Meta and Sierra published the Personal Agent Protocol on 6 October 2026: an open, OAuth-based standard that lets a customer's AI agent sign into a business's site or API with scoped, revocable permissions instead of a password. Walmart, Stripe, Shopify, Genesys, Instinct, and Rocket are founding backers. OpenAI, Anthropic, and Amazon are not. If you sell online or run a SaaS product, this is the first real spec for what an agent should be allowed to do on your systems.
What Is the Personal Agent Protocol?#
It's an open, OAuth-based standard, published 6 October 2026 by Meta and Sierra, that lets a customer's AI agent authenticate with a business and get scoped permissions, read-only or write, revocable any time, instead of a password.
Sierra co-founder Bret Taylor put it bluntly in coverage from Implicator.ai: "It is kind of chaos until such a standard exists." The spec gives a business three ways to let an agent in, and merchants set the permission level and limits on each:
- Ordinary web pages, same as a human visitor
- APIs via MCP or OpenAPI, for structured access
- A dedicated company agent, for conversational tasks
Per Forkast's reporting, part of what pushed this out now was Amazon quietly blocking Meta's own Muse agent from shopping on amazon.com over undisclosed access and credential concerns. v0.1 is due this month. Payments aren't in it yet.
Does This Change Anything If You Don't Run a Storefront or API?#
No. If you run a local service business with no online storefront and no public API, this changes nothing right now, full stop, and you can skip straight to the close below. Nothing here touches cash businesses or appointment books kept in a notebook.
If you sell through Shopify, run a SaaS product with its own login, or take bookings through a website rather than purely WhatsApp, this is worth your attention. It's the first time the biggest commerce and payments names have agreed on anything close to a shared doorway for agents. At WebEpex we spent part of this week checking which of our SaaS clients' backends already expose a documented OpenAPI schema and which only have internal, undocumented routes, because that's the actual lever this protocol pulls, not the AI part.
For WhatsApp-first businesses across the GCC, Europe, the US, Canada, and India, this protocol doesn't touch your chatbot directly. Messaging-channel agents are a separate fight, closer to what we covered in Decagon's Personal Agent Gateway and OpenAI's dots.
The Honest Trade-Offs#
The upside is real: one shared spec beats every merchant building bespoke agent-detection, which is what vendors like Decagon have been selling as a stopgap. If v0.1 holds, a Shopify store and a self-hosted SaaS dashboard could expose the same kind of scoped, revocable access instead of each inventing its own rulebook.
The downside is bigger right now. OpenAI, Anthropic, and Amazon sitting out means the AI stacks most of our clients build on aren't committed yet. Payments are explicitly out of v1, the part most online businesses actually care about. And trust is close to zero: only 3% of US adults say they'd let an agent complete a purchase for them, per the same reporting. Still a draft. Not a standard yet.
I didn't think this story earned a post until I read why it happened. Amazon blocking Muse isn't a roadmap slide, it's a live fight over access, and that's the part worth tracking.
How We're Already Building Around It#
We reviewed the spec the day it posted and made one call: build toward it, don't wire into it. We rewrote DevAegis's own API verification step in September to return a scoped permission object instead of a flat yes or no, before this protocol existed, which is probably why reading Sierra's draft felt like confirmation rather than news.
For every new SaaS backend we ship now, on Next.js and PostgreSQL, we write the OpenAPI schema first and treat it as documentation a future agent could read. That's the actual preparation step. My read: the SDK work can wait until v1 lands with payments in scope and at least one of OpenAI or Anthropic on board. Anything earlier is building against a moving target.
We build SaaS backends and WhatsApp automation for founders across the GCC, Europe, the US, Canada, and India, and the clients who already have a documented API are the ones who'll adopt whatever this becomes without a rebuild.
What I'd Tell a Client Asking About This#
Check one thing this week: does your API have an actual OpenAPI or Swagger schema, or does it only exist in your team's heads? That's the real homework, whether or not this specific protocol survives to v1. If you're running a SaaS MVP, this is the cheapest insurance you can buy against a rebuild later.
If you're WhatsApp-only, do nothing. This isn't your fight yet. And if you're mid-build with us, we're already defaulting new backends to documented, versioned APIs, so you don't need to ask.
Standards like this die in committee more often than they ship. This one might not. If you want a plain read on whether your current setup is anywhere close to ready for it, send me what you're running. Two minutes, no pitch. cal.com/webepex/growth-review