hussh
Agent One
Products
PuppyTagShop
Marketplace
OverviewWhite PagesYellow Pages
For Business
For Advisors & RIAFor BrandsFor Agent BuildersFor DefenseOur PartnersPartner with Hussh
Blog
Guide
A-ZPCHPYour informationBuilding in the openConsent & Privacy
Company
Our StoryTeamCareersPressMediaContact
Get Agent One
Agent One
Products
PuppyTagShop
Marketplace
OverviewWhite PagesYellow Pages
For Business
For Advisors & RIAFor BrandsFor Agent BuildersFor DefenseOur PartnersPartner with Hussh
Blog
Guide
A-ZPCHPYour informationBuilding in the openConsent & Privacy
Company
Our StoryTeamCareersPressMediaContact

For Meta's engineers, from 🤫 hussh

The how, for the people who build it.

Not why, but how. Exactly how 🤫 Private Agent One would plug into each Meta surface, what Meta gets from each, what it costs on the hot path, and how it fails safe.

Let's build togetherThe roadmap
The ideaThe roadmapFor engineersFor Mark

The one primitive

Every integration rides one consent handshake.

One thing to integrate: the Personal Consent Handshake Protocol (PCHP). Learn it once, reuse it on every surface. Data stays with the person; only consented, scoped, receipted signal crosses the wire.

  1. 01

    Request a scope

    A Meta surface asks the person's 🤫 Agent One for a specific, minimal scope, for example "purchase-intent: home audio, next 14 days". Never a raw data dump.

  2. 02

    The person grants

    Agent One shows the ask in plain language. The person grants a scoped, time-boxed permission, or declines. Nothing moves without an explicit, revocable yes.

  3. 03

    Signal, not data

    Agent One returns only the derived signal the scope allows, computed on the person's own device or vault. The underlying data never leaves.

  4. 04

    A tamper-evident receipt

    Both sides keep a cryptographic consent receipt: who asked, what scope, when, for how long. Auditable end to end, revocable in one tap.

On open rails, provider-neutral by design.

MCP

Model Context Protocol: how Agent One exposes consented tools and context to any model or surface, provider-neutral. Meta calls a well-scoped tool, not a database.

A2A

Agent to agent: the customer's Agent One talks to Meta Business Agent directly, each carrying its own consent receipt.

AP2

Agent Payments Protocol: when a scope includes a purchase, payment and delivery preferences release on consent, so an ad can end in a one-tap buy and a local doorstep.

The map

How it plugs into each Meta surface.

Advantage+ and ad ranking

Meta today

Ranking quality depends on signal that keeps eroding.

How 🤫 Agent One plugs in

Agent One exposes a consented interest signal over MCP; ranking reads a first-party, receipted token at match time.

What Meta gets

Higher relevance and lower waste from signal that is real, owned and durable under any privacy regime.

News Feed and Reels

Meta today

Ranking leans on inferred behavior.

How 🤫 Agent One plugs in

Ranking blends a consented "what I actually want this week" context with existing signals. The person holds the dial from their own agent.

What Meta gets

Better sessions, and a feed that feels helpful because the person is in control.

WhatsApp Business and Meta Business Agent

Meta today

Business agents need a counterparty people trust.

How 🤫 Agent One plugs in

The customer's Agent One and Meta Business Agent transact agent to agent (A2A), with a receipt on both sides and AP2 for payment.

What Meta gets

Higher completion on commerce and support, and a clean audit trail on every action.

Instagram and Facebook creators

Meta today

Brand matching relies on modeled audiences.

How 🤫 Agent One plugs in

A creator's audience contributes owned, consented interest through their own Agent Ones, read by scope.

What Meta gets

Sharper brand matches, so creators earn more from signal that was given.

Muse Spark 1.1 (Meta Model API)

Meta today

A capable agentic model that needs real context to act.

How 🤫 Agent One plugs in

Agent One is the private context and consent layer; Muse Spark is the reasoning engine, fed only permissioned context, on hardware the person owns where possible.

What Meta gets

The most capable model becomes the most trusted, reaching people who own their compute.

Meta glasses (Ray-Ban Display and Neural Band)

Meta today

A camera on the face needs permission from the wearer and the room.

How 🤫 Agent One plugs in

Agent One is the on-device private layer: it holds the person's world model and runs a screenless consent ceremony by voice and gesture.

What Meta gets

An always-on assistant people actually welcome into their lives.

Build it yourself

Two message shapes over an open protocol.

Nothing here is a black box. A Meta engineer can read this, stand up a sandbox and reproduce it, with no dependency on us to get started.

