PACT, MCP and A2A
PACT is built on MCP and decides who may call which tool. A2A and ANP assume a stranger may find and call your agent; PACT assumes nobody reaches you until both of you have said yes.
Built on MCP
Every participant exposes one MCP server over HTTPS (Streamable HTTP, the current MCP specification). Authorization is the proven certificate chain, resolved to a pinned root — a client certificate or an envelope signature, never OAuth on this surface. That identity selects a tier and a permission profile, and MCP’s tools/list returns only what that caller may use (§ 6). Sending a message is calling the other side’s send_message tool; booking a slot is calling book_slot (§ 6.2). Anything else a person wants to expose to contacts is another MCP tool on the same server behind the same permission switchboard, so the protocol never needs a verb registry: integrations are tools.
Consumer MCP clients such as hosted chat apps cannot present client certificates, and that is fine: the callers here are agents. A separate OAuth-protected façade for third-party assistants can be added later without touching the protocol (§ 6).
Where A2A and ANP differ
Almost every difference between PACT and the open agent protocols comes down to one choice. A2A and ANP assume a stranger may find and call your agent: agents publish what they are and can do, and anyone can find and call them, which needs discovery, capability advertising and negotiation with strangers, and makes every stranger a caller. PACT assumes nobody reaches you until both of you have said yes: there is no directory, a relationship starts from a card or an invite and exists once both people approve it (§ 5), and a stranger reaches a guest tier of two tools, ten calls an hour by default (§ 6.1, § 12).
Declined is not missing. A directory, open discovery and a relay are what a network needs when it has no consent gate; PACT replaced them with one human act, so it does without them on purpose (the non-goals). The comparison on the front page shows the rows PACT wins and the rows it loses, protocol by protocol.