Personal Agent Protocol: What Meta and Sierra Announced, and How It Fits With UCP
On 6 October, Sierra's Bret Taylor and Clay Bavor announced the Personal Agent Protocol, "an open standard Meta and Sierra are developing along with industry partners at Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart that defines how personal agents interact with businesses". It's open for anyone to implement. The first specification, v0.1, is due later in October.
If you work on agentic commerce, the obvious question is how it relates to the Universal Commerce Protocol. Shopify and Stripe are named in both efforts, and both deal with an agent signing in to a business on a customer's behalf. This post covers what was announced, how the protocol is meant to work, and where it appears to sit next to UCP, keeping to what has actually been published.
What is the Personal Agent Protocol?
The Personal Agent Protocol is a proposed open standard for how a consumer's personal AI agent, such as Meta's Muse, connects to a business: how it finds the business, signs in for the customer, gets the access the customer allows, and does the task. Sierra's announcement says it is designed "to handle authentication, empower consumers and give companies visibility into what personal agents do through their websites, APIs or company agents".
The principle, in Sierra's words: "consumers decide what access to give their personal agents, and companies set parameters for what those agents can do."
The problem it targets
Sierra's post describes how most personal agents work today: they "use websites and apps the way people do — loading pages and clicking through forms", and fall back to support lines or web chat when that fails. A direct connection, it argues, "could get the same task done securely in seconds".
Each side wants something different from that connection:
- Consumers want speed, dependability and trust.
- Brands want visibility and control: "to know when a personal agent is acting for a customer and to decide for themselves what it can do".
- Agent builders want "a direct, consistent way to work with participating companies".
How it is meant to work
The announcement describes the flow in four steps:
- Discovery on the website. A personal agent starts on the company's site, where it "can discover what the company offers and how to reach it".
- A session, as a guest or signed in. The agent begins a session for its user. A guest session "may be enough to check product availability or ask about a returns policy". For account tasks, the customer signs in on the company's page or uses credentials already set up with their agent.
- Customer-chosen access. "The customer is always in control, deciding whether the agent has read-only or write access." The session is built on OAuth and carries across channels, so a question before sign-in and an order change after it are "part of the same visit".
- Company-chosen routes. The agent then works through whichever route the company prefers: its website, its APIs ("built on standards such as MCP and OpenAPI"), or its own agent, for tasks that need conversation, such as a warranty claim.
Sierra also lists what may come later: finer permissions on specific actions, push notifications (a delayed flight, a shipped order), and "payments extensions" so an agent could complete a purchase without sharing card details. Payments are not part of the starting scope.
Who's involved, and who isn't
The announcement names Meta, Sierra, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart. Four partners are quoted:
- Shopify (Mani Fazeli, VP Product): the protocol "helps establish how agents and merchants can work together", from product questions to purchases, returns and exchanges.
- Stripe (Kevin Miller, Head of Payments): Stripe is contributing "to give businesses a standard way to recognize their customers' agents, efficiently interact with them, and shape their customer relationships".
- Genesys (Tony Bates, Chairman and CEO): "Brands need a trusted way to know who an AI agent represents, what it's authorized to do, its intent, and how to work with it securely."
- Rocket Companies (Shawn Malhotra, CTO), on letting a Muse agent move across its home-buying platform.
According to CNBC's report, OpenAI and Anthropic aren't participating at this stage, and Taylor said he expects other agent builders to join.
How it relates to UCP
Nothing published so far mentions UCP, and the PAP specification isn't out yet. So this section compares what each has published, without guessing at how they'll connect.
They start from different questions. UCP defines commerce operations and their data: what a catalog search returns, what a cart and a checkout contain, how an order is reported, and how a business declares all of that in a profile at /.well-known/ucp. Going by Sierra's description, PAP is about the session around those operations: who the agent is acting for, what the customer has allowed, and which route the business offers.
They overlap in three places:
- Discovery. UCP businesses publish a machine-readable profile listing their capabilities. PAP starts with the agent discovering "what the company offers and how to reach it" on the website. How PAP discovery will work is one of the things v0.1 should show.
