Verifiable agent identity
The provider checks the personal agent's signed JWT against published public keys before treating the request as agent-authenticated.
Personal Agent Consent & Trust Protocol
PACT lets a personal agent contact a brand's support agent with verifiable identity and only the permissions the user granted. AffixIO fits around that consent flow by proving whether the next action should be allowed, denied or reviewed before the business changes an account, cancels an order, issues a refund or calls a protected tool.
Direct answer: AffixIO does not claim to own PACT or be a Decagon or Instinct partner. This page explains how AffixIO can add proof-before-action, signed decision evidence and audit context around PACT-style identity, consent and delegation flows.
Compare with PAPWhat PACT solves
Decagon's announcement says PACT is built on Agent2Agent and OAuth 2.0. The open docs describe a personal agent registering with a provider, discovering a brand Agent Card, signing requests with a short-lived JWT, asking the user to consent through the brand's login page, then carrying a short-lived delegation token for later actions.
The provider checks the personal agent's signed JWT against published public keys before treating the request as agent-authenticated.
The user signs in with the brand, approves specific scopes such as orders:read or orders:cancel, and never gives the agent the password.
Later requests carry agent identity and delegation. The provider verifies both before the brand's support agent acts.
Architecture
PACT can say who is calling and which scopes were granted. AffixIO sits at the final action boundary, where a business must decide whether this exact request should run under current policy.
The brand or provider advertises endpoint, auth requirements and available scopes.
The personal agent sends a JWT, plus conversation context where relevant.
The user signs in with the brand and approves the requested scope.
The controlled action is checked against policy, scope, account state and risk.
The business keeps signed decision evidence alongside PACT receipt context.
Working model
This model turns PACT identity and consent into an action-level decision. It does not move money, expose customer credentials or claim a live PACT integration.
Use cases
The strongest fit is customer service, account support and post-purchase operations where a personal agent needs to act for a user but the brand still needs enforcement, evidence and recourse.
Allow read-only order status checks while recording which personal agent asked and which account context was used.
Check whether the cancellation window, order state, user scope and business policy all support the action.
Route higher-risk refunds to review when value, fraud indicators or account rules require human control.
Prevent broad write scopes becoming blanket permission for sensitive customer profile changes.
Bind PACT receipt context to an AffixIO decision proof so support and disputes share the same action record.
Support Muse, Instinct, dots and other personal agents without treating every agent message as anonymous chat.
Clear boundaries
| Layer | Question it answers | AffixIO role |
|---|---|---|
| A2A | How do agents communicate and keep conversation state? | Use conversation context as one input to the action decision. |
| PACT | Which personal agent is calling and what customer consent was granted? | Verify the requested action is within scope and policy at execution time. |
| OAuth | How does the customer log in and grant scopes without sharing credentials? | Use approved scopes as inputs, not as automatic permission for every action. |
| AffixIO | Should this exact action run now? | Return yes, no or review evidence with audit context. |
FAQ
No. This page references public Decagon and Open PACT Protocol materials. It does not claim a Decagon, Instinct, A2A or PACT working group partnership.
No. PAP and PACT are related market movements around personal agents, but PACT focuses on consent and trust for personal agents contacting brand support agents through A2A and OAuth.
No. AffixIO can complement PACT by proving whether an action under a granted scope should execute under business policy.
Yes, conceptually. A PACT receipt can become evidence context for an AffixIO decision record. The business should still enforce policy before the controlled action runs.
No. A scope narrows permission, but the business still needs action-level checks, risk routing and audit evidence.
This page covers Personal Agent Consent & Trust Protocol from Decagon and Open PACT Protocol, not unrelated projects using the PACT acronym.
Read next
Sources
Decagon announced Personal Agent Consent & Trust Protocol on 6 October 2026 and described it as open sourced, co-developed and supported by Instinct, built on Agent2Agent and OAuth 2.0. The Open PACT Protocol docs explain signed personal-agent requests, brand Agent Cards, OAuth user consent, delegation tokens and action receipts.