On October 6, Sierra and Meta published the Personal Agent Protocol. Six founding members. One conspicuous absence. Stripe, Shopify, Walmart, and Genesys signed on to standardize how personal AI agents carry identity, intent, and permission across the web. Anthropic did not—even though PAP is built on top of MCP, the tool-calling layer Anthropic authored. Read that twice. You do not announce the front door of agent commerce and then lock the foundation's owner out of the lobby. Chaos is just data waiting for a pattern, and the pattern here is a standards war that started before the standard even shipped. Amazon is absent too, and it is simultaneously suing Perplexity and blocking Meta's agent from its catalog. The alliance is real. The coalition is not.
Strip the launch language and PAP is an OAuth 2.0 extension. It reuses existing identity providers, token refresh, and scope-based grants. On top, it bolts a permission gradient—read-only up to write, which in practice means an agent can move money—and it standardizes "intent declarations," so an agent can announce what it is about to do before it does it. It supports plain websites, MCP, and OpenAPI. The pitch is clean: PAP governs the "who" and the "what" of a transaction and hands the "how" to existing financial tracks. Sierra, Bret Taylor's customer-service agent company last valued around $4.5 billion, wants to graduate from SaaS vendor to infrastructure standard-setter. Meta—represented by David Singleton, ex-Stripe CTO, now a VP at Meta Superintelligence Labs—wants to convert its messaging distribution into a commerce entry point. Singleton compares PAP to email. Hold that thought; it collapses under scrutiny.
Here is where my audit experience bites. Through 2025 I was stress-testing AI-agent-driven DeFi protocols, feeding them volatile oracle data and watching exactly where the authorization logic broke. What I found then is what PAP ignores now. The crypto-native world already solved delegated authority. Session keys, account abstraction under ERC-4337, delegate frameworks—scoped, time-boxed, revocable, cryptographically attestable, with every grant written to a ledger and every revocation propagating in the open. OAuth has none of that. It has no native revocation propagation across domains, no cryptographic attestation of intent, and no auditable authorization log. PAP's two hardest problems—cross-channel permission persistence and verifying that an agent's claimed identity is not a phishing shell—are precisely the problems smart accounts shipped solutions for back in 2023. Listen to the whispers, but trust the ledger. PAP asks you to trust an OAuth handshake instead.
The intent-declaration gap is the technical crux. PAP standardizes the announcement of intent but says nothing about who verifies it, who backs it, or whether it can be forged. That is the entire trust model, and it is unaddressed. A prompt-injected agent reads a product page, absorbs a hidden instruction, and declares "buy." PAP authenticates the agent's identity. It cannot authenticate the agent's judgment. There is no circuit breaker, no anomaly log, no defined liability when the agent overspends, misfires, or gets hijacked mid-session. Those are not edge cases. They are the product.
And the MCP dependency is a structural contradiction, not a feature. PAP extends MCP while excluding the lab that owns it. You are building your floor on someone else's foundation and charging rent on the room above. Taylor expects OpenAI and Anthropic to "eventually participate." That is a wish, not a commitment. Meanwhile the fragmented reality is already here: Shopify-Meta's Muse checkout, TikTok's Shopping Assistant, Amazon's own walls. Every platform is building a back door while PAP pitches a unified front door.
Everyone frames PAP as pro-consumer plumbing. It is not. It is a toll booth. Whoever owns the authorization layer owns the entry point—and the entry point is where agentic-commerce rents get captured. This is the same maneuver intent-based architectures pulled on DEXs: move MEV off-chain into solver networks and rename it "efficiency." PAP relocates extraction from the merchant's checkout to the orchestrator's gate. The trust math is brutal for that pitch: roughly 3% of US adults say they trust an agent to buy on their behalf, and one in three active AI users say they will never authorize one. The email analogy is bait. SMTP won because no single giant could tax it and everyone had an incentive to interconnect. Agent commerce has the opposite incentive structure—every player wants a walled garden, because the wall is the margin. The "open standard" is the loss leader; the value-added layer—agent hosting, distribution, flow fees—is the actual business. The yield was sweet, but the exit was sharper.
Watch two signals, and only two. First, whether OpenAI or Anthropic joins—or ships a competing authorization layer that extends MCP upward on its own. If MCP absorbs identity, PAP is redundant before it scales. Second, whether Meta binds PAP adoption to access on its own channels. That is the only forcing function that converts six signatures into a network. Speed is the only currency that does not wait for consensus, but a press release is not adoption. The front door is built. Whether the keyholders actually walk in is the only number that matters.


