How the OAuth Tiering Actually Works
PAP is not a new payments rail or a new browser API - it is an open standard meant to dictate how AI agents interact with businesses, developed by Meta and Sierra together with Genesys, Instinct, Rocket, Shopify, Stripe, and Walmart[1]. Structurally it's a permissioning layer bolted onto OAuth: a personal agent first shows up at a business as a guest with read-only access. Only once the human customer signs in does the agent get upgraded to write access, and that authenticated session is designed to persist across channels, whether the agent is hitting the company's website directly, calling it through MCP or OpenAPI, or routing through the company's own in-house agent[2]. Meta frames this as deliberately unglamorous infrastructure rather than a product: Meta Superintelligence Labs VP David Singleton, a former Stripe CTO, described it as "rails that we hope personal agents and business agents can run over for the future"[3]. The pitch is that businesses get an audit trail and an on/off switch for agent access, and agents get a consistent way to prove who they are acting for - the exact thing that was missing when Amazon caught Muse browsing without identifying itself.



