Personal Agent Protocol, PAP and proof before action

Personal agents need permission evidence before they touch the real world.

Sierra and Meta have announced Personal Agent Protocol as an open standard for how personal AI agents interact with businesses. AffixIO fits around that kind of session by proving whether a specific agent action should be allowed, denied or reviewed before it reaches checkout, support, account changes, MCP tools or OpenAPI routes.

Direct answer: AffixIO does not claim to own PAP or be a Sierra, Meta, Shopify, Stripe or Walmart partner. It provides a proof-before-action layer that can be used around PAP-style personal agent sessions once a business exposes a website, MCP tool, OpenAPI route or company agent.

Agent reference

What changed

PAP gives personal agents a route into companies. AffixIO gives companies proof at the action boundary.

Sierra described Personal Agent Protocol as starting on a website, letting a personal agent discover what a company offers, then beginning a session on the user's behalf. Public checks can remain guest-level. Account actions can require sign-in or credentials already set up with the personal agent. The customer decides read-only or write access, and the company chooses whether the agent uses the website, APIs such as MCP and OpenAPI, or a company agent.

1

Discovery and session

The personal agent finds the company route and begins a session. PAP is the emerging language for that handshake.

2

Scoped access

OAuth can describe account access, guest access, read-only access or write access. Access is not the same as approval for every action.

3

Action proof

AffixIO can check the exact action, policy, limits, recipient, merchant, expiry and evidence requirements before execution.

Architecture

Where AffixIO sits in a PAP-style workflow.

The cleanest implementation is to call AffixIO between the agent request and the controlled action. That applies whether the route is a website form, an MCP tool, an OpenAPI endpoint, a checkout step, a support workflow or a company-owned agent.

1

Agent discovers route

The business makes clear what an agent can do and which interface it should use.

2

Session begins

The agent acts as guest or with user-approved account access.

3

Action requested

The request has an action, target, account, amount, merchant or tool context.

4

AffixIO decides

The policy check returns allow, deny or review with signed decision evidence.

5

Business enforces

The website, API or company agent executes only if the result allows it.

6

Audit remains

Support, risk, compliance and future disputes share the same proof record.

Working model

Choose an agent route and see the AffixIO check.

This demo keeps the payment rail, website or MCP server separate. It shows the proof-before-action question a business should ask before letting the agent proceed.

Use cases

Personal agent use cases where proof matters.

Personal agents will not only browse. They will ask to return products, change subscriptions, book services, update details, claim warranties, call paid tools and trigger purchases. Each action needs a business-grade decision, not just a friendly chat transcript.

A

Agentic commerce

Before checkout, prove the agent has the right mandate, amount ceiling, merchant scope and expiry.

B

Support actions

Before a refund, warranty claim or account change, prove the agent has the right account context and allowed action.

C

MCP and OpenAPI

Before tool invocation, prove the agent can see and call that tool for this user and this purpose.

D

Read-only access

Let agents check availability, status or policy without accidentally granting write authority.

E

Write access

Separate permitted edits from account takeover risk by binding scope, account and intended outcome.

F

Evidence

Keep a signed record that answers what was requested, what was checked, and why the system allowed or blocked it.

Clear boundaries

PAP, OAuth and AffixIO answer different questions.

LayerQuestion it answersAffixIO role
Personal Agent ProtocolHow can a personal agent discover and interact with a business?Use the session and route context as inputs for decision evidence.
OAuthHas access been authorised for this account or resource?Check whether the requested action is within policy right now.
MCP or OpenAPIWhich tools or endpoints are available?Gate visibility and invocation before the tool or endpoint runs.
Payment railCan money move through the processor or wallet?Prove the action, authority and transaction intent before payment execution.

FAQ

Personal Agent Protocol FAQ for AffixIO buyers and builders.

Is AffixIO claiming a PAP partnership?

No. This page references public reporting and explains where AffixIO can fit technically. It does not claim a partnership with Sierra, Meta, Shopify, Stripe, Walmart or any other named organisation.

Is PAP already final?

No. Sierra stated that it plans to publish a v0.1 specification later in October 2026. AffixIO should track the spec when it appears and adapt implementation language accordingly.

Does AffixIO replace OAuth?

No. OAuth can authorise access. AffixIO checks the proposed action under that access and produces evidence for allow, deny or review.

Can AffixIO support PAP payments?

Payments were described as a future extension in the announcement. AffixIO can already model payment intent proof, spend limits and agentic payment checks around existing rails, but payment processors still authorise payment.

Can browsers be personal agent interfaces?

Yes, a browser can be the interface or controlled runtime for a personal agent workflow. A normal anonymous tab is not trusted by itself. Protected keys and policy checks should remain on a trusted backend or controlled runtime.

What should a business implement first?

Start by listing actions, classifying them as public, read-only, write, payment or review, then call AffixIO before any write, paid or sensitive action executes.

Sources

Public PAP references used for this page.

Sierra announced Personal Agent Protocol on 6 October 2026 and described it as an open standard being developed by Meta and Sierra with named industry partners. TNW separately reported the OAuth basis, website, API and company-agent routes, the pending v0.1 specification and payments as a future extension.

Sierra announcement ยท TNW report

PACT consent context

Scopes still need proof before execution.

PACT can identify the personal agent and carry user-granted scopes. AffixIO can check the exact action and return yes, no or review evidence before the brand lets it run.

Read the PACT fit