The problem
Your customers' assistants already use your site the way people do: loading pages, clicking through forms, and when that fails, calling your support line. It's slow, and the task often fails.
An independent guide by Ora. PAP is developed by its authors (Meta and Sierra, with Genesys, Instinct, Rocket, Shopify, Stripe and Walmart) at personalagentprotocol.org.
The Personal Agent Protocol is a new, open protocol for how an AI assistant finds a company's front door. Then the assistant proves who it is, and uses a person's account only within what that person approved.
Your customers' assistants already use your site the way people do: loading pages, clicking through forms, and when that fails, calling your support line. It's slow, and the task often fails.
The Personal Agent Protocol (PAP for short, which its spec calls Poppy) gives those assistants a standard front door. Your site publishes one public file that says where assistants should go, and your sign-in server confirms the file is yours.
Each assistant proves who it is and gets a short-lived key. The key is tied to a secret only that assistant holds, so a copy is no use to anyone else. When a task needs the customer's account, the customer signs in, usually on your own page, and approves what the assistant may do. The key then covers only that. Think of a valet key.
One exception: MCP, a common way to connect tools to assistants, can't check that secret. So a key made for an MCP server works at that one server only.
When people sign in on your own page, they never give their password to an assistant. You keep your own login, your own rules, and a record of what each assistant may do. People can disconnect an assistant from their account settings.
Assistants get one way in that is the same on every PAP site. Each company still decides which assistants it lets in.
PAP is Draft 0.1, published 2026-10-09. Any part of it can still change. A reference implementation is promised.
A public file at a fixed address on the company's site tells assistants where to go.
The assistant proves who it is and gets a short-lived key tied to a secret it holds. To reach an account, the person signs in, usually on the company's own page.
Each API call carries the key and, except at MCP servers, fresh proof of the secret. The company checks them, and allows account actions only within what the person approved.