Agent identity and trust

Personal Agent Consent & Trust Protocol (PACT)

An open protocol, built on A2A and OAuth, that lets businesses verify which personal agent is calling and what the customer has authorized it to do.

Status
New, open-sourced October 6, 2026
Governance
Decagon, co-developed with Instinct
Sources
Project siteSpecification

What to know

  • It separates agent identity (a short-lived signed JWT checked against the agent's published keys) from authority (a delegation token issued after the customer consents).
  • Customers sign in with the business through OAuth device authorization, so the personal agent never handles their login credentials.
  • Each business defines its own scopes, such as orders:read or orders:cancel, advertised in its A2A Agent Card.
  • Replies under delegated authority include signed receipts of the scopes used and actions taken.
  • Decagon says it is also joining the Personal Agent Protocol working group led by Sierra and Meta.

When to use it

Use it when consumer personal agents need to act on customer accounts through a business's A2A support agent with explicit, auditable consent.

Related standards

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 7, 2026. Spotted something out of date? Email hello@agentatlas.dev.