2A (Agent2Agent)

A protocol for agents from different vendors to exchange tasks, started by Google. Not named in the PAP announcement. [PAP vs A2A →](/compare/pap-vs-a2a)

### PACT (Personal Agent Consent & Trust Protocol)

Decagon's protocol, open-sourced with Instinct on the day PAP was announced. Built on A2A and OAuth 2.0, it separates an agent's identity from its authority to act on an account.[PAP vs PACT →](/compare/pap-vs-pact)

### UCP (Universal Commerce Protocol)

Google's open protocol for agent shopping, from discovery through checkout and after. Announced January 11, 2026. [PAP vs UCP →](/compare/pap-vs-ucp)

### ACP (Agentic Commerce Protocol)

OpenAI and Stripe's checkout protocol, behind Instant Checkout in ChatGPT. Released September 29, 2025. [PAP vs ACP →](/compare/pap-vs-acp)

### TAP (Trusted Agent Protocol)

Visa and Cloudflare's protocol for proving an agent's identity by signing its HTTP requests.[PAP vs TAP →](/compare/pap-vs-tap)

### Web Bot Auth

An IETF draft, led by Cloudflare, for bots and agents to sign HTTP requests using HTTP Message Signatures (RFC 9421). TAP builds on it.

## Participants

### Customer

The person who decides what access to give their personal agent. They want speed, dependability, and an agent that acts in their interest.

### Company

The business that sets parameters for what agents can do, and which routes exist. Companies want to know when a personal agent is acting for a customer.

### Agent builder

A company building personal agents. They want a direct, consistent way to work with participating companies.

## Announced next, not shipping yet

### More detailed permissions

A possible later feature: customers and companies set limits on specific actions.

### Push notifications

A possible later feature: the company tells the personal agent when a flight is delayed or an order ships.

### Payment extensions

A possible later feature: the agent completes a purchase without sharing credit card information.

## See also

- [Protocol overview](/docs/overview)
- [Core architecture](/docs/architecture)
- [Partners](/ecosystem/partners)
- [Agent protocol map](/compare)
- [FAQ](/faq)

## Sources

- [Introducing Personal Agent Protocol](https://sierra.ai/blog/introducing-personal-agent-protocol) · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- [Introducing the Personal Agent Consent & Trust Protocol (PACT)](https://decagon.ai/blog/introducing-the-personal-agent-consent-trust-protocol-pact) · Decagon, Oct 6, 2026 · primary source
- [Model Context Protocol](https://modelcontextprotocol.io) · modelcontextprotocol.io · primary source
- [Agent2Agent (A2A) Protocol](https://a2a-protocol.org) · a2a-protocol.org · primary source
- [Under the Hood: Universal Commerce Protocol (UCP)](https://developers.googleblog.com/en/under-the-hood-universal-commerce-protocol-ucp/) · Google Developers Blog · primary source
- [Stripe powers Instant Checkout in ChatGPT and releases Agentic Commerce Protocol codeveloped with OpenAI](https://stripe.com/newsroom/news/stripe-openai-instant-checkout) · Stripe, Sep 29, 2025 · primary source
- [Getting Started with Visa's Trusted Agent Protocol](https://developer.visa.com/capabilities/trusted-agent-protocol/docs-getting-started) · Visa Developer · primary source

pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.
