Personal Agent Protocol (PAP): what Sierra and Meta have shipped so far

Rama Adi
Written by

Rama Adi

Katelin Teen
Reviewed by

Katelin Teen

Last edited October 9, 2026

Expert Verified
Hand-drawn illustration of a customer with an AI-agent earpiece shaking hands with a shopkeeper who holds a ring of keys at an open door

What is the Personal Agent Protocol?

I build integrations for eesel, so when a standard promises to say how an agent "authenticates with and acts on" a business, I read it the way I read an API contract: what is defined, what is a sentence of intent. The Sierra announcement is mostly intent, but the intent is specific.

Personal agents are the assistants that work for a consumer, like Meta Muse, Instinct and OpenAI dots. Today, Sierra says, most of them "use websites and apps the way people do," and when that fails they call the support line or open web chat. PAP is meant to replace that with a direct, authorized connection. Three parties want different things from it:

  • Consumers want speed, dependability and trust.
  • Brands want visibility and control: to know when a personal agent is acting for a customer and to decide what it can do.
  • Agent builders want one consistent way to work with participating companies.
Sierra's diagram of Personal Agent Protocol: personal agents connect through one protocol layer for discovery and sign-in, then reach a brand through its website, APIs or company agent, as taken from Sierra
Sierra's diagram of Personal Agent Protocol: personal agents connect through one protocol layer for discovery and sign-in, then reach a brand through its website, APIs or company agent, as taken from Sierra

The partners named in Sierra's post are Genesys, Instinct, Rocket, Shopify, Stripe and Walmart, alongside Meta and Sierra. Stripe's Kevin Miller framed the business side plainly:

"We're contributing to the Personal Agent Protocol to give businesses a standard way to recognize their customers' agents, efficiently interact with them, and shape their customer relationships."

How does a PAP session work?

Here is the flow as Sierra describes it, step by step. The protocol starts on the website, where a personal agent can discover what the company offers and how to reach it. The agent then opens a session for its user, and the session can start as a guest. A guest session might be enough to check product availability or ask about a returns policy.

When the task needs account access, the customer signs in on the company's page or uses credentials already set up with their agent. The customer decides whether the agent gets read-only or write access. The session is built on OAuth, the same authorization standard behind "sign in with Google," and it carries across channels, so a question asked before sign-in and an order change made after are one visit.

Hand-drawn flow of a customer's agent moving from guest to signed in read-only to signed in write, then reaching a building with three doors for the website, APIs and the company's own agent
Hand-drawn flow of a customer's agent moving from guest to signed in read-only to signed in write, then reaching a building with three doors for the website, APIs and the company's own agent

The business then chooses the door:

DoorWhat the agent doesGood for
WebsiteNavigates your regular pagesOrder status, policy lookups
APIs (MCP, OpenAPI)Calls interfaces you publishFast, structured actions
Company agentTalks to your own AI agentAnything needing conversation, such as a warranty claim

That third door is where support teams should look. Sierra's own post says the company agent handles "tasks that need conversation," and a company agent on a helpdesk is exactly that. Meta Business Agent, which David Singleton names in his post, is Meta's version of the same idea on the business side. My read: PAP is a front-door standard, and what stands behind the door is still your policies and your AI customer service workflow.

One more thing worth saying out loud: Sierra, Genesys and Decagon all sell company-side agents or contact-center software, so the "company agent" door is also their product lane. That does not make the idea wrong. It does mean you should read the word "open" as "open spec," and check who writes the first reference implementation.

What has actually shipped and what is only promised?

This is the part most coverage skipped, so I tracked it by date. Everything below links to the publisher's own page.

DateWhatStatus
Oct 6Sierra's announcement and Bret Taylor's postPublished: principles, flow, partner quotes
Oct 6Meta's David Singleton postPublished: "previewing our work"
Oct 6Decagon open-sources PACTPublished: spec and reference code
Oct 8Sierra's fleming-1Shipped: detects AI callers on phone calls
"Later this month"v0.1 specificationPromised, not found
Not datedDesign workshops, reference implementationPromised
Not datedDetailed per-action limits, push notifications, payment extensionsListed as things that "could" come
Hand-drawn comparison of two shelves: published so far with the announcement, OAuth-based sessions, agent caller detection and PACT code, versus promised but not published with the v0.1 spec, workshops, reference implementation and payments and push alerts
Hand-drawn comparison of two shelves: published so far with the announcement, OAuth-based sessions, agent caller detection and PACT code, versus promised but not published with the v0.1 spec, workshops, reference implementation and payments and push alerts

Read the last row twice. The announcement states the principle that "companies set parameters for what those agents can do," but the finer controls, letting customers and companies limit specific actions, are described as future work. So today's PAP gives you three things on paper: guest versus signed-in sessions, read versus write access, and your choice of door. Per-action limits are not in the first version as described.