- Signing in. UCP has an identity linking capability, built on OAuth 2.0, in which the business issues tokens scoped to UCP capabilities, such as
dev.ucp.common.ask:readfor personalised answers. UCP also has Web Bot Auth interop for identifying the agent itself. PAP puts sign-in, and a customer's read-only or write choice, at the centre. - Guest questions. PAP's guest example, checking availability or asking about returns, is the job UCP's newly merged
askcapability does: open questions answered from public information, with no state change.
They may meet at the API route. PAP lets a business route agents to its APIs, "built on standards such as MCP and OpenAPI". UCP businesses already expose catalog, cart and checkout over MCP and REST. Whether PAP will point to a UCP endpoint as one of those APIs is an open question until the spec is published.
The same companies are in the room. Shopify and Stripe are named PAP partners and active in UCP. Meta staff co-chair UCP's Bulk Product Discovery working group, and Meta's James Andersen was among those at UCP's Shopping Tech Council meeting on 2 October. With that overlap, the two efforts have every reason to fit together. Whether they do is something the v0.1 spec will start to show.
What to watch for in v0.1
- Discovery: whether PAP defines its own discovery document or reuses existing ones.
- Session and scopes: how read-only and write access are expressed, and whether they map to OAuth scopes a UCP business already issues.
- Agent identity: how a business recognises which agent and which customer it's dealing with, and how that relates to signed agent requests such as Web Bot Auth.
- The API route: whether commerce operations are left to existing protocols such as UCP.
- Payments: the "payments extensions" Sierra mentions as later work.
We'll read the spec when it's published and cover it.
FAQ
What is the Personal Agent Protocol? An open standard Meta and Sierra are developing, with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart, that defines how personal AI agents interact with businesses: discovery, sign-in, customer-chosen access, and the routes a business offers.
Who created the Personal Agent Protocol? Meta and Sierra, announced by Sierra's Bret Taylor and Clay Bavor on 6 October 2026, with industry partners.
Is the Personal Agent Protocol available yet? Not as a specification. Sierra plans to publish v0.1 later in October 2026, along with design workshops and a reference implementation.
Does the Personal Agent Protocol use OAuth? Yes. Sierra says the session is built on OAuth, and the customer decides whether the agent has read-only or write access.
Is the Personal Agent Protocol a competitor to UCP? It doesn't appear to be aimed at the same layer. UCP defines commerce operations such as catalog, cart and checkout. PAP, as announced, defines how a personal agent signs in and what it may do. They overlap on discovery and sign-in, and nothing published yet says how they'll connect.
Does the Personal Agent Protocol handle payments? Not at the start. Sierra lists payments extensions as possible future work.
Are OpenAI and Anthropic involved? Not currently, according to CNBC's report.
About UCP Checker
UCP Checker is the independent validation and observability layer for the Universal Commerce Protocol. We crawl, validate and grade every public UCP manifest we can find, run the merchant directory, the UCP Score, live adoption stats, the vertical guides and the authority-bound vendor map, and track the spec as it evolves so you don't have to — measured from two vantages (what a business declares, and what actually happens when an agent transacts), the same way for everyone, without picking winners.
Sources
- Introducing Personal Agent Protocol, Bret Taylor and Clay Bavor, Sierra, 6 October 2026
- Meta, Walmart, Instinct, Shopify, Sierra, Stripe, and others publish the Personal Agent Protocol, Kate Rooney, CNBC (via Techmeme), 6 October 2026
- Identity Linking capability (draft docs), ucp.dev
- Ask capability (draft docs), ucp.dev
- Shopping Tech Council minutes, 2 October 2026
- Bulk Product Discovery DWG page, chairs and members
Related coverage: UCP's Ask Is Merged · Agent Identity in UCP: Web Bot Auth Interop · TikTok Buy Direct Runs on UCP · Google's UCP Integration Hub
Check your domain's UCP status
See if your storefront is ready for agentic commerce in seconds.
Get the agentic commerce digest every Monday
Real adoption data, ecosystem trends, new spec versions, and the stores that broke or recovered this week. Read by founders and engineers building the next generation of commerce.

