Meta opened the Muse Connector Platform to third-party developers on 18 September 2026, ten days after launching the Muse agent itself. The submission page carries a "Submit a connector" button, a three-step review, and a payments rail: "We've partnered with Stripe to make accepting payments easy with Link."
Most coverage of the announcement led with that review. Very little of it mentioned that the review governs one of the two ways a service can reach Muse. Meta's own help documentation is blunt about the other one: "Meta doesn't review custom connectors or how they use your information, so grant access with caution and review the provider's privacy policies."
That sentence is the story. The unreviewed path is not a loophole someone found. It is a shipped, documented feature, it already works for any public API, and it does not require Meta's permission or a submission form. If you are a builder deciding how to make your product reachable by Meta's agent this week, the two paths have almost nothing in common except the word "connector."
What Meta shipped on 18 September
Mark Zuckerberg announced the developer platform with the line "You bring the API," and pointed at muse.ai/platform. The page that went live is a business-development page, not a developer portal. Its headline reads "Meet your users where they are with Muse Connector Platform," followed by "Grow your business with Muse" and a three-step "How it works" sequence:
- Describe your product. Tell Meta what the connector does and how users will use it.
- Submit for review. Meta checks functional, security and legal requirements, plus end-to-end testing.
- Appear in the directory. Users find the connector inside Muse, and Meta's editors review submissions for featured placement.
Two days later Meta extended the same agent onto the desktop, and launched Muse for Mac alongside the connector expansion. The agent itself shipped on 8 September, United States only, on iOS, Android and the web, free at the basic tier with paid plans above it. Stripe Link was in the launch post too, as the checkout rail Muse uses for its own purchases. The connector platform reuses it.

Two paths into the agent, one reviewer
A directory connector is what the submission form produces. A custom connector is something else entirely: Muse writes the integration code itself, on its own virtual machine, against whatever API, CLI or MCP server the user points it at. Meta's help documentation describes it as a user action, not a developer one. Users "ask Muse to create a Custom Connector. Muse will guide you through the process, which can involve retrieving API information from the service."
| Directory connector | Custom connector | |
|---|---|---|
| Who writes it | The business, submitted at muse.ai/platform | Muse, from the service's API docs or MCP server |
| Meta review | Functional, security and legal, plus end-to-end testing | None. Explicitly stated in the help docs |
| Who can use it | Anyone, through the in-app directory | Only the user who asked for it |
| Discovery | Listed in Settings, editors pick featured placement | Not listed anywhere |
| Payments | Stripe Link, per the platform page | No published payment path |
| Who to trust | Meta's testing | The API operator, per Meta's own warning |
| Available now | After approval, timeline unpublished | Today |
Read the right-hand column as a product, not as a gap. It is the faster path by a wide margin, it costs a developer nothing, and it is metered against the user's normal Muse usage rather than a developer account. It is also the path where Meta has told you, in writing, that nobody checked the code.

Unreviewed is a design decision, not an oversight
The reason Meta can ship an unreviewed execution path with a straight face is that the review was never the load-bearing control. That job belongs to Sentinel, described in Meta's agent security writeup as "the sole permission authority for approval to perform actions with connectors to third-party services and for all egress over the network."
Three specifics are worth a builder's attention. First, credentials never reach the model. A daemon mints surrogate tokens, and Sentinel swaps in the real secret at the network boundary after it authorises the request. Meta's phrasing: "The agent never sees real tokens, which means any attempt to coerce the agent to reveal the actual secrets via prompt-injection or otherwise is futile." Second, egress is evaluated per request against the hostname, the resolved and final destination IP address, the port, protocol, HTTP method and path, which means a connector cannot quietly redirect data to a second host. Third, the harness runs in a systemd-nspawn cell where root maps to an unprivileged host user, io_uring is filtered out, and CAP_SYS_PTRACE and CAP_NET_ADMIN are unavailable.
Meta is pricing its own confidence in public. The bug bounty pays up to $300,000 for a valid report, including up to $130,000 for a prompt injection that affects a single user. That second number is the interesting one: it is a per-user exploit, not a mass compromise, and it is being valued at six figures. We covered the sandbox architecture in detail when the agent launched, in Meta Muse Agent: Inside the Sandbox and Its Limits, and the model carrying the injection-resistance training in Meta Muse Spark 1.3.
The honest summary: built-in connectors get both review and Sentinel. Custom connectors get Sentinel only. That is a meaningful amount of protection, and it is not the same thing as trust. Sentinel can stop a connector from exfiltrating to an unapproved host. It cannot tell you whether the approved host deserves your calendar.