Sierra also admits the gap that matters most to a support team. In its fleming-1 post it says that when an agent uses the protocol, "the company knows it's an agent and who it's acting for," and then adds: "Of course, some agents may not respect the protocol." That is why Sierra shipped fleming-1 two days later, a model that scores a caller's speech in real time for signs it was generated by AI. Sierra says it is "tuned to be conservative by default, so real people don't inadvertently get flagged," and it is meant to give information, not a verdict.

Who is in and who is missing?

The partner list depends on whom you ask, and I think that is worth a table, because the differences are the story. I checked each source directly.

SourceNamed partners
Sierra blogGenesys, Instinct, Rocket, Shopify, Stripe, Walmart (with Meta and Sierra)
Jeff Weinstein, StripeMeta, Sierra, Genesys, Instinct, Rocket, Shopify, Walmart, with Stripe as "founding members"
David Singleton, MetaGenesys, NiCE, Decagon, Rocket, Shopify, Stripe, Walmart, with Muse and Meta Business Agent
Decagon on XJoining the "Personal Agent Protocol working group by @Muse"

Singleton's list adds NiCE and Decagon and leaves out Instinct, whereas Sierra's has Instinct and no NiCE or Decagon. Most likely the working group grew in two days, which is what you would expect from a draft standard. What none of the four posts names is OpenAI, Anthropic, Amazon, Google, Zendesk or Salesforce. Amazon matters most for commerce: it blocked Meta's Muse from its retail site in September, and one commentator on X put the cost of that bluntly.

"Nobody asked the person whose agent stopped working."

Reaction on X to the launch was mixed. One reply on Stripe's post reads like a lot of the industry skepticism I have seen:

"like you read the PACT announcement and released this with no spec?"

That is a guess about motive, and Sierra's post does not say it. But the dates do line up: PACT's code went public on October 6, the same day PAP was announced without one.

How does PAP relate to PACT?

PACT is the best-defined cousin, so it is worth understanding. PACT stands for Personal Agent Consent & Trust. Decagon co-developed it with Instinct, and the open repository carries the spec, TypeScript schemas, a reference provider, a demo personal agent and conformance tests, all Apache-2.0.

It runs in three steps:

  1. Discover and connect. The personal agent reads the business's A2A Agent Card, which lists the endpoint, how to authenticate and the scopes on offer, like orders:read or orders:cancel. The agent signs each request with a short-lived JWT, so the provider can verify which platform is calling.
  2. Authenticate the customer. The agent asks for scopes through OAuth's device authorization flow and shows the customer a login link. The customer signs in directly with the business and approves permissions. The agent never sees the password.
  3. Act within the grant. Each request carries both the agent's identity and the customer's delegation, and replies include signed receipts that record the scopes used and actions taken.

PACT's design choice I like most is separating identity from authority: "Verify which agent is calling independently of what the customer has permitted it to do." One replier on X flagged why that matters for plain OAuth:

"OAuth tells the business which customer, not which agent process holds the token. A copied bearer token works until it expires, so keep those short."

PACT answers that with signed agent JWTs and short-lived delegation tokens. PAP's announcement does not say yet how it handles it, which is one more reason the v0.1 text matters. For the product built on PACT, including detection and the airline example, see my earlier breakdown of the Decagon Personal Agent Gateway. One correction to that post: it said the PACT spec was not public. It is now, with the repository published on October 6.

How does PAP compare with the other protocols?

The honest answer is that these protocols mostly answer different questions, and the comparison is lopsided because only some have text you can read. This is the table I would screenshot.

ProtocolBacked byQuestion it answersPublic text todayReaches support chats?
Personal Agent ProtocolMeta, Sierra and partnersWhich door, which customer, read or writeNo, v0.1 promisedYes, via the company-agent door
PACTDecagon, InstinctWhose agent is this, what scopes did the customer grantYes, spec and code on GitHubYes, built for support agents
A2AAgentic AI Foundation, 150+ organizationsHow do two agents find and message each otherYes, 1.0 specTransport only: authorization is "implementation-specific"
MCPNamed in PAP as an API optionHow does an AI call tools and dataYesTools, not consent
Web Bot AuthCloudflareWhich bot is visiting my siteYesNo, web traffic
Trusted Agent ProtocolVisaIs this checkout agent trustedYes, with a "development and deployment" caveatNo, merchant checkout
Agent Pay probability scoreMastercardWas this payment started by an AI agentUS testingNo, payments
fleming-1SierraIs this phone caller an AIProduct feature, Sierra voice agentsVoice calls
Hand-drawn layer map with four rows: is this a bot with Web Bot Auth and fleming-1, whose agent and what may it do with Personal Agent Protocol and PACT highlighted, how do agents talk with A2A and MCP, and who pays with Visa TAP and Agent Pay
Hand-drawn layer map with four rows: is this a bot with Web Bot Auth and fleming-1, whose agent and what may it do with Personal Agent Protocol and PACT highlighted, how do agents talk with A2A and MCP, and who pays with Visa TAP and Agent Pay

