metir
metir
Docs
Download on App StoreGet it on Google PlayLog inSign up
Back to Blog
AI Agents
Personal Agent Protocol
Meta
Agentic Commerce
Standards

Personal Agent Protocol: Meta and Sierra's Agent Standard

Meta and Sierra's Personal Agent Protocol proposes an OAuth-based way for AI agents to authenticate with businesses. How it differs from MCP, A2A and ACP.

Metir AI TeamOctober 7, 20268 min read
Personal Agent Protocol: Meta and Sierra's Agent Standard

On October 6, 2026, Sierra announced the Personal Agent Protocol, an open standard meant to define how a person's AI agent authenticates with, and acts at, a business. Sierra is developing it with Meta and a list of industry partners, and a first v0.1 specification is promised for later in October. This article explains what has been announced, how the design works, how it relates to existing agent standards, and why the timing matters.

Meta logoMeta
Meta is co-developing the protocol with Sierra. Partners named across coverage include Genesys, Instinct, Rocket, Shopify, Stripe and Walmart.
Oct 6, 2026Protocol announcedBy Sierra, with Meta
3 tiersAccess levelsGuest, read-only, write
3 routesHow agents connectWebsite, APIs, company agent
Late Octv0.1 spec dueNot yet published

What the Personal Agent Protocol is, and what is confirmed

According to Unite.AI's report on the announcement, Sierra is building the protocol with Meta and partners at Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. Other coverage, including CMSWire and a Cellcog write-up, also names NiCE and Decagon, and CMSWire notes that Sierra's and Meta's partner lists differ, with NiCE named by Meta but not in Sierra's announcement. We could not confirm one definitive list, so treat the partner roster as still settling.

The stated goal is to handle authentication, give consumers control, and let companies see what personal agents are doing when they connect through a company's website, its APIs, or an agent the company runs itself. The announcement's core principle, as quoted by several outlets, is that "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do."

One caveat on sourcing: we could not retrieve Sierra's or Meta's own announcement pages directly, so the details below come from outlets that quote them. A written specification did not exist at announcement. A Beri analysis notes there was no published spec, license or governing body at launch, and that v0.1 covers "identity and coarse read/write scope only."

How the identity and consent model works

The design is OAuth-based, the same family of authorization flows people already use when an app asks to access an account. Reporting describes a sequence: the agent discovers what a company offers, starts as a guest, the customer signs in on the company's own pages or with stored agent credentials, and the customer then chooses read-only or write access. Sessions are reported to carry across channels, before and after sign-in.

Personal Agent Protocol: three access tiers, three routes

One OAuth-based session carries across channels. Access widens only when the customer grants it.

1. Guest
No sign-in. Company sets what a guest agent may see.
Reported example: check stock or a returns policy
2. Signed-in, read-only
Customer signs in and chooses read-only.
Illustration: view an order status
3. Signed-in, write
Customer signs in and chooses write access.
Illustration: change or cancel an order
Connection routes the company can offer
Company websiteAPIs (MCP and OpenAPI)Company's own agent

Sources: Sierra announcement (Oct 6, 2026) as reported by Unite.AI, CMSWire and AI Weekly. Read-only and write examples are our illustrations, not from the spec.

Three properties of this model are worth separating.

Consent is granted by the customer, scoped by the company. The customer picks how much power the agent gets, while the business defines the ceiling on what an agent may do. That is a two-sided control, unlike a simple "allow all" token.

Identity is tied to a sign-in the business already trusts. Rather than a new credential type, the agent rides on the customer's existing account relationship. That keeps the business's authentication, fraud and audit systems in the loop, which is the visibility the announcement emphasizes.

Guest access comes first. AI Weekly reports that an agent can act as a guest to do things like check stock or a returns policy before anyone signs in. This matters because most agent work starts with questions, not transactions.

Companies choose the route. Per the reporting, an agent can interact through a regular website, through APIs described with MCP and OpenAPI, or through the company's own AI agent for conversational tasks. The protocol therefore does not replace those channels; it standardizes the access and consent layer in front of them.

“

Turning away a personal agent means turning away the customer behind it.

Meta, as quoted by CMSWire

The anti-bot problem the protocol is aimed at

The backdrop is a collision between personal agents and sites built to keep automated traffic out. Meta launched its Muse personal agent in the US on September 8, 2026, described as able to browse websites, fill out forms, book travel and make purchases. According to The Star, Amazon blocked Muse from its retail site on Sunday, September 20, and shoppers who tried to use it saw a pop-up saying the use violated Amazon's terms.

Aerial view of the Menlo Park, California campus used by Meta, surrounded by parking lots and salt marsh
An aerial view of the Menlo Park, California campus used by Meta, in a photo taken in September 2019. The image illustrates the company's location only, not the protocol or any 2026 event. Photo by Pi.1415926535 via Wikimedia Commons, CC BY-SA 3.0.

