Last checked against sources:

Getting your business ready for personal agents

You can't implement PAP yet because there's no spec. You can still do most of the groundwork, since the announcement already tells you the shape: a guest mode, OAuth sign-in, a read/write split, and three routes you get to pick from.

This checklist sticks to that shape. Anything that depends on details v0.1 hasn't defined is flagged as such. Treat it as a starting point for your own team's review, not as security or legal advice.

1. Find out who's already visiting

Personal agents aren't waiting for a standard. Muse launched on September 8, 2026. By September 20 Amazon was blocking it, saying the agent didn't identify itself. Before you plan for agents, check your logs and support queues for the ones you already have.

2. Decide what a guest agent can see

Sierra's examples for a guest session are product availability and returns policies. Make sure that information is easy to read on your site without signing in. That's useful for agents today, whatever v0.1 says.

3. Sort your account actions into read and write

Read-only or write is the only split PAP has announced. List what an agent might do on a customer account (see orders, track a delivery, change an address, cancel, reorder) and put each one in a column. Some won't fit neatly. That's worth knowing now, because finer permissions are only on the "later" list.

4. Check your sign-in can authorize a third party

Sessions run on OAuth, and the customer signs in on your page or uses credentials already set up with their agent. If your login can't grant scoped access to an outside app today, that's the biggest piece of work on this list.

5. Pick your route

RouteGood fit whenWhat you'd need
WebsiteYou don't want to build anything new yetPages an agent can actually use: clear forms, stable markup
APIsYou already have an API or an MCP serverAn MCP server or an OpenAPI description, the two standards Sierra names
Your own agentTasks need back-and-forth, like a warranty claimA customer-facing agent that can take requests from other agents

6. Keep payments out of scope for now

Payments are a future PAP extension. If agents need to check out today, look at what's already live: ACP with Stripe, UCP from Google, or Visa's TAP.See how they compare →

What not to do yet

  • Don't build against endpoint paths, discovery files or scope names you've seen in blog posts. None of them come from a published spec.
  • Don't treat PAP as the only door. OpenAI, Google and Amazon aren't part of it, and their agents will keep showing up.
  • Don't promise customers anything about agent liability or chargebacks. Nothing announced so far covers it.

When the spec lands

Sierra says design workshops and a reference implementation will follow v0.1. We'll update this checklist against the real spec and log the changes on the status page.

Sources

  1. Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
  2. Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec · BERI
  3. Meta joins with group of companies to tame 'chaos' of doing business with AI bots · CNBC, Oct 6, 2026
  4. Model Context Protocol · modelcontextprotocol.io · primary source

pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.