Two things jump out. First, PAP is aiming at the row nobody has finished: consent and scope between a consumer's agent and a business, across every channel. Second, nothing in the payments row talks to support at all. Visa's protocol uses signatures bound to the domain and the specific operation, and Mastercard's score is about whether a transaction was AI-initiated. Neither tells your helpdesk that a customer's agent wants a refund. Sierra's own post lists "payments extensions" as future PAP work, which tells you where the protocol families may eventually meet. If you sell online, the agentic commerce protocol and Stripe's version are the checkout side of the same story.

Which protocol covers your case?

Pick the job you care about. The widget shows which standard speaks to it, how ready it is, and what I would do now.

What do you need to handle?
Pick a situation. Each answer shows the closest standard, how ready it is as of October 9, 2026, and what I would do this week.
Detect first, standardize later

fleming-1 for voice, Decagon's gateway for chat and voice

Closest standard: PAP and PACT for agents that declare themselves. Detection products for the ones that do not.

Readiness: detection products exist, PAP has no spec yet, PACT has public code.

Do now: measure how often it happens before buying anything, then gate money-moving actions behind approval.

Wait for v0.1

Personal Agent Protocol

Closest standard: PAP for sign-in, PACT for scoped consent on support agents.

Readiness: PAP spec promised later in October, PACT readable today.

Do now: decide which of your actions are read, reversible write or money-moving. Those become your scopes later.

Checkout layer

Visa Trusted Agent Protocol, Mastercard Agent Pay, agentic commerce protocols

Closest standard: payment-network and commerce protocols, not PAP.

Readiness: Visa's is published with a "development and deployment" caveat, Mastercard's score is in US testing.

Do now: ask your payment provider what it supports. PAP lists payments only as a future extension.

Web traffic layer

Web Bot Auth

Closest standard: Cloudflare's Web Bot Auth lets a bot cryptographically identify itself to a site.

Readiness: published, and it only covers website traffic.

Do now: this is your security team's call. It does not tell you what a customer allowed.

Transport layer

A2A, with MCP for tools

Closest standard: A2A for agent-to-agent messages, MCP for tools and data.

Readiness: both are published. A2A leaves authorization "implementation-specific."

Do now: use them for partner integrations. They do not carry customer consent by themselves.

What should a support team do before the spec lands?

Most support teams will not be early adopters of a protocol that has no spec. The useful work is on your side of the door, and it is the same work whether the standard ends up being PAP, PACT or both. Customers' agents are already reaching queues through chat, email and phone, as OpenAI dots for customer support and Instinct for customer support show, so I would do this in order:

  1. List every action your support AI can take. Sort each into read, reversible write, money-moving or account control. Most teams have never written this down, and it becomes your scope list.
  2. Put approvals on money and account changes. A refund is a refund whether a person or an agent asked. The Zendesk advanced AI actions and Gorgias AI actions guides show what native tools can gate.
  3. Count your agent traffic. Tag conversations that look agent-sent and measure the share before you buy detection. Sierra itself says a high-volume company "might start by measuring how often it happens."
  4. Write escalation with two exits. Your AI should hand off to a person and also say what it needs from the customer's agent. The AI escalation management guide covers the person side.
  5. Keep a way in for APIs. If you already publish an AI customer service API or helpdesk API, that is door number two. Scope it before you advertise it.
  6. Replay past tickets before go-live. Run real refund and cancellation tickets against your AI and see where it bends. A customer's agent will find the soft spot faster than any customer.

The sixth point has a scar behind it. One support lead on a sales call told eesel what they needed from an AI before they would trust it:

"I need an AI who is only handling the tickets that it's confident to handle and all the other ones, leave them alone."

A CX lead at a DTC supplements brand on Gorgias and Shopify, about 7,000 tickets a month

That sentence is a scope definition in plain words. It is also the right test for a personal agent on the other end: if your AI cannot say "this one is not mine," it cannot safely meet an agent that will ask five different ways.

