Amazon Blocked Meta's Muse: AI Agents Have to Prove Who They Are
💡 Tool Tip:User-Agent Parser, JWT Decoder, robots.txt Generator
On the evening of September 20, 2026, people who asked Meta's Muse to shop on Amazon started seeing a popup: continued access by an unauthorized AI agent violates Amazon's Conditions of Use. It was not a glitch but an explicit block. Amazon said it was never told about, and never authorized, Muse's access to its store, and asked Meta to remove Amazon from the experience. Two days earlier, Muse had been the number one free app in Apple's US App Store. The fight looks like a battle over who controls the shopping entrance. Technically, it turns on something much smaller: whether the agent says who it is.
When an agent buys for a user, identity becomes the entry ticket
1. What Happened: The Timeline in Facts
Meta launched Muse on September 8, 2026, as a US-only personal agent that carries out multi-step tasks rather than answering one-off questions, connecting to email, calendar, payments, dining, and shopping. It runs on what Meta calls a secure virtual machine with its own browser. Its connection mechanism sits at the center of the dispute: if a service has a public API, Muse connects using credentials the user provides; if it has no API, Meta says the agent can use the service through a browser the way you would. Within a week, Muse hit number one on Apple's US free-app chart, ahead of ChatGPT, and early users reported it switching an auto insurance policy, hunting down discount codes at checkout, and filling an online grocery cart. On Sunday night, September 20, the block landed.
# What an agent should send when it acts for a user.
# Declare the agent, the principal, and prove it with a signature
# (HTTP Message Signatures, RFC 9421).
GET /dp/B0EXAMPLE HTTP/1.1
Host: www.example-retailer.com
User-Agent: MuseAgent/1.0 (+https://example.com/agent-policy)
Signature-Agent: https://agents.example.com/.well-known/http-message-signatures-directory
X-Agent-Principal: user-hash-7f3a9c # opaque, not a raw account id
X-Agent-Purpose: shopping-assist
Signature-Input: sig1=("@authority" "@path" "user-agent")
Signature: sig1=:MEUCIQ...: # verifiable by the retailer
# Amazon's complaint was simple: the agent never identified itself.
# If you send nothing, expect a bot block, not a conversation.2. Amazon's Four Specific Complaints
Amazon's public reasoning is unusually specific, and worth reading line by line. First, it was not told in advance and did not authorize the access. Second, Muse does not identify itself when it browses. Third, Muse appears to capture and store customer credentials. Fourth, it scrapes account data. An Amazon spokesperson put it this way: third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate. By contrast, Amazon's own agentic shopping feature, Buy for Me, identifies itself and lets brands opt out, which is precisely the line Amazon is drawing between a compliant intermediary and an unwelcome bot.
# Publish an agent policy so crawlers and buyers know the rules
# before they pull a cart through your checkout.
# /.well-known/agent-policy.json
{
"version": "2026-09",
"operator": { "name": "Example Agent Co", "contact": "[email protected]" },
"identification": { "required": true, "signature": "http-message-signatures" },
"actions": {
"browse": { "allowed": true },
"price_compare": { "allowed": true, "rate_limit": "60/hour" },
"checkout": { "allowed": false, "requires": "partner_api_key" }
},
"opt_out": { "method": "headers", "header": "X-Agent-Opt-Out: 1" }
}3. The Legal Backdrop: From Anti-Hacking Law to Terms of Service
To understand why this arrived as a popup rather than a lawsuit, follow the timeline. In March 2026, Amazon won a preliminary injunction against Perplexity over shopping activity conducted through its Comet browser. On August 4, the Ninth Circuit reversed it, ruling that under federal anti-hacking law the user, not the AI company, is the one accessing Amazon's computers. The court denied Amazon's petition for rehearing on September 10. With that avenue closed, one path remained: contract and terms of service. So the message users saw does not accuse anyone of hacking; it cites Amazon's Conditions of Use, which exclude data mining, robots, or similar data gathering and extraction tools but do not explicitly mention AI agents at all. That gap is the most fragile interface in the whole debate. The rules are not written yet, and the agents have already arrived.
// Retailer side: verify the caller, then decide. Do not guess
// "human" versus "bot" from heuristics alone.
import { verifyMessage } from "http-message-signatures";
export async function gate(req) {
const sig = req.headers.get("signature");
if (!sig) return deny("unidentified-agent");
const agentUrl = req.headers.get("signature-agent");
const keyDir = await fetchDirectory(agentUrl); // well-known directory
const ok = await verifyMessage(req, keyDir);
if (!ok) return deny("bad-signature");
const policy = await loadAgentPolicy(req.headers.get("x-agent-purpose"));
if (!policy.allowed) return deny("purpose-not-allowed");
return allow({ principal: req.headers.get("x-agent-principal"), policy });
}4. The Engineering Lesson: Agent Identity Is Not a User-Agent String
For any team building an agent that acts for users on the open web, this incident sets a clear bar: your agent must be able to prove three things to a counterparty with no human in the loop. Who it is, who it acts for, and what it is authorized to do. The industry is moving toward verifiable identity. Sign requests with HTTP Message Signatures (RFC 9421), publish the public key in a well-known directory so the retailer can verify offline, and declare both a principal (an opaque reference, never a raw account ID) and a purpose for the visit. Second, publish policy. