On October 6, 2026, Sierra announced the Personal Agent Protocol, an open standard meant to define how a person's AI agent authenticates with, and acts at, a business. Sierra is developing it with Meta and a list of industry partners, and a first v0.1 specification is promised for later in October. This article explains what has been announced, how the design works, how it relates to existing agent standards, and why the timing matters.
MetaWhat the Personal Agent Protocol is, and what is confirmed
According to Unite.AI's report on the announcement, Sierra is building the protocol with Meta and partners at Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. Other coverage, including CMSWire and a Cellcog write-up, also names NiCE and Decagon, and CMSWire notes that Sierra's and Meta's partner lists differ, with NiCE named by Meta but not in Sierra's announcement. We could not confirm one definitive list, so treat the partner roster as still settling.
The stated goal is to handle authentication, give consumers control, and let companies see what personal agents are doing when they connect through a company's website, its APIs, or an agent the company runs itself. The announcement's core principle, as quoted by several outlets, is that "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do."
One caveat on sourcing: we could not retrieve Sierra's or Meta's own announcement pages directly, so the details below come from outlets that quote them. A written specification did not exist at announcement. A Beri analysis notes there was no published spec, license or governing body at launch, and that v0.1 covers "identity and coarse read/write scope only."
How the identity and consent model works
The design is OAuth-based, the same family of authorization flows people already use when an app asks to access an account. Reporting describes a sequence: the agent discovers what a company offers, starts as a guest, the customer signs in on the company's own pages or with stored agent credentials, and the customer then chooses read-only or write access. Sessions are reported to carry across channels, before and after sign-in.
Personal Agent Protocol: three access tiers, three routes
One OAuth-based session carries across channels. Access widens only when the customer grants it.
Sources: Sierra announcement (Oct 6, 2026) as reported by Unite.AI, CMSWire and AI Weekly. Read-only and write examples are our illustrations, not from the spec.
Three properties of this model are worth separating.
Consent is granted by the customer, scoped by the company. The customer picks how much power the agent gets, while the business defines the ceiling on what an agent may do. That is a two-sided control, unlike a simple "allow all" token.
Identity is tied to a sign-in the business already trusts. Rather than a new credential type, the agent rides on the customer's existing account relationship. That keeps the business's authentication, fraud and audit systems in the loop, which is the visibility the announcement emphasizes.
Guest access comes first. AI Weekly reports that an agent can act as a guest to do things like check stock or a returns policy before anyone signs in. This matters because most agent work starts with questions, not transactions.
Companies choose the route. Per the reporting, an agent can interact through a regular website, through APIs described with MCP and OpenAPI, or through the company's own AI agent for conversational tasks. The protocol therefore does not replace those channels; it standardizes the access and consent layer in front of them.
Turning away a personal agent means turning away the customer behind it.
Meta, as quoted by CMSWire
The anti-bot problem the protocol is aimed at
The backdrop is a collision between personal agents and sites built to keep automated traffic out. Meta launched its Muse personal agent in the US on September 8, 2026, described as able to browse websites, fill out forms, book travel and make purchases. According to The Star, Amazon blocked Muse from its retail site on Sunday, September 20, and shoppers who tried to use it saw a pop-up saying the use violated Amazon's terms.

Amazon spokesperson Lara Hendrickson said the company had asked Meta to remove Amazon from the experience, and argued that third-party shopping agents should operate with opt-in approval, similar to food delivery and travel booking apps. Coverage by TechRepublic and others adds that Amazon said Muse does not identify itself as an AI agent and can reach account information when acting on a user's instructions, while Meta disputed that, saying Muse cannot see customers' passwords or payment information. The Star also notes Amazon had earlier sued Perplexity over shopping agents.
From agent launch to a proposed standard: 28 days
Days elapsed since Meta launched its Muse agent on September 8, 2026.
Sources: The Star and TechRepublic (Amazon block), Unite.AI and CMSWire (protocol announcement). Day counts are our own arithmetic. Hover a bar for details.
