Sierra and Meta are spearheading the Personal Agent Protocol to standardize how AI agents interact with businesses

The rapid proliferation of generative AI has moved beyond simple text-based chatbots and into the realm of autonomous agents capable of performing complex tasks on behalf of users. As these digital assistants become more prevalent, the lack of a standardized framework for authentication, security, and interoperability has created a fragmented digital landscape. To address this, Sierra and Meta have joined forces to launch the Personal Agent Protocol (PAP), a nascent open standard designed to govern how personal AI agents authenticate with enterprise systems and define the scope of their operational authority.
The initiative, announced via a blog post by Sierra co-founders Bret Taylor and Clay Bavor, seeks to provide a predictable, secure handshake between individual user agents and corporate platforms. Early partners in this consortium include industry titans such as Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart. The group plans to release the v0.1 specification later this month, marking the first formal step toward establishing a universal language for agent-to-business commerce.
The Technical Foundation: OAuth and Interoperability
At its core, the Personal Agent Protocol is built upon the established OAuth standard, a framework widely used for secure authorization. By leveraging this existing technology, the protocol allows for a granular approach to agent permissions. When a user engages an AI agent, the agent can initially function as an unauthenticated guest—a mode suitable for checking inventory, browsing product catalogs, or reviewing return policies.
Once a user decides to proceed with a more sensitive action, such as modifying an existing order or managing account settings, the protocol triggers an authentication flow. Crucially, the user retains control over the agent’s scope, granting either read-only or read-write access to their data. This session-based approach is designed to persist across various channels, ensuring that an inquiry initiated prior to authentication remains linked to an order finalized after the user has signed in.
The flexibility of the protocol extends to the implementation side as well. Businesses have the autonomy to decide how their platforms interface with these agents, whether through direct web integration, API-based bridges utilizing standards such as MCP (Model Context Protocol) and OpenAPI, or by routing requests through their own proprietary internal agents.
A Growing Rivalry: The Landscape of Agentic Standards
The Personal Agent Protocol does not exist in a vacuum. The race to define the infrastructure of the "agent economy" is heating up, with significant overlap among key stakeholders. Notably, both Stripe and Shopify—two of the most influential players in e-commerce infrastructure—have signed on to the Personal Agent Protocol despite already being participants in a rival framework: the Trusted Agent Protocol championed by Visa.
In June, Visa made headlines by integrating its infrastructure with OpenAI’s ChatGPT, enabling agents to execute transactions across a network of approximately 175 million merchants. That initiative, supported by Microsoft, Stripe, Shopify, and Worldpay, focuses heavily on the financial settlement aspect of agentic behavior. By participating in both ecosystems, Stripe and Shopify are positioning themselves as neutral infrastructure providers, ensuring that their merchants remain compatible with whichever agent standards eventually achieve mass adoption.
The urgency behind these standards is driven by the sheer speed at which agentic software is being deployed. For instance, Rocket recently detailed the capabilities of Meta’s "Muse" agent, which can navigate its platform to assist users with home-buying workflows, including the arrangement of financing. Muse, which launched in mid-October, leverages Stripe’s Link for seamless, one-click payments, demonstrating that the functional capabilities of agents are currently outpacing the regulatory and standard-setting frameworks designed to govern them.
Market Context: The "Agentic" Shift
The industry’s pivot toward autonomous agents marks a significant evolution in digital interaction. Unlike traditional automation, which follows rigid, pre-programmed logic, AI agents are designed to reason through tasks, handle exceptions, and adapt to changing user requirements in real-time.
Recent market entrants highlight the breadth of this trend. Hark, a technology firm, recently unveiled an agent capable of performing a wide array of consumer tasks, from grocery shopping and booking transportation to bill payment. This rollout comes a full year ahead of the company’s scheduled hardware launch, underscoring the industry’s "software-first" approach to agent development.
However, the rapid deployment of these tools brings significant regulatory challenges. One of the most pressing concerns is the European Union’s Strong Customer Authentication (SCA) requirements under the Revised Payment Services Directive (PSD2). Current regulations were drafted with human-in-the-loop transactions in mind, requiring explicit approval for specific payees and fixed amounts. There is currently no regulatory carve-out for autonomous software acting on a user’s behalf. Recognizing these legal hurdles, the architects of the Personal Agent Protocol have intentionally excluded payments from the v0.1 specification, designating it as a "future extension" to allow for further regulatory dialogue and security hardening.
Strategic Implications and Future Work
The decision to defer payment integration is a strategic one, reflecting the complexity of global financial compliance. Beyond payments, the developers of the Personal Agent Protocol have signaled that future iterations will prioritize sophisticated permission management and standardized push notification systems. These features are essential for ensuring that agents do not become a source of "notification fatigue" or, more critically, a security vector for unauthorized data access.
The geographic distribution of the consortium’s membership is also noteworthy. While Stripe possesses a significant operational footprint in both San Francisco and Dublin, there is a distinct lack of participation from major European retail, banking, or payment institutions in the initial announcement. As the protocol moves toward its v0.1 release, the ability of Sierra and Meta to attract European partners will be critical, particularly given the continent’s stringent data protection and financial regulations.
The success of the Personal Agent Protocol will likely hinge on three factors:
- Developer Adoption: Providing tools that are easy for developers to integrate into existing CI/CD pipelines without compromising platform security.
- User Trust: Ensuring that the "handshake" between the user, the agent, and the business is transparent and easily revocable.
- Interoperability: Preventing the emergence of "walled gardens" where agents only work with specific, pre-approved merchants.
As it stands, the industry is in a phase of competitive standardization. While the Personal Agent Protocol and the Trusted Agent Protocol serve slightly different primary functions—one focusing on the broader scope of authenticated interaction and the other on the mechanics of financial settlement—the eventual goal is a unified standard that allows agents to move seamlessly across the digital economy.
Looking Ahead
The timeline for the coming months is aggressive. With the v0.1 specification expected by the end of this month, the developer community will soon have its first concrete look at the implementation details. If the protocol gains traction, it could effectively set the ground rules for how the next generation of digital commerce functions, shifting the focus from individual brand-specific bots to a cohesive, agent-driven ecosystem.
For businesses, the choice to adopt these standards is no longer optional. As consumers begin to rely on AI to handle their day-to-day administrative and purchasing tasks, companies that fail to provide a secure, standardized entry point for these agents risk being excluded from a growing channel of commerce. Whether the Personal Agent Protocol becomes the industry bedrock remains to be seen, but its arrival confirms that the era of autonomous, agentic interaction has officially begun, and the infrastructure to support it is currently under construction.







