Personal Agent Protocol:
what's announced,
what's still missing.
The Personal Agent Protocol (PAP) is an open standard Sierra and Meta announced on October 6, 2026. It sets out how your AI agent signs in to a business and acts for you. You choose read-only or write. The business chooses the route. The spec itself isn't out yet.
pap.md is an independent tracker, not affiliated with Sierra, Meta or the partners. We log every partner, date and claim with its source, and we'll annotate v0.1 the day it ships.
The customer picks access
Read-only or write. That’s the whole menu for now; finer limits are on the "later" list.
Sessions run on OAuth
Sign in on the company’s own page, or use credentials already set up with the agent. A guest visit is fine for stock checks.
The business picks the route
Its website, an API such as MCP or OpenAPI, or its own agent when the job needs a conversation.
PAP in ten lines
Everything here comes from Sierra's post or named coverage. If it isn't sourced, it isn't on the list. Checked Oct 8, 2026.
How we got here: the timeline- Full name
- Personal Agent Protocol (PAP)
- Announced
- October 6, 2026, at Sierra Summit, San Francisco
- Created by
- Sierra (Bret Taylor, Clay Bavor) and Meta
- What it covers
- How a personal AI agent signs in to a business and what it may do there
- Auth
- OAuth sessions; guest or signed in
- Access levels
- Read-only or write, chosen by the customer
- Routes
- Company website, APIs (MCP, OpenAPI), or the company’s own agent
- Spec
- v0.1 promised for later in October 2026, not published yet
- Not covered yet
- Payments, push notifications, finer permissions
- Not participating
- OpenAI, Anthropic, Google, Amazon
How the Personal Agent Protocol works
You, your agent and the company share one visit. Here's the flow from Sierra's post, minus anything the spec hasn't confirmed.
Discover on the site
The agent finds what the company offers and how to reach it. A guest session can check stock or a returns policy.
You choose access
If the task needs your account, you sign in. You decide read-only or write. The visit stays the same.
The company picks a route
Website pages, an API such as MCP or OpenAPI, or the company’s own agent.
Built on OAuth, details pending
Sierra says the session is built on OAuth. What it hasn't said yet: the discovery format, scope names, token rules. Those wait for v0.1, and so do we.
See the architectureWhere PAP fits next to MCP, A2A, UCP, ACP, TAP and PACT
Agents already have a protocol for tools, one for talking to each other, two for shopping and one for proving who they are. PAP adds the customer's permission. Here's where each one ends.
PAP vs MCP
Low overlapModel Context Protocol · Anthropic
Tools and data an AI app can call
Read the comparisonPAP vs A2A
Some overlapAgent2Agent · Google, now a Linux Foundation project
How two agents talk to each other
Read the comparisonPAP vs UCP
Some overlapUniversal Commerce Protocol · Google, with Shopify and retailers
The shopping flow: discovery, checkout, after-sale
Read the comparisonPAP vs ACP
Some overlapAgentic Commerce Protocol · OpenAI and Stripe
In-agent checkout and payment tokens
Read the comparisonPAP vs TAP
High overlapTrusted Agent Protocol · Visa and Cloudflare
Proving an agent’s identity on each request
Read the comparisonPAP vs PACT
High overlapPersonal Agent Consent & Trust Protocol · Decagon and Instinct
Agent identity and customer authority, agent-to-agent
Read the comparisonTwo announcements, two partner lists
Sierra and Meta didn't publish the same names. Seven appear on both. Instinct is only on Sierra's list; NiCE and Decagon are only on Meta's.
| Company | Role | Sierra post | Meta post |
|---|---|---|---|
| Sierra | Co-creator | ||
| Meta | Co-creator | ||
| Genesys | Launch partner | ||
| Rocket Companies | Launch partner | ||
| Shopify | Launch partner | ||
| Stripe | Launch partner | ||
| Walmart | Launch partner | ||
| Instinct | Launch partner | ||
| NiCE | Partner | ||
| Decagon | Working group |
Not on either list: OpenAI, Anthropic, Google, Amazon. Meta's list as reported by CMSWire.
Questions people keep asking
Is the PAP specification published?+
Not as of Oct 8, 2026. Sierra said v0.1 would come "later this month", meaning October 2026, followed by design workshops and a reference implementation.
Are OpenAI, Anthropic, Google or Amazon part of PAP?+
No. None of them is on either partner list. Bret Taylor, who also chairs OpenAI’s board, told CNBC he expects OpenAI and Anthropic to take part and would be "really disappointed" if competitors didn’t use it.
Does PAP handle payments?+
Not in the announced first version. Payment extensions, letting an agent buy without sharing card details, are listed as a possible later step.
Does PAP replace MCP?+
No. The announcement names MCP and OpenAPI as API routes a company can offer inside a PAP session.
Building for agents before the spec lands?
Don't code against guessed endpoints. Start with what's actually been announced, and check the tracker. We'll publish an annotated read of v0.1 the day it goes live.