For Meta's engineers, from 🤫 hussh
The how, for the people who build it.
Not why, but how. Exactly how 🤫 Private Agent One would plug into each Meta surface, what Meta gets from each, what it costs on the hot path, and how it fails safe.
The one primitive
Every integration rides one consent handshake.
One thing to integrate: the Personal Consent Handshake Protocol (PCHP). Learn it once, reuse it on every surface. Data stays with the person; only consented, scoped, receipted signal crosses the wire.
- 01
Request a scope
A Meta surface asks the person's 🤫 Agent One for a specific, minimal scope, for example "purchase-intent: home audio, next 14 days". Never a raw data dump.
- 02
The person grants
Agent One shows the ask in plain language. The person grants a scoped, time-boxed permission, or declines. Nothing moves without an explicit, revocable yes.
- 03
Signal, not data
Agent One returns only the derived signal the scope allows, computed on the person's own device or vault. The underlying data never leaves.
- 04
A tamper-evident receipt
Both sides keep a cryptographic consent receipt: who asked, what scope, when, for how long. Auditable end to end, revocable in one tap.
On open rails, provider-neutral by design.
MCP
Model Context Protocol: how Agent One exposes consented tools and context to any model or surface, provider-neutral. Meta calls a well-scoped tool, not a database.
A2A
Agent to agent: the customer's Agent One talks to Meta Business Agent directly, each carrying its own consent receipt.
AP2
Agent Payments Protocol: when a scope includes a purchase, payment and delivery preferences release on consent, so an ad can end in a one-tap buy and a local doorstep.
The map
How it plugs into each Meta surface.
Advantage+ and ad ranking
Ranking quality depends on signal that keeps eroding.
Agent One exposes a consented interest signal over MCP; ranking reads a first-party, receipted token at match time.
Higher relevance and lower waste from signal that is real, owned and durable under any privacy regime.
News Feed and Reels
Ranking leans on inferred behavior.
Ranking blends a consented "what I actually want this week" context with existing signals. The person holds the dial from their own agent.
Better sessions, and a feed that feels helpful because the person is in control.
WhatsApp Business and Meta Business Agent
Business agents need a counterparty people trust.
The customer's Agent One and Meta Business Agent transact agent to agent (A2A), with a receipt on both sides and AP2 for payment.
Higher completion on commerce and support, and a clean audit trail on every action.
Instagram and Facebook creators
Brand matching relies on modeled audiences.
A creator's audience contributes owned, consented interest through their own Agent Ones, read by scope.
Sharper brand matches, so creators earn more from signal that was given.
Muse Spark 1.1 (Meta Model API)
A capable agentic model that needs real context to act.
Agent One is the private context and consent layer; Muse Spark is the reasoning engine, fed only permissioned context, on hardware the person owns where possible.
The most capable model becomes the most trusted, reaching people who own their compute.
Meta glasses (Ray-Ban Display and Neural Band)
A camera on the face needs permission from the wearer and the room.
Agent One is the on-device private layer: it holds the person's world model and runs a screenless consent ceremony by voice and gesture.
An always-on assistant people actually welcome into their lives.
Build it yourself
Two message shapes over an open protocol.
Nothing here is a black box. A Meta engineer can read this, stand up a sandbox and reproduce it, with no dependency on us to get started.
POST mcp://agent-one/tools/consent.request
{
"scope": "purchase-intent:home-audio",
"window": "P14D", // time-boxed
"purpose": "ad-ranking", // stated, narrow
"requester":"meta://advantage-plus",
"minimal": true // signal, never raw data
}{
"receipt_id": "rcpt_…",
"scope": "purchase-intent:home-audio",
"purpose": "ad-ranking",
"granted_at": "…", "expires_at": "…",
"nonce": "…", // verifier dedups
"signal": { "category":"home-audio",
"intent":"high" }, // bucketed
"cohort_att": "…", // k>=5000, attested
"budget_id": "…", // per-requester ε debit
"device_key": "dk_…", // certified by identity key
"revocable": true, // one tap, anytime
"sig": "ed25519:…" // over the canonical receipt
}The consent service verifies the signature and issuer chain once at ingest, then materializes a trusted feature; ranking just reads the signal. The person's raw data never leaves their device. Revoke, and the signal stops. That is the whole contract, on every surface.
- Weeks 0 to 2
Stand up the rail
Pull the Agent One SDK and run the MCP consent server in a sandbox. Define one scope (purchase-intent:home-audio) and one purpose (ad-ranking). No production data touched.
- Weeks 2 to 6
Wire one surface
Point Advantage+ ranking at the consented-signal tool for an opted-in cohort. Receipts flow; a control group runs alongside. Instrument relevance and conversion.
- Weeks 6 to 12
Read the number, harden
Report the lift against control. Harden one-tap revocation and the audit trail, add the scopes the pilot proved, and decide to scale on real data.
If your team decides to build the consent rail yourselves, the person wins either way. We would rather be chosen for being the most useful, most trusted layer than for locking anyone in.
The systems answer
What it costs at ranking time: almost nothing.
Sub-millisecond in the ranking path, zero device round-trips, and graceful fallback to today's behavior when a signal is absent.
- 01
Compute on device
Agent One derives features inside the person's vault (phone, laptop, glasses or 🤫 Puppy), reduces them to one purpose-bound signal, quantizes it to coarse buckets, and releases the bucket under local differential privacy (randomized response) at a small ε. Cohort size (k, for example 5,000 or more) is established by a private set-cardinality service, not self-asserted. Raw features never leave the device.