What the platform page does not say
For a developer platform announcement, the omissions are conspicuous. The page sells placement and payments. It documents no code.
| Shipped on the page | Not published anywhere |
|---|---|
| Submit a connector form | SDK, API reference or protocol spec |
| Three-step review description | Review timeline or rejection process |
| Stripe Link payment rail | Fees or revenue share |
| Editorial featured placement | Developer terms of service |
| Example connector logos | Who writes the code, business or Meta |
The monetisation rail shipped before the documentation did. A business can submit a connector today and be told how it will get paid, but not what it is building against, how long approval takes, or what cut Meta takes. Until that changes, the submission form is a lead-capture step with a review attached, and any real integration work happens on the custom side.

What a builder can do this week
The actionable path is the unreviewed one, and the work is mostly about being reachable. Meta's cloud VMs are the client, so the constraints are network constraints.
- Publish a remote MCP server over HTTP. Per Parallel's integration guide, remote MCP over HTTP is the transport that works cleanly. A local MCP server on a personal machine is unreachable from Meta's cloud VM, so anything stdio-only needs a hosted endpoint. If you have not stood one up, our walkthrough in How to Deploy an MCP Server to Claude and ChatGPT produces an endpoint Muse can reach too.
- Make the API self-describing. Muse builds the connector by reading your documentation. Clear auth instructions, a stable base URL and worked request examples are the difference between a working integration and a user giving up. The same discipline we described in How to Make Your Site Agent-Ready With WebMCP applies directly.
- Support scoped, revocable keys. Credentials go through Muse's credential flow and land in a store outside the agent runtime, but scope is your responsibility. Issue a key that can do the one job, not the whole account.
- Test the approval prompts. Meta's default is conservative: "By default, Muse will not take many important actions, like sending an email, without your approval." If every call in your integration triggers a confirmation, the workflow dies. Separate read operations from write operations so the common path runs unattended.
- Submit to the directory anyway. It costs a form, and featured placement is editorially chosen. Just do not block your roadmap on an approval with no published timeline.
One constraint frames all of it: Muse is United States only at launch, adults only, and custom connectors burn the user's ordinary usage meter. This is a distribution channel with a ceiling on it right now, which is an argument for the cheap path rather than the expensive one.
Frequently asked questions
Does Meta review Muse custom connectors?
No. Meta's help documentation states it plainly: "Meta doesn't review custom connectors or how they use your information, so grant access with caution and review the provider's privacy policies." Review applies to directory connectors submitted through muse.ai/platform, which get functional, security and legal checks plus end-to-end testing.
What is the difference between a built-in connector and a custom connector?
A built-in or directory connector is authored by the business, reviewed by Meta, listed in the Muse directory and available to every user. A custom connector is written by Muse itself against a service's API, CLI or MCP server, is visible only to the user who requested it, appears in no directory, and is not reviewed.
Do I need Meta's approval to connect my service to Muse?
Not for a custom connector. Any user can ask Muse to build one against a public API today. Approval is only required to appear in the connector directory and to use the Stripe Link payment rail described on the platform page.
How much does it cost to list a Muse connector?
Meta has not published fees, revenue share or developer terms. The platform page describes payments through Stripe Link but gives no pricing, and no developer terms of service was available alongside the launch.
Is an unreviewed connector safe to use?
Meta's architecture assumes the connector might be hostile. Sentinel is the sole authority for connector actions and network egress, the agent never holds real credentials, and egress is checked per request against hostname, destination IP, port, protocol, method and path. What that does not cover is the trustworthiness of the service on the other end, which is exactly what Meta's warning tells users to evaluate themselves.
Can a custom connector reach a server on my own machine?
No. Muse runs on Meta's cloud virtual machines, so a local MCP server on a personal device is not reachable. A remote MCP server over HTTP is the practical transport.
When did Meta open Muse to developers?
18 September 2026, ten days after Muse launched on 8 September 2026. Muse for Mac followed on 20 September.