Amazon spokesperson Lara Hendrickson said the company had asked Meta to remove Amazon from the experience, and argued that third-party shopping agents should operate with opt-in approval, similar to food delivery and travel booking apps. Coverage by TechRepublic and others adds that Amazon said Muse does not identify itself as an AI agent and can reach account information when acting on a user's instructions, while Meta disputed that, saying Muse cannot see customers' passwords or payment information. The Star also notes Amazon had earlier sued Perplexity over shopping agents.

From agent launch to a proposed standard: 28 days

Days elapsed since Meta launched its Muse agent on September 8, 2026.

Sources: The Star and TechRepublic (Amazon block), Unite.AI and CMSWire (protocol announcement). Day counts are our own arithmetic. Hover a bar for details.

The Personal Agent Protocol does not mention Amazon in the reporting we reviewed, and Amazon is reported to be absent from the coalition. Still, the dispute shows the mechanism the protocol targets. A site that cannot tell an authorized agent from a scraper tends to block both. A declared, authenticated agent, acting inside a scope the customer granted and the company defined, gives the business something to allow rather than something to detect. Meta's quoted framing is that rejecting the agent means rejecting the customer. Whether large retailers outside the coalition accept that framing is the open question.

How it compares with MCP, A2A, ACP and UCP

These standards solve different layers, so a direct ranking is the wrong lens. For deeper background, see our earlier overview of MCP, A2A and the discovery layer.

StandardLayer it addressesOrigin
Model Context Protocol (MCP)How an agent calls tools and data sourcesAnthropic, later under the Linux Foundation
Agent2Agent (A2A)How one agent talks to another agentGoogle
Agentic Commerce Protocol (ACP)Checkout and scoped payment inside an agentStripe and OpenAI
Universal Commerce Protocol (UCP)Discovery, cart, checkout, post-purchaseGoogle, announced Jan 2026
Personal Agent ProtocolAuthentication and consent between a personal agent and a businessSierra and Meta

The relationship to MCP is the clearest. Reporting says a business can expose APIs to personal agents using MCP and OpenAPI, so MCP is a transport the new protocol can sit in front of. It is not a competitor on tool calling. A2A, by contrast, is about agent-to-agent messaging in general, whereas this protocol is specifically about a consumer's agent reaching a company, including a company's own agent, which makes it adjacent to A2A rather than a replacement.

The commerce protocols are the nearest neighbors. ACP, launched in December 2025 and co-developed by Stripe and OpenAI, focuses on checkout and payment tokens; we cover it in our explainer on how AI agents learn to pay. A Beri analysis characterizes UCP as covering discovery through post-purchase, and Visa's Trusted Agent Protocol as signed agent identity and payment data. Against these, the Personal Agent Protocol starts earlier: who the agent is acting for, and what it may see or change, before any payment. Payments, push notifications and finer-grained permissions are listed as planned extensions, not part of v0.1. We did not find sourced details on Mastercard's agent payment work in this reporting, so we do not compare it here.

Overlap among sponsors is notable. The same Beri piece points out that Stripe and Shopify take part in several of these efforts, which it reads as hedging. That is commentary, but it fits a pattern where large players join multiple drafts until one gains adoption.

What to watch next

  • The v0.1 text. Late October is the target. Governance, licensing and the exact scope model are the details that will decide how open it is in practice.
  • Who joins. Cellcog reports that OpenAI and Anthropic are not on board yet, and that Sierra's Bret Taylor expressed confidence they eventually would. Amazon is also reported absent.
  • Behavioral rules. Constellation Research describes two tests Meta says Muse applies: whether a reasonable person would do the same thing, and whether the system would hold if every agent did it. The analyst called them fascinating but likely to be ineffective in practice. Whether any such rule becomes part of the protocol is unannounced.

For teams building on several model providers, as in a model-agnostic workspace like Metir, a shared access and consent layer would matter because the agent's identity would not depend on which model sits behind it. That is an implication of the design, not a stated feature.

Sources:

  • Sierra Unveils Personal Agent Protocol Built with Meta and Partners (Unite.AI)
  • Genesys, NiCE Join Sierra, Meta on Open Standard for Personal AI Agents (CMSWire)
  • Meta, Sierra pitch Personal Agent Protocol to govern how personal AI agents deal with business (Constellation Research)
  • Sierra, Meta Publish Personal Agent Protocol Backed by Walmart (AI Weekly)
  • Personal Agent Protocol: What Meta and Sierra Announced (Cellcog)
  • Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec (Beri)
  • Amazon blocks Meta's Muse AI agent from its retail site (The Star, Sep 22, 2026)
  • Amazon Blocks Meta's Muse AI Agent From Shopping on Amazon.com Over Bot Access (TechRepublic)
  • Agentic Commerce Protocol (Stripe Documentation)

Image credits

  • Hero: the Meta sign at 1 Hacker Way, Menlo Park, California. Photo by LPS.1 via Wikimedia Commons, CC0.
  • In-body: aerial view of the Menlo Park campus, September 2019. Photo by Pi.1415926535 via Wikimedia Commons, CC BY-SA 3.0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of service
  • Privacy policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational