Meta and Sierra said on October 6, 2026, that they are developing Personal Agent Protocol, a proposed open standard for how personal AI agents interact with businesses. Sierra’s announcement describes website-based discovery, an OAuth-based session, and customer choices between read-only and write access. The companies have not yet published the v0.1 specification.
How the proposed session would work
An agent would first discover a business’s available services from its website, then start a session on the customer’s behalf. A guest session could be enough to check product availability or ask about a returns policy. For an account-specific task, the customer could sign in on the business’s page or use credentials already configured with the agent.
Sierra says the session would use OAuth for authorization. The customer would choose whether the agent had read-only or write access, while the business would decide which actions and routes to make available. The session could continue across channels, so a question before sign-in and an account change afterward would remain part of the same visit.
A business could offer access through its existing website, an API built on standards such as MCP or OpenAPI, or a business agent for conversational tasks. Sierra lists Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart among the companies involved in developing the proposal.
What developers still need to see
The announcement describes intended behavior, not a published protocol that teams can implement today. Sierra plans to release a v0.1 specification later in October 2026, hold design workshops, and publish a reference implementation. Its post does not provide a deployable specification or interoperability results.
Several details therefore remain open for implementers, including the exact discovery format, authorization scopes, and how an agent’s identity and permitted actions will be represented. Sierra presents more granular permissions, push notifications, and payment extensions as possible future additions. None should be treated as a released capability of the initial proposal.
The useful next checkpoint is the v0.1 specification. It will show whether the proposed guest-to-account session and access controls are defined precisely enough for independent agents and businesses to implement consistently.