- 02
Sign and publish a receipt
It signs the canonical receipt (ed25519 over scope, purpose, requester, granted and expiry times, signal and a nonce) and writes it to a consent cache, Meta's feature store or a neutral edge KV, keyed by a pseudonymous id that is stable within the attribution window and rotates across epochs.
- 03
Verify once at ingest
On ingest, the consent service verifies the signature and issuer chain exactly once, dedups the nonce within the TTL, checks a fresh cohort attestation, and materializes a trusted value into the feature store. Ranking then reads a plain, pre-verified feature: no per-candidate crypto, no device round-trip.
- 04
Revoke by invalidation
A revocation invalidates the materialized feature and cache entry. A bounded revocation list is the backstop for pre-expiry compromise, checked at ingest. Propagation is bounded by the TTL, and consent stays authoritative on the device.
Fails safe.
Cache miss or device offline
The ranker falls back to its existing signals. 🤫 is strictly additive, never a hard dependency. No consented signal means no lift, not an outage.
Revocation lag
Bounded by the TTL. The worst case is a stale but still-consented signal for less than one TTL. Shorten the TTL where a surface needs tighter bounds.
Key compromise
A person-level identity key certifies short-lived per-device signing keys, and the verifier trusts a small issuer set. A lost pair of glasses revokes only the glasses: one device, one scope.
Replay and cross-surface misuse
Purpose binding stops a receipt minted for ad ranking from being replayed into another surface. A per-receipt nonce, deduped within the TTL, stops same-purpose replay.
Private and provable at scale.
Data minimization, stated precisely
Only a derived, purpose-bound signal crosses the wire, minimized by quantization and k-anonymity. That signal then rests in Meta's feature store, linkable to a pseudonymous id, so it is personal data and governed as such. The guarantee is minimization and purpose binding.
Scale, with the arithmetic
About 3×10⁹ people × ~5 active scopes × ~500 B ≈ 7.5 TB resident: feature-store scale. The real cost is writes, so receipts carry a longer expiry with a separate revocation channel and re-sign only on change, collapsing writes to the change rate. Verify is O(1); shard by id hash.
The right privacy at each layer
Local DP protects one person's released bucket and grounds the per-requester budget; population DP protects cross-user aggregates like a creator's audience distribution; k-anonymity governs cohort membership.
Auditable, and measured well
The receipt is the unit of audit. Measure lift with a randomized holdback, tighten intervals with CUPED, and scale what the number justifies.
Consistency model: consent is authoritative on the device; the cache is a read-through replica with bounded staleness. Additive, not load-bearing, so the worst failure is no lift, never an outage.
Trust root and threat model
The questions a security reviewer asks first.
A signature proves only that someone holding a key signed this. Here is who that someone is, and the abuse cases we design against, because at billions of people you assume the requester is adversarial.
Trust root and keys.
What the signature covers
ed25519 signs the canonical receipt: receipt_id, scope, purpose, requester, granted_at, expires_at, signal and nonce. No field is malleable.
Key to identity, not a bare key
A person-level identity key, in the phone's secure enclave or a 🤫 Puppy, certifies short-lived per-device signing keys. Meta trusts a small set of Agent One issuer keys, not billions of device keys.
How the issuer set is trusted
The issuer set is pinned like a CA root and published to a public key-transparency log. Rotation ships as a signed root update that chains to the prior root.
Replay and freshness
A nonce plus verifier dedup within the TTL stops replay; the issuer chain and expiry stop forgery and staleness.
Threat model.
The requester is untrusted
Agent One evaluates every ask against the person's policy on device and can narrow, counter-offer or decline. Minimization is enforced by the holder, not the asker.
No exfiltration by a thousand cuts
Each grant carries a real DP cost, so a per-requester budget composes them, for example ε_total ≈ 1.0 per 30-day epoch at ε_i ≈ 0.1. The budget is charged to a requester-scoped, blinded pseudonym, plus rate limits and anomaly detection.
Consent fatigue is an attack
The agent batches, defaults to decline, expires grants, and answers routine asks from standing policy, so meaningful consent survives at scale.
Deployment
Weeks to a pilot, not quarters.
One SDK, one protocol, no new data lake. The person's device does the private work; Meta receives clean, consented signal.
An SDK and an MCP server
Meta integrates against the Agent One SDK and an MCP server that speaks consented tools. No bespoke data pipeline, no new liability surface.
On-device runtime
Agent One runs on the person's phone, laptop, glasses or 🤫 Puppy. Context stays local; only consented, scoped signals cross the wire.
Edge inference on the 🤫 grid
Where Meta wants distributed inference for Muse Spark, the 🤫 grid, Puppy to Factory One, supplies burst compute at a low cost per token, alongside Meta's data centers.
Why it is worth it
Why this is worth Meta's time.
Consent helps the build-out pay
Consented first-party signal lifts ad, feed and commerce returns while liability goes down.
Own the agent era, with trust
Meta is building the model, the business agent, the assistant and the glasses. 🤫 is the layer that makes all of them trusted by design.
A neutral rail, not a walled garden
Agent One is provider-neutral and human-owned. Meta gets better signal without holding the person's raw data, which keeps regulators and people on side.
Aligned owners, low-risk entry
We are long-term Meta shareholders. Start with one measured pilot on one surface, with a control group and a clear number.
One pilot, one surface, a real number
Pick one surface: Advantage+ consented signal, one-tap to local delivery, or Agent One on glasses. Wire the consent rail, run a control group, and read the lift together. The person has to end up better off, or it is not worth doing.