Meta opened the Muse Connector Platform to third-party developers on 18 September 2026, ten days after launching the Muse agent itself. The submission page carries a "Submit a connector" button, a three-step review, and a payments rail: "We've partnered with Stripe to make accepting payments easy with Link."

Most coverage of the announcement led with that review. Very little of it mentioned that the review governs one of the two ways a service can reach Muse. Meta's own help documentation is blunt about the other one: "Meta doesn't review custom connectors or how they use your information, so grant access with caution and review the provider's privacy policies."

That sentence is the story. The unreviewed path is not a loophole someone found. It is a shipped, documented feature, it already works for any public API, and it does not require Meta's permission or a submission form. If you are a builder deciding how to make your product reachable by Meta's agent this week, the two paths have almost nothing in common except the word "connector."

What Meta shipped on 18 September

Mark Zuckerberg announced the developer platform with the line "You bring the API," and pointed at muse.ai/platform. The page that went live is a business-development page, not a developer portal. Its headline reads "Meet your users where they are with Muse Connector Platform," followed by "Grow your business with Muse" and a three-step "How it works" sequence:

  1. Describe your product. Tell Meta what the connector does and how users will use it.
  2. Submit for review. Meta checks functional, security and legal requirements, plus end-to-end testing.
  3. Appear in the directory. Users find the connector inside Muse, and Meta's editors review submissions for featured placement.

Two days later Meta extended the same agent onto the desktop, and launched Muse for Mac alongside the connector expansion. The agent itself shipped on 8 September, United States only, on iOS, Android and the web, free at the basic tier with paid plans above it. Stripe Link was in the launch post too, as the checkout rail Muse uses for its own purchases. The connector platform reuses it.

Three raised markers on a track engraved 8, 18 and 20, the middle one highlighted
Muse launched on the 8th, the connector platform on the 18th, the Mac app on the 20th.

Two paths into the agent, one reviewer

A directory connector is what the submission form produces. A custom connector is something else entirely: Muse writes the integration code itself, on its own virtual machine, against whatever API, CLI or MCP server the user points it at. Meta's help documentation describes it as a user action, not a developer one. Users "ask Muse to create a Custom Connector. Muse will guide you through the process, which can involve retrieving API information from the service."

Directory connectorCustom connector
Who writes itThe business, submitted at muse.ai/platformMuse, from the service's API docs or MCP server
Meta reviewFunctional, security and legal, plus end-to-end testingNone. Explicitly stated in the help docs
Who can use itAnyone, through the in-app directoryOnly the user who asked for it
DiscoveryListed in Settings, editors pick featured placementNot listed anywhere
PaymentsStripe Link, per the platform pageNo published payment path
Who to trustMeta's testingThe API operator, per Meta's own warning
Available nowAfter approval, timeline unpublishedToday

Read the right-hand column as a product, not as a gap. It is the faster path by a wide margin, it costs a developer nothing, and it is metered against the user's normal Muse usage rather than a developer account. It is also the path where Meta has told you, in writing, that nobody checked the code.

A forked track where only the Directory branch passes through a gate engraved Review
Both branches reach the agent. Only one passes a reviewer.

Unreviewed is a design decision, not an oversight

The reason Meta can ship an unreviewed execution path with a straight face is that the review was never the load-bearing control. That job belongs to Sentinel, described in Meta's agent security writeup as "the sole permission authority for approval to perform actions with connectors to third-party services and for all egress over the network."

Three specifics are worth a builder's attention. First, credentials never reach the model. A daemon mints surrogate tokens, and Sentinel swaps in the real secret at the network boundary after it authorises the request. Meta's phrasing: "The agent never sees real tokens, which means any attempt to coerce the agent to reveal the actual secrets via prompt-injection or otherwise is futile." Second, egress is evaluated per request against the hostname, the resolved and final destination IP address, the port, protocol, HTTP method and path, which means a connector cannot quietly redirect data to a second host. Third, the harness runs in a systemd-nspawn cell where root maps to an unprivileged host user, io_uring is filtered out, and CAP_SYS_PTRACE and CAP_NET_ADMIN are unavailable.

Meta is pricing its own confidence in public. The bug bounty pays up to $300,000 for a valid report, including up to $130,000 for a prompt injection that affects a single user. That second number is the interesting one: it is a per-user exploit, not a mass compromise, and it is being valued at six figures. We covered the sandbox architecture in detail when the agent launched, in Meta Muse Agent: Inside the Sandbox and Its Limits, and the model carrying the injection-resistance training in Meta Muse Spark 1.3.

