Spec v0.1 not published · checked Oct 8, 2026

Personal Agent Protocol:
what's announced,
what's still missing.

The Personal Agent Protocol (PAP) is an open standard Sierra and Meta announced on October 6, 2026. It sets out how your AI agent signs in to a business and acts for you. You choose read-only or write. The business chooses the route. The spec itself isn't out yet.

pap.md is an independent tracker, not affiliated with Sierra, Meta or the partners. We log every partner, date and claim with its source, and we'll annotate v0.1 the day it ships.

Announced
Oct 6
Named orgs
10
Auth
OAuth
One Personal Agent Protocol visit Four steps from the October 6, 2026 announcement. 1 Discover: the personal agent starts on the company website and finds what is offered and how to connect. 2 Guest: no sign-in needed to check stock or ask about returns. 3 Sign in with OAuth, only if the task needs the account, on the company page or with credentials already set up with the agent. 4 The customer chooses read-only or write access. All four are one OAuth session that carries across channels. One PAP visit Four steps, one session. As described in the October 6, 2026 announcement. 1 Discover AGENT Starts on the company’s website and finds what’s offered and how to connect. 2 Guest AGENT No sign-in needed to check stock or ask about a returns policy. 3 Sign in CUSTOMER Only if the task needs the account. OAuth, on the company’s page or with credentials already set up with the agent. 4 Pick access CUSTOMER The customer decides how far the agent can go: Read-only Write One OAuth session, across channels A question asked before sign-in and an order change made after it count as the same visit. Source: Sierra, “Introducing Personal Agent Protocol”, Oct 6, 2026. Diagram: pap.md (independent).
R / W
Access

The customer picks access

Read-only or write. That’s the whole menu for now; finer limits are on the "later" list.

OAuth
Session

Sessions run on OAuth

Sign in on the company’s own page, or use credentials already set up with the agent. A guest visit is fine for stock checks.

3
Routes

The business picks the route

Its website, an API such as MCP or OpenAPI, or its own agent when the job needs a conversation.

Fact sheet

PAP in ten lines

Everything here comes from Sierra's post or named coverage. If it isn't sourced, it isn't on the list. Checked Oct 8, 2026.

How we got here: the timeline
Full name
Personal Agent Protocol (PAP)
Announced
October 6, 2026, at Sierra Summit, San Francisco
Created by
Sierra (Bret Taylor, Clay Bavor) and Meta
What it covers
How a personal AI agent signs in to a business and what it may do there
Auth
OAuth sessions; guest or signed in
Access levels
Read-only or write, chosen by the customer
Routes
Company website, APIs (MCP, OpenAPI), or the company’s own agent
Spec
v0.1 promised for later in October 2026, not published yet
Not covered yet
Payments, push notifications, finer permissions
Not participating
OpenAI, Anthropic, Google, Amazon
As announced

How the Personal Agent Protocol works

You, your agent and the company share one visit. Here's the flow from Sierra's post, minus anything the spec hasn't confirmed.

01
WEB

Discover on the site

The agent finds what the company offers and how to reach it. A guest session can check stock or a returns policy.

GUEST
02
OAUTH

You choose access

If the task needs your account, you sign in. You decide read-only or write. The visit stays the same.

CONSENT
03
ROUTE

The company picks a route

Website pages, an API such as MCP or OpenAPI, or the company’s own agent.

DONE

Built on OAuth, details pending

Sierra says the session is built on OAuth. What it hasn't said yet: the discovery format, scope names, token rules. Those wait for v0.1, and so do we.

See the architecture
Who's in

Two announcements, two partner lists

Sierra and Meta didn't publish the same names. Seven appear on both. Instinct is only on Sierra's list; NiCE and Decagon are only on Meta's.

CompanyRoleSierra postMeta post
SierraCo-creator
MetaCo-creator
GenesysLaunch partner
Rocket CompaniesLaunch partner
ShopifyLaunch partner
StripeLaunch partner
WalmartLaunch partner
InstinctLaunch partner
NiCEPartner
DecagonWorking group

Not on either list: OpenAI, Anthropic, Google, Amazon. Meta's list as reported by CMSWire.

Questions people keep asking

Is the PAP specification published?+

Not as of Oct 8, 2026. Sierra said v0.1 would come "later this month", meaning October 2026, followed by design workshops and a reference implementation.

Are OpenAI, Anthropic, Google or Amazon part of PAP?+

No. None of them is on either partner list. Bret Taylor, who also chairs OpenAI’s board, told CNBC he expects OpenAI and Anthropic to take part and would be "really disappointed" if competitors didn’t use it.

Does PAP handle payments?+

Not in the announced first version. Payment extensions, letting an agent buy without sharing card details, are listed as a possible later step.

Does PAP replace MCP?+

No. The announcement names MCP and OpenAPI as API routes a company can offer inside a PAP session.

Waiting on v0.1 · promised for October 2026

Building for agents before the spec lands?

Don't code against guessed endpoints. Start with what's actually been announced, and check the tracker. We'll publish an annotated read of v0.1 the day it goes live.