Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- This is a standards-development initiative for interactions between personal agents and businesses. Shopify, Stripe, Walmart and others are helping develop it; that does not mean all their merchants have adopted it.
- The proposed sessions use OAuth. Agents can first ask about public information as guests; users decide whether account access is read-only or allows changes.
- Businesses can choose their website, an API using standards such as MCP or OpenAPI, or their own agent as the interaction channel.
- Fine-grained permissions, push notifications and payment extensions remain possible directions. Reference implementations are also planned, without a separately confirmed release date.
What was announced, and why should merchants care?
On October 6, 2026, Bret Taylor and Clay Bavor introduced Personal Agent Protocol on Sierra's official blog. Meta and Sierra are developing the open standard with partners including Genesys, Instinct, Rocket, Shopify, Stripe and Walmart.
It addresses a practical question: when a customer asks a personal AI agent to check stock, book a flight or handle an order, how does a business identify whom it represents and what it may do? The goal is direct collaboration that reduces repeated page searches and form filling. Actual efficiency still needs to be demonstrated by implementations.
How does the user decide what the agent can read or change?
The proposal begins at the business's website, where a personal agent discovers services and establishes a session on the user's behalf. Stock availability or return-policy questions can begin as guest interactions. When a task involves a personal account, users can sign in on the business's page or use credentials already configured in their own personal agent.
Sessions use OAuth, a mechanism for authorizing access. The user decides whether the agent receives read-only or write access. The session design also spans channels, keeping pre-login questions and subsequent signed-in order changes within the same visit.
Suppose a customer first asks an agent whether an item is in stock, then asks it to change an order. Permission for the public lookup cannot be treated as permission for the account change. This hypothetical scenario explains the read/write boundary; it is not a transaction performed by PuppyIP or evidence that the specification already defines every operational detail.
Must merchants expose an API to agents?
Sierra describes three channels: personal agents can browse the existing website, connect to APIs using standards such as MCP and OpenAPI, or talk to the business's own agent, for example about a warranty request. Businesses decide which channels and capabilities to offer; they need not put every interaction through one endpoint.
The participant list describes co-development. Shopify, Stripe or Walmart appearing in the announcement does not establish that every merchant can enable a unified interface today. Platform-specific eligibility, regions, fees and integration steps still need later official guidance.
When is the specification expected, and which features remain proposals?
Sierra plans to publish the v0.1 specification later in October 2026, hold design discussions and release reference implementations. The announcement gives no exact specification date and no separate promised date for those implementations. It is useful for understanding direction, but not for scheduling a launch as though a generally available service already exists.
More granular action permissions, notifications for flight delays or shipments, and payment extensions that avoid sharing credit-card details are described as possibilities. They are not features you can enable using this article's steps. They do not establish shopping without confirmation, automatic payment or interoperability across all personal agents.
Do existing WebMCP or Stripe MCP integrations need to migrate?
The announcement sets no mandatory migration deadline and does not require merchants to stop using existing checkout or support systems. Keep existing integrations operating under their platforms' current documentation. A protocol-development plan does not replace a product's permissions, authentication or order-confirmation requirements.
PuppyIP's Shopify Checkout WebMCP guide covers tools in the current checkout tab, while the Stripe MCP authentication guide covers credential migration. They answer different search questions from this personal-agent protocol announcement. They can provide background on existing systems, but should not be combined into one launch or configuration.
What can merchants and developers prepare before the specification arrives?
First separate information the agent only needs to read from actions that modify customer accounts, orders or other state. Document each existing interface, identity-check mechanism and human handling route. This is preparation advice, rather than a parameter list for the unpublished v0.1 specification.
Then map those needs to your website, APIs or business agent, favoring channels whose permission boundaries you can explain. Once the specification and reference implementations arrive, check actual permissions, session lifecycles and supported platforms and verify them in an authorized test environment. There is no need to change production workflows now for a planned standard.
Sources
Frequently Asked Questions
Will Personal Agent Protocol replace MCP or OpenAPI?
Sierra's design lists APIs using standards such as MCP and OpenAPI as supported interaction channels; it does not announce their replacement. Future combinations and compatibility need to be checked against the published specification and relevant platform documentation.
Does a write API give an agent permission to change a user's order?
The existence of an interface alone does not establish permission. The announcement's principles are that users decide read/write authorization and businesses limit available capabilities; both conditions matter. Specific action permissions, revocation and session lifetimes still require the specification and implementation guidance.