Related — October 7, 2026: Gumloop's Agent Browsers and AgentMail's AgentID tackle agent access and identity. See how each works.
Personal AI agents are now shopping, booking and calling on their users' behalf, and businesses have no standard way to tell a legitimate agent from a scraper. On October 6, 2026, Sierra unveiled the Personal Agent Protocol, an open standard meant to fix that, developed with Meta and partners Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. A v0.1 specification is planned for later in October.
The timing follows the rise of Meta's Muse, whose agent traffic has already collided with retailers. The protocol itself is what builders need to understand.

TL;DR: questions people will ask
| Question | Short answer |
|---|---|
| What is it? | An open standard for how personal AI agents interact with businesses |
| Who leads it? | Sierra, with Meta, Genesys, Instinct, Rocket, Shopify, Stripe, Walmart |
| Is the spec published? | Not yet. v0.1 is planned for later in October 2026 |
| How does auth work? | Built on OAuth, so users grant read or write access per account |
| Does it need a new transport? | No. Agents can use websites, APIs (MCP, OpenAPI) or a business's own agent |
| Is it open? | Sierra says anyone can implement it |
| What is coming later? | Detailed permissions, push notifications, payment extensions |
What problem is it solving?
Today a personal agent reaches a business in one of three clumsy ways: it drives the website like a human, it uses a public API built for developers, or it phones a call center. None of those tell the business who the agent represents, what the user allowed it to do, or whether to trust it.
Businesses respond by blocking. We covered one example when Amazon blocked Meta's Muse shopping agent. From the retailer's side, an unidentified agent that logs in and buys things looks like fraud. From the user's side, a blocked agent is a broken product.
The protocol aims for a middle position, according to Sierra's description: handle authentication, empower consumers, and let companies see what personal agents are doing when they connect through a website, an API or the company's own agent.
How the Personal Agent Protocol works (what is public so far)
The announcement gives a high-level design rather than a wire format. Four points are clear.
- OAuth underneath. A consumer authorizes an agent with the same pattern used when you let one app access another. The user grants read or write access to their account, and can revoke it.
- Business-controlled exposure. Each company decides which capabilities agents can use. A retailer might allow order lookups and returns but not account changes.
- Visibility for the business. Companies can see agent activity rather than treating all agent traffic as anonymous.
- Channel-agnostic. Agents can connect via a website, via APIs that use standards like MCP and OpenAPI, or through a company-run agent. For background on MCP, see our MCP guide.
Sierra says planned extensions include detailed permissions, push notifications for things like order and flight updates, and payment extensions that would enable purchases without sharing credit card numbers. Those extensions are where most of the hard design questions live, and none are specified yet.
Why Meta is in the room
Meta's Muse is the most visible personal agent at the moment, and it has already moved toward transactions. We covered the PayPal, Shopify and Expedia integrations, the developer connectors platform and the security architecture at launch. Each of those is a bilateral deal. A shared protocol would replace a growing pile of one-off integrations with one handshake that any agent, not just Muse, could use.
Having Walmart, Stripe and Shopify as partners is notable for the same reason. Those are the companies whose sites agents most want to transact on, and Stripe already works on agent payments elsewhere. Their participation suggests the protocol is aimed at commerce first.
How it fits next to other agent standards
The agent ecosystem already has several overlapping specs, so the obvious question is whether this adds another.
- MCP standardizes how an agent calls tools and data sources. It is a connection layer, and the announcement lists it as one way agents can reach a business.
- Agentic commerce protocols focus on completing a purchase. The Agentic Commerce Protocol, maintained by OpenAI and Stripe, is one example of a checkout-focused standard.
- The Personal Agent Protocol sits at the relationship layer: which agent is this, whose behalf is it acting on, what has it been allowed to do.
Based on the public description, these look complementary rather than competing, but only the v0.1 text will show how much overlap exists. Stripe appearing on both sides is a hint that the layers are meant to compose.
One political detail is worth noting. OpenAI's chairman co-founded Sierra, and Sierra is leading a protocol that Meta, a direct competitor to OpenAI's consumer agent, is helping build. Our comparison of OpenAI Dots, Grok Bot and Meta Muse shows how crowded personal agents already are. A neutral protocol is attractive to everyone who does not own a dominant agent, and to businesses that would rather integrate once.
What this means if you build agents or run a storefront
If you build a personal agent: plan for identity. Whatever the v0.1 text says, the direction is that agents will be expected to authenticate with scoped grants, not impersonate a user session. Start by moving any credential-sharing flows toward OAuth-style delegation.
If you run a business with customers who will use agents: decide now which actions you would let an agent perform on a user's behalf, and which need a human. A clean inventory of read actions, write actions and money-moving actions is the work the protocol will ask for anyway.
If you build for businesses (support, CRM, commerce): the "company agent" channel is the interesting one. A business-side agent that speaks the protocol can negotiate with a personal agent directly instead of a human reading a chat widget.
If you are worried about security: the open issues are the same ones we raised in our MCP security guide: scoped tokens, prompt injection through agent-readable content, and audit trails. OAuth gives revocation and scoping, but it does not by itself stop an agent from being tricked into misusing a legitimate grant.
What is not known yet
- The actual specification. v0.1 is promised for later in October, so details such as message formats, discovery and error handling are unpublished.
- Governance. The announcement calls it open, but who owns the spec long term, and how other companies join, has not been described in the coverage I could verify.
- Adoption commitments. Partners are helping develop it, which is not the same as shipping support. Whether Walmart or Shopify enable it in production is unannounced.
- Payments. The extension for buying without sharing card numbers is listed as future work.
These gaps matter. Press-release alignment from big names often outpaces engineering, and a protocol is only useful once a major business and a major agent both ship against it.
A worked example: rebooking a flight
Picture a user who asks a personal agent to move a Thursday flight to Friday. Today the agent logs into the airline site with stored credentials or calls the airline, and the airline sees something indistinguishable from a bot.
Under a protocol like this one, the flow would look different. The user grants the agent a scoped permission to read bookings and change them. The airline checks the grant, exposes a change-booking action through its API or its own agent, and logs that the change came from a named personal agent acting for that customer. If the fare difference needs payment, the planned payment extension would handle it without the agent ever holding the card number. Each step is something the airline can allow, limit or deny, which is exactly the control that blanket bot-blocking lacks.
How to follow along
- Watch Sierra's announcement channels for the v0.1 spec release later in October.
- Read the draft with an eye on discovery: how does an agent learn what a business supports?
- Compare its permission model to your own OAuth scopes and note the gaps.
- Prototype a read-only integration first, before write or payment scopes.
We will update this post when the specification lands.
Bottom line
The Personal Agent Protocol is an early but credible attempt to give personal agents a standard way to identify themselves and for businesses to say yes or no. The OAuth foundation and the partner list are encouraging, and the lack of a published spec is the main caveat. For now, treat it as a signal of where agent-to-business interaction is heading: scoped, visible and negotiated rather than scraped.
Related reading
- Meta Turns Muse Into a Transaction Layer With PayPal, Shopify and Expedia
- Amazon blocks Meta's Muse shopping agent
- Meta Muse developer connectors platform
- Meta launches Muse with a Sentinel security architecture
- OpenAI Dots vs Grok Bot vs Meta Muse
- What is MCP? Model Context Protocol guide
- MCP security guide
- Official: Sierra, Introducing the Personal Agent Protocol
- Coverage: Unite.AI on the announcement
Accurate as of October 6, 2026. The v0.1 specification had not been published at the time of writing.