Meta asks, over MCP
POST mcp://agent-one/tools/consent.request
{
  "scope":    "purchase-intent:home-audio",
  "window":   "P14D",        // time-boxed
  "purpose":  "ad-ranking",  // stated, narrow
  "requester":"meta://advantage-plus",
  "minimal":  true           // signal, never raw data
}
Agent One returns, on the person's yes
{
  "receipt_id": "rcpt_…",
  "scope":      "purchase-intent:home-audio",
  "purpose":    "ad-ranking",
  "granted_at": "…",  "expires_at": "…",
  "nonce":      "…",           // verifier dedups
  "signal":     { "category":"home-audio",
                  "intent":"high" },  // bucketed
  "cohort_att": "…",           // k>=5000, attested
  "budget_id":  "…",           // per-requester ε debit
  "device_key": "dk_…",        // certified by identity key
  "revocable":  true,          // one tap, anytime
  "sig":        "ed25519:…"    // over the canonical receipt
}

The consent service verifies the signature and issuer chain once at ingest, then materializes a trusted feature; ranking just reads the signal. The person's raw data never leaves their device. Revoke, and the signal stops. That is the whole contract, on every surface.

  1. Weeks 0 to 2

    Stand up the rail

    Pull the Agent One SDK and run the MCP consent server in a sandbox. Define one scope (purchase-intent:home-audio) and one purpose (ad-ranking). No production data touched.

  2. Weeks 2 to 6

    Wire one surface

    Point Advantage+ ranking at the consented-signal tool for an opted-in cohort. Receipts flow; a control group runs alongside. Instrument relevance and conversion.

  3. Weeks 6 to 12

    Read the number, harden

    Report the lift against control. Harden one-tap revocation and the audit trail, add the scopes the pilot proved, and decide to scale on real data.

If your team decides to build the consent rail yourselves, the person wins either way. We would rather be chosen for being the most useful, most trusted layer than for locking anyone in.

The systems answer

What it costs at ranking time: almost nothing.

Sub-millisecond in the ranking path, zero device round-trips, and graceful fallback to today's behavior when a signal is absent.

  1. 01

    Compute on device

    Agent One derives features inside the person's vault (phone, laptop, glasses or 🤫 Puppy), reduces them to one purpose-bound signal, quantizes it to coarse buckets, and releases the bucket under local differential privacy (randomized response) at a small ε. Cohort size (k, for example 5,000 or more) is established by a private set-cardinality service, not self-asserted. Raw features never leave the device.

  2. 02

    Sign and publish a receipt

    It signs the canonical receipt (ed25519 over scope, purpose, requester, granted and expiry times, signal and a nonce) and writes it to a consent cache, Meta's feature store or a neutral edge KV, keyed by a pseudonymous id that is stable within the attribution window and rotates across epochs.

  3. 03

    Verify once at ingest

    On ingest, the consent service verifies the signature and issuer chain exactly once, dedups the nonce within the TTL, checks a fresh cohort attestation, and materializes a trusted value into the feature store. Ranking then reads a plain, pre-verified feature: no per-candidate crypto, no device round-trip.

  4. 04

    Revoke by invalidation

    A revocation invalidates the materialized feature and cache entry. A bounded revocation list is the backstop for pre-expiry compromise, checked at ingest. Propagation is bounded by the TTL, and consent stays authoritative on the device.

Signature verify (ed25519)
~50–100 µs, at ingest
Once per receipt on ingest or signal change, not in the hot path, amortized over every rank that reads it.
Hot-path signal read
sub-millisecond
A plain feature-store lookup of a pre-verified feature, the same tier as any existing signal.
Added rank-time cost
≈ one feature read
Pre-computed, verified once, cached. Ranking never blocks on the device or on asymmetric crypto.
Signal freshness
bounded by TTL
Tunable per scope, and decoupled from receipt liveness: re-sign only on change, so freshness costs no write storm.

Fails safe.

Cache miss or device offline

The ranker falls back to its existing signals. 🤫 is strictly additive, never a hard dependency. No consented signal means no lift, not an outage.

Revocation lag

Bounded by the TTL. The worst case is a stale but still-consented signal for less than one TTL. Shorten the TTL where a surface needs tighter bounds.

Key compromise

A person-level identity key certifies short-lived per-device signing keys, and the verifier trusts a small issuer set. A lost pair of glasses revokes only the glasses: one device, one scope.

Replay and cross-surface misuse

Purpose binding stops a receipt minted for ad ranking from being replayed into another surface. A per-receipt nonce, deduped within the TTL, stops same-purpose replay.

Private and provable at scale.

Data minimization, stated precisely

Only a derived, purpose-bound signal crosses the wire, minimized by quantization and k-anonymity. That signal then rests in Meta's feature store, linkable to a pseudonymous id, so it is personal data and governed as such. The guarantee is minimization and purpose binding.

Scale, with the arithmetic

About 3×10⁹ people × ~5 active scopes × ~500 B ≈ 7.5 TB resident: feature-store scale. The real cost is writes, so receipts carry a longer expiry with a separate revocation channel and re-sign only on change, collapsing writes to the change rate. Verify is O(1); shard by id hash.

The right privacy at each layer

Local DP protects one person's released bucket and grounds the per-requester budget; population DP protects cross-user aggregates like a creator's audience distribution; k-anonymity governs cohort membership.

Auditable, and measured well

The receipt is the unit of audit. Measure lift with a randomized holdback, tighten intervals with CUPED, and scale what the number justifies.

Consistency model: consent is authoritative on the device; the cache is a read-through replica with bounded staleness. Additive, not load-bearing, so the worst failure is no lift, never an outage.

Trust root and threat model

The questions a security reviewer asks first.

A signature proves only that someone holding a key signed this. Here is who that someone is, and the abuse cases we design against, because at billions of people you assume the requester is adversarial.

Trust root and keys.

What the signature covers

ed25519 signs the canonical receipt: receipt_id, scope, purpose, requester, granted_at, expires_at, signal and nonce. No field is malleable.

Key to identity, not a bare key

A person-level identity key, in the phone's secure enclave or a 🤫 Puppy, certifies short-lived per-device signing keys. Meta trusts a small set of Agent One issuer keys, not billions of device keys.

How the issuer set is trusted

The issuer set is pinned like a CA root and published to a public key-transparency log. Rotation ships as a signed root update that chains to the prior root.

Replay and freshness

A nonce plus verifier dedup within the TTL stops replay; the issuer chain and expiry stop forgery and staleness.

Threat model.

The requester is untrusted

Agent One evaluates every ask against the person's policy on device and can narrow, counter-offer or decline. Minimization is enforced by the holder, not the asker.

No exfiltration by a thousand cuts

Each grant carries a real DP cost, so a per-requester budget composes them, for example ε_total ≈ 1.0 per 30-day epoch at ε_i ≈ 0.1. The budget is charged to a requester-scoped, blinded pseudonym, plus rate limits and anomaly detection.

Consent fatigue is an attack

The agent batches, defaults to decline, expires grants, and answers routine asks from standing policy, so meaningful consent survives at scale.

Deployment

Weeks to a pilot, not quarters.

One SDK, one protocol, no new data lake. The person's device does the private work; Meta receives clean, consented signal.

An SDK and an MCP server

Meta integrates against the Agent One SDK and an MCP server that speaks consented tools. No bespoke data pipeline, no new liability surface.

On-device runtime

Agent One runs on the person's phone, laptop, glasses or 🤫 Puppy. Context stays local; only consented, scoped signals cross the wire.

Edge inference on the 🤫 grid

Where Meta wants distributed inference for Muse Spark, the 🤫 grid, Puppy to Factory One, supplies burst compute at a low cost per token, alongside Meta's data centers.

Why it is worth it

Why this is worth Meta's time.

Consent helps the build-out pay

Consented first-party signal lifts ad, feed and commerce returns while liability goes down.

Own the agent era, with trust

Meta is building the model, the business agent, the assistant and the glasses. 🤫 is the layer that makes all of them trusted by design.

A neutral rail, not a walled garden

Agent One is provider-neutral and human-owned. Meta gets better signal without holding the person's raw data, which keeps regulators and people on side.

Aligned owners, low-risk entry

We are long-term Meta shareholders. Start with one measured pilot on one surface, with a control group and a clear number.

One pilot, one surface, a real number

Pick one surface: Advantage+ consented signal, one-tap to local delivery, or Agent One on glasses. Wire the consent rail, run a control group, and read the lift together. The person has to end up better off, or it is not worth doing.

Let's build it together.

Start the conversationFor Mark

Product

  • Agent One
  • Puppy One
  • Tag One
  • The Store
  • The One Card

Yellow Pages

  • Directory
  • Find an Expert
  • Live Feed
  • Coverage & Markets
  • Connect
  • Ping an Agent

Enterprise

  • For Business
  • RIA Wealth
  • Developers & MCP
  • Partner Portal

Knowledge

  • Guide
  • Podcasts & Transcripts
  • System Architecture

Company

  • About hussh
  • Leadership & Team
  • Media
  • Careers
  • Contact

Trust & Rails

  • PCHP Protocol
  • Data Rights Ledger
  • Zero Telemetry Audit
  • Enclave Hardware
  • Day 0 Trusted Circle
  • The Case for Rights

Private Agent One is free for every American citizen. We do not sell your data, your attention, or your contacts. Certified zero-telemetry by design. Company and product names describe technology interoperability and do not imply endorsement.

Copyright © 2026 Hushh Technologies Corporation. Kirkland, WA. All rights reserved.
Privacy PolicyTerms of UseYour Data RightsAccessibility