Commerce teams have one more job. If you run Shopify, which is in the partner list, the Shopify AI customer service strategies guide and Muse for Shopify customer support show how agents already reach those queues. For Meta's own side of the story, see Meta Muse for customer support.

Where does eesel fit?

I will be direct about the limits. eesel does not detect personal agents, and it does not implement PAP, PACT or A2A. If you need a vendor that is building an agent-to-agent channel with customer-granted scopes, Sierra and Decagon are the two to look at, and the Decagon vs Sierra comparison and Sierra alternatives roundup lay out the trade-offs. When v0.1 is published I will read it against what eesel does and write up the gap, not guess at it now.

What eesel does is the permission layer on the helpdesk you already run. The AI helpdesk teammate joins Zendesk, Freshdesk or Gorgias like a new hire. Every action it can take is set to Auto, Needs approval or Disabled, grouped into Read and Write, per eesel's actions docs. You can say it in plain words: "look things up on your own, but ask me before any refund."

eesel's Zendesk actions settings, with the Read group on Auto and Write actions like assign, close ticket and send reply each set to auto, needs approval or disabled, as taken from eesel docs
eesel's Zendesk actions settings, with the Read group on Auto and Write actions like assign, close ticket and send reply each set to auto, needs approval or disabled, as taken from eesel docs

That is the same read-versus-write split the protocols formalize, aimed at your own AI. If PAP does land with per-action limits, these are the settings I would map them to. And because the protocols talk about APIs and MCP, one more detail: every eesel workspace is also an MCP server, and the eesel CLI drives the same teammate from a terminal. A coding agent like Claude Code can run eesel integrations <platform> actions to see every action and its approval setting, or eesel approvals to approve or deny held actions. The CLI follows the same permissions as the dashboard, so a write set to "needs approval" stays held until a person approves it.

What are people saying?

The public reaction to PAP itself is still thin, which makes sense three days after launch. The wider argument about agents contacting support is louder. On Hacker News, the most useful comment I found came from a customer's side of the table:

Hacker News

"The solution for both sides is for the companies to implement support bots that have more power to address my problem than the humans they replaced were ever given."

Put that next to Simon Taylor's read of PAP on X, where he called it an alternative to blocking and said it lets a business "recognize it, give it read-only by default, and route anything that moves money to your own agent." That is his interpretation, not Sierra's wording, but it is the version I would build toward. Blocking turns away the customer, and an open door with no limits is worse. The scopes are what let both sides get something.

Try eesel

If customers' agents are about to start asking your queue for refunds, the first job is deciding what your own AI may say yes to. eesel's AI helpdesk teammate plugs into Zendesk, Freshdesk or Gorgias, learns from your past tickets and help center, and keeps refunds and cancellations behind an approval until you have watched it hold the line. You can run it on past tickets in a simulation before it touches a customer.

eesel activity view with approved, rejected and pending filters showing helpdesk conversations the AI teammate worked
eesel activity view with approved, rejected and pending filters showing helpdesk conversations the AI teammate worked

The free plan includes 100 credits and every integration, and paid plans start at $299 a month for 500 credits, where a ticket or a chat is 1 credit, on the eesel pricing page. Try eesel on your own queue.

Frequently Asked Questions

What is the Personal Agent Protocol?
Personal Agent Protocol (PAP) is an open standard that Sierra and Meta announced on October 6, 2026. It defines how a customer's personal AI agent, such as Meta Muse or Instinct, discovers a business, signs in with the customer's permission and works through the business's website, APIs or its own agent.
Is the Personal Agent Protocol specification published yet?
Not as of October 9, 2026. Sierra says it plans to publish the v0.1 specification later in October, along with design workshops and a reference implementation. The closest thing you can read today is PACT, an Apache-2.0 protocol from Decagon and Instinct that Decagon is bringing to the PAP working group.
How is PAP different from PACT?
PAP is the broader effort led by Meta and Sierra and has no public spec yet. PACT is a published protocol built on A2A and OAuth 2.0 that lets a business verify which personal agent is calling and what scopes the customer approved. Decagon says it is joining the PAP working group, so the two may converge, but nobody has said how. See the Decagon Personal Agent Gateway breakdown for the product built on PACT.
Does PAP replace MCP or A2A?
No. Sierra's announcement lists MCP and OpenAPI as ways a business can expose its APIs to a personal agent, so PAP sits above them as the sign-in and discovery layer. PACT builds on A2A. If you already run an MCP server for your AI agent, nothing about PAP asks you to throw it away.
How should a support team prepare for customers' AI agents?
Do not wait for a spec. Sort every action your support AI can take into read, reversible write and money-moving, and put approvals on the last group. That is a policy exercise you can finish this week, and it works whatever protocol wins. A good starting point is the guide to AI for refund requests and your AI escalation rules.
Does eesel support the Personal Agent Protocol?
No. eesel does not detect personal agents and does not implement PAP, PACT or A2A today. What it offers is the permission layer on your own helpdesk: the AI helpdesk teammate sets every action to Auto, Needs approval or Disabled, which is the same read-versus-write thinking the protocols formalize. You can try it on the free plan.
Are OpenAI, Anthropic and Amazon part of the Personal Agent Protocol?
None of them is named in the launch posts from Sierra, Meta's David Singleton, Stripe or Decagon as of October 9, 2026. The named partners are Genesys, Instinct, Rocket, Shopify, Stripe and Walmart on Sierra's list, and Genesys, NiCE, Decagon, Rocket, Shopify, Stripe and Walmart on Singleton's. Compare the personal agents themselves in Instinct AI vs Meta Muse.