The Personal Agent Protocol does not mention Amazon in the reporting we reviewed, and Amazon is reported to be absent from the coalition. Still, the dispute shows the mechanism the protocol targets. A site that cannot tell an authorized agent from a scraper tends to block both. A declared, authenticated agent, acting inside a scope the customer granted and the company defined, gives the business something to allow rather than something to detect. Meta's quoted framing is that rejecting the agent means rejecting the customer. Whether large retailers outside the coalition accept that framing is the open question.
How it compares with MCP, A2A, ACP and UCP
These standards solve different layers, so a direct ranking is the wrong lens. For deeper background, see our earlier overview of MCP, A2A and the discovery layer.
| Standard | Layer it addresses | Origin |
|---|---|---|
| Model Context Protocol (MCP) | How an agent calls tools and data sources | Anthropic, later under the Linux Foundation |
| Agent2Agent (A2A) | How one agent talks to another agent | |
| Agentic Commerce Protocol (ACP) | Checkout and scoped payment inside an agent | Stripe and OpenAI |
| Universal Commerce Protocol (UCP) | Discovery, cart, checkout, post-purchase | Google, announced Jan 2026 |
| Personal Agent Protocol | Authentication and consent between a personal agent and a business | Sierra and Meta |
The relationship to MCP is the clearest. Reporting says a business can expose APIs to personal agents using MCP and OpenAPI, so MCP is a transport the new protocol can sit in front of. It is not a competitor on tool calling. A2A, by contrast, is about agent-to-agent messaging in general, whereas this protocol is specifically about a consumer's agent reaching a company, including a company's own agent, which makes it adjacent to A2A rather than a replacement.
The commerce protocols are the nearest neighbors. ACP, launched in December 2025 and co-developed by Stripe and OpenAI, focuses on checkout and payment tokens; we cover it in our explainer on how AI agents learn to pay. A Beri analysis characterizes UCP as covering discovery through post-purchase, and Visa's Trusted Agent Protocol as signed agent identity and payment data. Against these, the Personal Agent Protocol starts earlier: who the agent is acting for, and what it may see or change, before any payment. Payments, push notifications and finer-grained permissions are listed as planned extensions, not part of v0.1. We did not find sourced details on Mastercard's agent payment work in this reporting, so we do not compare it here.
Overlap among sponsors is notable. The same Beri piece points out that Stripe and Shopify take part in several of these efforts, which it reads as hedging. That is commentary, but it fits a pattern where large players join multiple drafts until one gains adoption.
What to watch next
- The v0.1 text. Late October is the target. Governance, licensing and the exact scope model are the details that will decide how open it is in practice.
- Who joins. Cellcog reports that OpenAI and Anthropic are not on board yet, and that Sierra's Bret Taylor expressed confidence they eventually would. Amazon is also reported absent.
- Behavioral rules. Constellation Research describes two tests Meta says Muse applies: whether a reasonable person would do the same thing, and whether the system would hold if every agent did it. The analyst called them fascinating but likely to be ineffective in practice. Whether any such rule becomes part of the protocol is unannounced.
For teams building on several model providers, as in a model-agnostic workspace like Metir, a shared access and consent layer would matter because the agent's identity would not depend on which model sits behind it. That is an implication of the design, not a stated feature.
Sources:
- Sierra Unveils Personal Agent Protocol Built with Meta and Partners (Unite.AI)
- Genesys, NiCE Join Sierra, Meta on Open Standard for Personal AI Agents (CMSWire)
- Meta, Sierra pitch Personal Agent Protocol to govern how personal AI agents deal with business (Constellation Research)
- Sierra, Meta Publish Personal Agent Protocol Backed by Walmart (AI Weekly)
- Personal Agent Protocol: What Meta and Sierra Announced (Cellcog)
- Meta's Personal Agent Protocol Signs Walmart Before It Has a Spec (Beri)
- Amazon blocks Meta's Muse AI agent from its retail site (The Star, Sep 22, 2026)
- Amazon Blocks Meta's Muse AI Agent From Shopping on Amazon.com Over Bot Access (TechRepublic)
- Agentic Commerce Protocol (Stripe Documentation)
Image credits
- Hero: the Meta sign at 1 Hacker Way, Menlo Park, California. Photo by LPS.1 via Wikimedia Commons, CC0.
- In-body: aerial view of the Menlo Park campus, September 2019. Photo by Pi.1415926535 via Wikimedia Commons, CC BY-SA 3.0.
