Changes confirmed medium confidence

Decagon Open-Sources PACT for Personal-Agent Consent

The proposed protocol separates an agent's verified identity from a customer's delegated authority, combining Agent2Agent discovery with OAuth-based permission grants.

Edited by Tyronne Panaino

Decagon announced on October 6, 2026 that it is open-sourcing the Personal Agent Consent & Trust Protocol, or PACT, a specification co-developed and supported by Instinct. The proposal gives businesses a way to distinguish which personal-agent platform is calling from what a customer has authorized that agent to do, addressing a practical trust gap as consumer agents begin contacting business-operated agents.

PACT builds on the Agent2Agent protocol and OAuth 2.0 rather than defining an entirely separate communication and authorization stack. Its central design choice is to keep agent identity and delegated customer authority as different proofs. That separation matters because recognizing a calling platform does not by itself establish that it may read an order, cancel a booking or act on a particular customer account.

Three parties and two kinds of proof

The protocol describes three parties: the customer's personal agent, the business and the provider hosting the business's agent. A business advertises its endpoint, authentication requirements and available permission scopes through an A2A Agent Card. The personal agent can then identify the scopes needed for the requested task.

For platform identity, the personal agent sends a short-lived signed JWT. The provider checks that signature against the platform's published public keys. Decagon's explanation is explicit that this step identifies the calling platform but does not prove ownership of a customer account.

Customer authorization follows a separate route. The personal agent requests scopes through OAuth's device authorization flow and gives the customer a login link. The customer signs in directly with the business and selects permissions there, so the personal agent does not handle the customer's login credentials.

The provider then issues a short-lived signed delegation token. That token binds the verified customer account, the personal-agent platform, the target business and the approved scopes. Subsequent requests carry both the agent identity and the customer delegation, allowing the provider to evaluate the request against the granted permissions and the business's own policies.

Scopes can change during a conversation

A task may require more authority than the customer initially granted. PACT uses Agent2Agent's authorization-required state to request an additional permission and continue the same conversation. Replies under delegated authorization can include signed receipts recording which scopes were used and which actions were taken.

This design creates a clearer record of consent than treating a personal agent as broadly trusted once connected. It also leaves businesses in control of the scopes they offer and the policies governing the underlying tools and workflows. Standardization is focused on discovery, identity, delegation and receipts rather than forcing every business to expose identical actions.

Open specification does not yet prove interoperability

Decagon says it published the specification openly to invite personal-agent developers, businesses and agent platforms to implement and shape it. The announcement establishes availability and describes the protocol flow, but it does not provide independent security analysis, a conformance suite, production adoption data or evidence that separately built implementations interoperate without ambiguity.

That limitation is especially important for authorization infrastructure. Short-lived tokens, customer-controlled login and signed receipts are meaningful design elements, but their security depends on details such as validation rules, key handling, scope semantics, replay protection and implementation quality. This article does not infer those outcomes from the architectural description alone.

What to watch next

The next verifiable checkpoints are implementations outside Decagon and Instinct, interoperable tests between personal and business agents, published conformance requirements and independent review of the authorization design. Clear handling of revocation, scope escalation, receipts and provider failures would help show whether the proposal can become a dependable shared standard.

Status

Confirmed. Decagon has published PACT and described its consent and authorization flow. Internal confidence is medium because the technical and adoption claims come from the vendor announcement and have not been independently validated here.

Sources

Update note: Last reviewed 2026-10-07. We will revise this post when independent implementations, conformance tests or security reviews become available.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More Changes coverage