Share this article

Rama Adi

Article by

Rama Adi

Rama is a software engineer at eesel AI with two years of experience writing about B2B SaaS, AI tools, and customer support technology. Based in Bali, Indonesia, he brings a developer's perspective to product comparisons — cutting through marketing copy to what the integrations and APIs actually do.

Related Posts

All posts →
Illustration of a satellite orbiting the Moon, feeding stacked crater, ice and volcanic data layers into a foundation model that two scientists study
Trending

NASA-IBM Lunar Foundation Model: the open-source Moon AI, explained

NASA and IBM just open-sourced a foundation model trained only on Moon data. It beats a bigger generic model at finding ice and craters. Here is what it is, and the lesson underneath it.

KiraKiraSep 11, 2026
Illustration of the Salesforce Trusted Enterprise AI Harness wrapping an AI agent in six trust layers under an AI Control Plane
Trending

Salesforce AI Harness: the Trusted Enterprise AI Harness explained

Salesforce's new Trusted Enterprise AI Harness bundles six trusted capabilities and an AI Control Plane to govern every agent. Here is what it is, and who needs it.

Rama AdiRama AdiSep 11, 2026
A friendly AI avatar on a support chat screen talking to a customer at a laptop
Guides

AI avatars for customer service: what they actually do in 2026

AI avatars for customer service look impressive, but most are a face on top of an agent you still have to build. Here is what they do, what they cost, and when a face actually helps.

KiraKiraSep 28, 2026
Grok Bot and OpenClaw compared, a hosted AI agent and a self-hosted one side by side
Trending

Grok Bot vs OpenClaw: which AI agent should you actually run?

A hands-on comparison of Grok Bot and OpenClaw: how each AI agent works, what they really cost, the security trade-offs of a hosted bot versus a self-hosted one, and where neither one fits.

Rama AdiRama AdiSep 23, 2026
Illustration of a self-hosted AI agent runtime running as a single binary
Trending

ZeroClaw review: the open-source AI agent runtime, honestly tested

An honest ZeroClaw review: what the open-source, Rust-based AI agent runtime does brilliantly, where its security story wobbles, and who should skip it.

Rama AdiRama AdiJul 19, 2026
Illustrated hero banner for a hands-on review of Paperclip, the open-source AI agent control plane
Trending

Paperclip review: the open-source AI agent runtime, tested

An honest Paperclip review: what the open-source control plane for running a company of AI agents does brilliantly, where its support story falls short, and who should actually run it.

Rama AdiRama AdiJul 20, 2026
Illustrated hero banner for a hands-on review of NemoClaw, NVIDIA's governed AI agent runtime
Trending

NemoClaw review: NVIDIA's governed AI agent runtime, tested

An honest NemoClaw review: what NVIDIA's open-source governed agent runtime does brilliantly, where its alpha-stage security story wobbles, and who should actually run it.

KiraKiraJul 20, 2026
Illustration of Meta Muse, a personal AI agent, running errands inside a secure cloud computer
Trending

What is Meta Muse? Meta's personal AI agent, explained

Meta Muse is a personal AI agent that shops, books, and emails for you inside its own Secure VM. Here is what it does, how it works, and where it fits.

KiraKiraSep 9, 2026
Shadow, the AI interface for Mac, review cover illustration
Trending

Shadow review (2026): the AI interface for Mac

My hands-on Shadow review: the bot-free AI interface for Mac that transcribes meetings on-device, runs custom Skills from a shortcut, and costs $8 a month.

KiraKiraJul 8, 2026

Ready to hire your AI teammate?

Set up in minutes. No credit card required.

Get started free