Sierra and Meta draft protocol for personal AI agents
The proposed standard sets rules for how agents authenticate with businesses and what they can do on their sites. Its first specification excludes payments.
Sierra and Meta are developing Personal Agent Protocol, with a v0.1 specification due later this month and payments excluded. The proposed standard would let businesses authenticate personal AI agents and set their permissions on websites. The announcement identifies participating companies, but does not describe a regulator, legal process or adopted rules.
The specification is therefore a technical draft, not a legal requirement described in the source material. Sierra lists payments as a future extension, while push notifications and more detailed permissions are also planned for later work.
The draft sets access permissions
Personal Agent Protocol is intended to define how an agent proves its identity to a business and what it may do there. The account given by Sierra describes sessions built on OAuth, a method for granting access without handing over a password. A customer could begin a session as a guest, then sign in and decide whether the agent receives read-only or write access. The source says the session can continue across channels, keeping actions before and after sign-in within one visit.
That model separates checking information from changing it. An agent could inspect stock or a returns policy while operating as a guest, then receive broader rights only after the customer signs in. Read-only access permits viewing, while write access permits changes, according to the source description. The proposal does not yet include payment authority, so it does not specify how an agent would obtain permission to complete a transaction.
Businesses choose the route
The standard leaves businesses to choose how agents interact with their services. They may use a website, connect through APIs using standards such as MCP and OpenAPI, or provide an agent of their own. This gives businesses a choice of implementation, while the protocol is meant to govern authentication and permitted actions. The source does not state that any particular route is mandatory.
The partner list includes Genesys, Instinct, Rocket, Shopify, Stripe and Walmart alongside Sierra and Meta. The source also notes that Shopify and Stripe have joined Trusted Agent Protocol, a rival initiative associated with Visa. Their participation in both efforts is reported as a fact; the material does not give a reason for their involvement in each. No European retailer, bank or payment company is named as a participant, though Stripe has dual headquarters in San Francisco and Dublin.
Payments remain outside the first draft
The decision to defer payments matters because software acting for a person can initiate a transaction on that person’s behalf. The source says such a payment has no exception from strong customer authentication, a requirement written around a person approving a transaction linked to a named payee and an amount. It does not provide a legal ruling or explain how the proposed standard would meet that requirement. Sierra’s stated position is that payments belong in a future extension rather than the first specification.
Rocket’s statement describes Meta Muse moving across its platform from finding a home to arranging financing. It says Muse launched four weeks earlier and uses saved cards through Stripe Link for payment. That account illustrates activity involving agents and purchases, but the source does not say the payment is covered by Personal Agent Protocol. The proposed protocol’s first version leaves payment arrangements unresolved.
Draft publication will clarify scope
The source expects v0.1 later this month, but gives no exact publication date or specification text. It also does not identify a regulator, formal legal stage, or any authority response, and reports no company response beyond Sierra’s description of the planned scope. The draft could clarify how authentication and permissions are represented across websites and APIs. Until then, payment treatment, stronger permission controls and push notifications remain future work rather than features confirmed for the first release.