Getting your business ready for personal agents
You can't implement PAP yet because there's no spec. You can still do most of the groundwork, since the announcement already tells you the shape: a guest mode, OAuth sign-in, a read/write split, and three routes you get to pick from.
This checklist sticks to that shape. Anything that depends on details v0.1 hasn't defined is flagged as such. Treat it as a starting point for your own team's review, not as security or legal advice.
1. Find out who's already visiting
Personal agents aren't waiting for a standard. Muse launched on September 8, 2026. By September 20 Amazon was blocking it, saying the agent didn't identify itself. Before you plan for agents, check your logs and support queues for the ones you already have.
2. Decide what a guest agent can see
Sierra's examples for a guest session are product availability and returns policies. Make sure that information is easy to read on your site without signing in. That's useful for agents today, whatever v0.1 says.
3. Sort your account actions into read and write
Read-only or write is the only split PAP has announced. List what an agent might do on a customer account (see orders, track a delivery, change an address, cancel, reorder) and put each one in a column. Some won't fit neatly. That's worth knowing now, because finer permissions are only on the "later" list.
4. Check your sign-in can authorize a third party
Sessions run on OAuth, and the customer signs in on your page or uses credentials already set up with their agent. If your login can't grant scoped access to an outside app today, that's the biggest piece of work on this list.
5. Pick your route
| Route | Good fit when | What you'd need |
|---|---|---|
| Website | You don't want to build anything new yet | Pages an agent can actually use: clear forms, stable markup |
| APIs | You already have an API or an MCP server | An MCP server or an OpenAPI description, the two standards Sierra names |
| Your own agent | Tasks need back-and-forth, like a warranty claim | A customer-facing agent that can take requests from other agents |
6. Keep payments out of scope for now
Payments are a future PAP extension. If agents need to check out today, look at what's already live: ACP with Stripe, UCP from Google, or Visa's TAP.See how they compare →
What not to do yet
- Don't build against endpoint paths, discovery files or scope names you've seen in blog posts. None of them come from a published spec.
- Don't treat PAP as the only door. OpenAI, Google and Amazon aren't part of it, and their agents will keep showing up.
- Don't promise customers anything about agent liability or chargebacks. Nothing announced so far covers it.
When the spec lands
Sierra says design workshops and a reference implementation will follow v0.1. We'll update this checklist against the real spec and log the changes on the status page.
Sources
- Introducing Personal Agent Protocol · Sierra (Bret Taylor, Clay Bavor), Oct 6, 2026 · primary source
- Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec · BERI
- Meta joins with group of companies to tame 'chaos' of doing business with AI bots · CNBC, Oct 6, 2026
- Model Context Protocol · modelcontextprotocol.io · primary source
pap.md is independent and not affiliated with Sierra, Meta or any PAP partner. Facts here come from the sources listed on each page.