# What Is the Personal Agent Protocol (PAP)? A Sourced Guide

> The Personal Agent Protocol (PAP) is an open standard from Sierra and Meta for how personal AI agents sign in to businesses and act for customers. How it works, who's in, what's missing.

Source: https://pap.md/docs/overview.html

Last checked against sources: Oct 8, 2026

# What is the Personal Agent Protocol?

The Personal Agent Protocol (PAP) is an open standard for how a personal AI agent works with a business on a customer's behalf. Sierra and Meta announced it on October 6, 2026. Sessions run on OAuth, the customer picks read-only or write access, and the business decides which route the agent uses.

 No spec yet. v0.1 was promised for later in October 2026 and hadn't been published as of Oct 8, 2026. Everything below comes from the announcement. Spec status →

Not to be confused with the Password Authentication Protocol, the older networking PAP used with PPP.

## The problem it's aimed at

Today a personal agent uses a company's website the way you would. It loads pages, clicks through forms and, when it gets stuck, calls support or opens a chat window. It's slow, and it breaks whenever the site changes.

The business has its own problem: it can't tell a customer's agent from a scraper. Amazon's reason for blocking Meta's Muse in September was exactly that, an agent that didn't say who it was. Sierra's pitch is that a direct, agreed connection could finish the same task in seconds.

## Who wants what

The announcement frames PAP around three parties. Each one is after something different, and the protocol is supposed to give all three enough to show up.

### Customers

Speed, and a task done right the first time, by an agent that's working for them.

### Businesses

To know when an agent is acting for a real customer, and to decide what it may do.

### Agent builders

One direct, consistent way in, instead of a different workaround for every site.

## How a visit works

The rule of thumb from Sierra's post: customers decide what access their agent gets, and companies set the parameters for what agents can do. In practice:

- **Discover.** The agent starts on the company's website and finds what's offered and how to connect. No discovery file or URL has been named.
- **Start as a guest** when that's enough, say to check stock or a returns policy.
- **Sign in** when the task needs the account, on the company's own page or with credentials already set up with the agent.
- **Pick read-only or write.** The customer decides.
- **Finish on a route** the company offers: its website, its APIs (MCP and OpenAPI are the two named), or its own agent.

The session carries across channels, so a question asked before sign-in and an order change made afterward count as the same visit. [Diagrams and detail →](/docs/architecture)

## What PAP doesn't do yet

Sierra lists three ideas as possible later steps: finer permissions on specific actions, push notifications (a delayed flight, a shipped order) and payments without sharing card details. None is in the announced first version. If you need agent checkout today, that's ACP, UCP or TAP territory. [How they compare →](/compare)

## Who's behind it

Sierra is the AI customer-service company run by Bret Taylor and Clay Bavor. Taylor was Facebook's CTO, helped create the "log in with Facebook" style of sign-in, and now chairs OpenAI's board. Meta makes Muse, the personal agent that pushed this whole issue into the open.

10 organisations are named across the two announcements. Genesys, Rocket, Shopify, Stripe and Walmart are on both. Sierra adds Instinct; Meta adds NiCE and Decagon. OpenAI, Anthropic, Google and Amazon aren't on either list.[Full partner comparison →](/ecosystem/partners)

## Two comparisons the founders use

Taylor compares PAP to social sign-in, the "log in with Google or Facebook" flow he worked on. Meta's David Singleton, a former Stripe CTO, reaches for email instead: it works because anyone can use the standard to talk to anyone. Both analogies point the same way. Whether PAP gets there depends on the companies that aren't in the room yet.

### Spec status →

What was promised, what's shipped, and when we last checked.

### FAQ →

Short sourced answers to the questions people keep asking.

## Sources

- [Introducing Personal Agent Protocol](https://sierra.ai/blog/introducing-personal-agent-protocol) · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- [Meta joins with group of companies to tame 'chaos' of doing business with AI bots](https://www.cnbc.com/2026/10/06/meta-joins-companies-to-tame-chaos-of-doing-business-with-ai-bots.html) · CNBC, Oct 6, 2026
- [Genesys, NiCE Join Sierra, Meta on Open Standard for Personal AI Agents](https://www.cmswire.com/contact-center/genesys-joins-sierra-meta-on-open-standard-for-personal-ai-agents-01/) · CMSWire
- [Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec](https://www.beri.net/article/meta-sierra-personal-agent-protocol-oauth-guest-read-write-access-vs-ucp-acp-trusted-agent-protocol-retail-banks) · BERI

pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.
