On OAuth as the right foundation, what business-layer agent auth actually needs to do, and why Shopify committing to both PAP and Visa's UCP is the data point worth tracking
The Personal Agent Protocol looks right. The spec isn't published yet. The Shopify hedge is the tell.
Anti-AI
00
Skeptic
01
Neutral
00
Pro (practical)
03
Pro (hyped)
00
← Anti-AI · Pro-AI →
On October 6, Sierra and Meta jointly announced the Personal Agent Protocol — a proposed open standard for how AI agents authenticate with businesses when they're acting on behalf of a user. The framing is straightforward: right now, if an AI agent tries to book a flight, check a return policy, or place an order, the business receiving that request has no good way to verify it came from an authorized agent rather than a scraper or a bot. PAP is an attempt to fix that at the protocol layer.
The launch partners — Genesys, NiCE, Decagon, Instinct, Rocket, Shopify, Stripe, and Walmart — are exactly who you'd want at the table. The v0.1 spec is due later this month. That's the missing piece right now.
What it is and what it isn't
PAP is specifically a spec for the agent-to-business authentication layer. That's a distinct problem from agent-to-agent communication — if you've been watching Google's Agent-to-Agent (A2A) protocol or IBM's Agent Communication Protocol (ACP), those are trying to solve how agents talk to each other. PAP is upstream of that: it's asking how a business can trust that the AI acting on behalf of a customer has the customer's actual authorization to do so.
The OAuth framing is the right call. OAuth is battle-tested identity delegation. The design decision to build on it rather than invent a new credential type means PAP can work with existing identity infrastructure. That's important for enterprise adoption — it's much easier to extend something procurement and security teams already understand than to ask them to evaluate a novel token format.
What PAP is not doing, at least in v0.1: payments. Stripe is a launch partner, but the initial spec isn't trying to handle payment authorization. That's the right sequencing — payments are where the liability questions get complicated fast, and getting the identity/auth primitive right first is the correct order of operations.
Source spread
- The Next Web — Sierra announces Personal Agent Protocol — builder. Primary announcement coverage with partner list and spec timeline.
- VentureBeat — Sierra and Meta launch Personal Agent Protocol — builder. Bret Taylor's framing on why agent auth is the core problem to solve.
- The Information — Agent Protocol Wars — skeptic. Frames this against A2A, ACP, and Visa's Universal Commerce Protocol. Useful for competitive context.
- Sierra blog — PAP announcement — builder. Primary source. Spec architecture outline; v0.1 draft expected late October.
What's interesting about the governance gap
PAP launched with a blog post and a partner list. The spec isn't public yet. This is a normal stage-0 announcement for a protocol that needs ecosystem buy-in before a spec can be useful — you need Shopify and Stripe at the table before you write the "this is how Shopify and Stripe MUST implement this" sections.
But it means that right now, the protocol is whatever Bret Taylor says it is. The v0.1 spec will determine:
- How consent is scoped and revoked (can a user grant an agent "book flights under $500" without granting "book anything"?)
- Whether businesses can query the scope an agent was granted (or just verify it's valid)
- How PAP handles conflicting delegations (user grants Claude one thing, their employer's IT policy grants something else)
- Liability model when an agent acts on a forged or stolen PAP credential
These are hard problems. The partner list signals intent to solve them. The spec will signal ability.
The Shopify/Stripe tell
| Protocol | Layer | Backers | Status | Payments |
|---|---|---|---|---|
| PAP | Agent → Business auth | Sierra, Meta, Shopify, Stripe, Walmart | v0.1 spec due late Oct | Out of scope (v0.1) |
| A2A (Google) | Agent → Agent comms | Google, 50+ partners | v0.1 live | Not applicable |
| ACP (IBM) | Agent → Agent comms | IBM, LangChain, CrewAI | Beta | Not applicable |
| UCP (Visa) | Commerce transactions | Visa, Shopify, Stripe, Mastercard | Pilot | Core scope |
Shopify and Stripe are on both PAP and Visa's Universal Commerce Protocol. That's the data point worth reading carefully.
UCP is Visa's play at the agent-commerce layer: a credential system that authorizes agents to execute transactions on behalf of users, with Visa as the trust anchor. It's in pilot. Stripe and Shopify are both participating in that pilot too.
The dual commitment isn't necessarily hedging — a company like Shopify probably wants to support whatever agent auth standard their merchants' customers end up using. But it does mean neither protocol has won yet. And it means Shopify and Stripe have more leverage over the final shape of both specs than most other participants.
Watch whether PAP's v0.1 spec includes a payments-compatible scope design, even if payments themselves are out of scope. If it does, that's Bret Taylor making an architectural move to avoid being flanked by Visa later.
What builders need to know
If you're building agent products that interact with businesses: PAP is worth tracking closely before you build custom auth flows. The spec will likely establish patterns that become table stakes for enterprise integrations — "does your agent support PAP?" will probably be a procurement question within 12 months if the coalition holds. Don't build a bespoke business-API auth layer today without a plan to integrate with whatever standard wins this space.
If you're integrating with Shopify, Stripe, or Walmart specifically: These partners committed early. Watch for their developer docs to add PAP guides when the spec ships. They'll be the first reference implementations.
If you're already building on A2A or ACP: Those are different layers. PAP doesn't replace A2A — you'd likely use both. PAP handles "the user said this agent is authorized to act for them" (business-facing trust); A2A handles "this agent needs to call that agent" (agent-facing interop). They solve adjacent problems.
On the timeline: v0.1 spec due late October. That's four to six weeks. If they slip it, that's a signal about whether the partner alignment is as solid as the announcement implies.
Further reading
- Sierra blog — Personal Agent Protocol announcement
- VentureBeat — Sierra and Meta launch Personal Agent Protocol
- The Next Web — Sierra announces the Personal Agent Protocol
- The Information — Agent Protocol Wars
- Google A2A spec on GitHub — for comparison: the agent-to-agent layer PAP sits alongside
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.