The honest summary: built-in connectors get both review and Sentinel. Custom connectors get Sentinel only. That is a meaningful amount of protection, and it is not the same thing as trust. Sentinel can stop a connector from exfiltrating to an unapproved host. It cannot tell you whether the approved host deserves your calendar.

A valve engraved Sentinel swapping a cube marked surrogate for one marked real
The agent holds a surrogate. Sentinel swaps in the real secret at the network edge.

What the platform page does not say

For a developer platform announcement, the omissions are conspicuous. The page sells placement and payments. It documents no code.

Shipped on the pageNot published anywhere
Submit a connector formSDK, API reference or protocol spec
Three-step review descriptionReview timeline or rejection process
Stripe Link payment railFees or revenue share
Editorial featured placementDeveloper terms of service
Example connector logosWho writes the code, business or Meta

The monetisation rail shipped before the documentation did. A business can submit a connector today and be told how it will get paid, but not what it is building against, how long approval takes, or what cut Meta takes. Until that changes, the submission form is a lead-capture step with a review attached, and any real integration work happens on the custom side.

A solid block engraved Stripe Link beside an empty hollow outline engraved SDK
The payment rail shipped. The developer documentation did not.

What a builder can do this week

The actionable path is the unreviewed one, and the work is mostly about being reachable. Meta's cloud VMs are the client, so the constraints are network constraints.

  1. Publish a remote MCP server over HTTP. Per Parallel's integration guide, remote MCP over HTTP is the transport that works cleanly. A local MCP server on a personal machine is unreachable from Meta's cloud VM, so anything stdio-only needs a hosted endpoint. If you have not stood one up, our walkthrough in How to Deploy an MCP Server to Claude and ChatGPT produces an endpoint Muse can reach too.
  2. Make the API self-describing. Muse builds the connector by reading your documentation. Clear auth instructions, a stable base URL and worked request examples are the difference between a working integration and a user giving up. The same discipline we described in How to Make Your Site Agent-Ready With WebMCP applies directly.
  3. Support scoped, revocable keys. Credentials go through Muse's credential flow and land in a store outside the agent runtime, but scope is your responsibility. Issue a key that can do the one job, not the whole account.
  4. Test the approval prompts. Meta's default is conservative: "By default, Muse will not take many important actions, like sending an email, without your approval." If every call in your integration triggers a confirmation, the workflow dies. Separate read operations from write operations so the common path runs unattended.
  5. Submit to the directory anyway. It costs a form, and featured placement is editorially chosen. Just do not block your roadmap on an approval with no published timeline.

One constraint frames all of it: Muse is United States only at launch, adults only, and custom connectors burn the user's ordinary usage meter. This is a distribution channel with a ceiling on it right now, which is an argument for the cheap path rather than the expensive one.

Frequently asked questions

Does Meta review Muse custom connectors?

No. Meta's help documentation states it plainly: "Meta doesn't review custom connectors or how they use your information, so grant access with caution and review the provider's privacy policies." Review applies to directory connectors submitted through muse.ai/platform, which get functional, security and legal checks plus end-to-end testing.

What is the difference between a built-in connector and a custom connector?

A built-in or directory connector is authored by the business, reviewed by Meta, listed in the Muse directory and available to every user. A custom connector is written by Muse itself against a service's API, CLI or MCP server, is visible only to the user who requested it, appears in no directory, and is not reviewed.

Do I need Meta's approval to connect my service to Muse?

Not for a custom connector. Any user can ask Muse to build one against a public API today. Approval is only required to appear in the connector directory and to use the Stripe Link payment rail described on the platform page.

How much does it cost to list a Muse connector?

Meta has not published fees, revenue share or developer terms. The platform page describes payments through Stripe Link but gives no pricing, and no developer terms of service was available alongside the launch.

Is an unreviewed connector safe to use?

Meta's architecture assumes the connector might be hostile. Sentinel is the sole authority for connector actions and network egress, the agent never holds real credentials, and egress is checked per request against hostname, destination IP, port, protocol, method and path. What that does not cover is the trustworthiness of the service on the other end, which is exactly what Meta's warning tells users to evaluate themselves.

Can a custom connector reach a server on my own machine?

No. Muse runs on Meta's cloud virtual machines, so a local MCP server on a personal device is not reachable. A remote MCP server over HTTP is the practical transport.

When did Meta open Muse to developers?

18 September 2026, ten days after Muse launched on 8 September 2026. Muse for Mac followed on 20 September.