Meta and Sierra just announced the Personal Agent Protocol, an open standard that would let your AI agent sign in to a store or service and act for you with limited permissions. It is only a draft for now, with the first spec due later this month.
Here are the quick facts:
- Announced October 6, 2026, by Sierra and Meta
- Backers include Genesys, Instinct, Rocket, Shopify, Stripe and Walmart
- Version 0.1 of the spec is due later in October
- Payments are not covered in the first version
If you have ever wondered how an AI agent could safely log in to your accounts, this is the first serious attempt at an answer from big names.
What the Personal Agent Protocol actually does
Today, an AI agent that wants to check an order or change a booking has to scrape a website or borrow your login. Neither is great. According to The Next Web, the new open standard defines how agents authenticate with a business and what permissions they get once they are in.
Think of it as a front door with a clear rulebook. The business knows the visitor is an agent, and you decide how much it can do.
Businesses can connect in a few ways: through their website, through APIs built on MCP and OpenAPI, or through their own agent. That flexibility matters because most companies will not rebuild everything for one standard.
How the sign-in flow works
The protocol starts with a guest session. After that, you sign in or let your agent use credentials you set up earlier, and you pick read-only or write access. Implicator reports that sessions would run on OAuth, the same authorization system behind the “Sign in with” buttons you already use.
Here is how the three access levels map out in plain terms:
| Stage | What the agent can do | Who decides |
|---|---|---|
| Guest session | Browse the business like any visitor, without your account | Starts by default |
| Read-only | View your account details, such as past orders | You, after signing in |
| Write access | Take actions for you, such as changing an order | You, after signing in |
Sessions also carry across channels, so something you asked in chat can follow you to a later step. That means fewer repeated questions.
Why a shared rulebook matters for AI agents
Right now, every company handles agents in its own way. One site blocks them, another lets them in with no checks, and a third asks you to paste in a password. That mess is risky for you and hard for developers.
A common standard would make the rules predictable. A store could tell a trusted agent from a bot, and you could revoke access without hunting through settings on ten different sites.
There is also a trust angle. When a site knows exactly what permission your agent holds, it can log actions clearly. If something goes wrong, you have a record of what the agent was allowed to do.
Who is backing it, and who isn’t
The list is strong. Sierra, Meta, Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are named backers. Still, Implicator points out that Stripe, Shopify and Walmart already sit in rival agent protocols from Visa, Google and OpenAI.
OpenAI and Anthropic are not part of this announcement. For a standard meant to work across many agents, that is a gap worth watching.
What it will not do yet
This is not a finished standard. Version 0.1 is a draft, and payments are listed as future work, so your agent will not check out through this protocol at launch.
The same Implicator report notes that no license or governing body has been published, and reference implementations are still being planned. Treat the launch partners as intent, not proof that stores will adopt it.
What this means for you
Nothing changes on your phone or PC today. If the standard sticks, though, you would get one consistent way to say “this agent can look, but not buy.” That is more comfortable than handing over a password.
The safety side is the real test. We have covered how Nvidia is trying to box in rogue AI agents and how macOS is tightening Full Disk Access for AI agents. A shared sign-in rulebook fits that same trend: give agents narrow access, not the keys to everything.
If you build online stores or apps, keep an eye on the v0.1 spec when it lands. Early support for guest and read-only sessions looks like the easiest place to start.
Frequently Asked Questions
What is the Personal Agent Protocol?
It is a proposed open standard from Sierra and Meta that sets how personal AI agents sign in to businesses and what permissions they receive. It is currently a draft.
When will the Personal Agent Protocol spec be released?
Version 0.1 of the spec is due later in October 2026, according to The Next Web. Nothing is final until it is published.
Does the Personal Agent Protocol handle payments?
Not at first. Payments are listed as future work, so the opening version focuses on sign-in and permissions.
Do OpenAI and Anthropic support it?
They were not named in the announcement. Several backers, such as Stripe and Shopify, also support rival protocols.
My take: wait for the spec
The idea is sound, and the partner list is real. But a draft with no governing body and no payments is a promise, not a product. Do not change anything yet. Check back when v0.1 is out, and see whether OpenAI or Anthropic sign on.


Leave a Reply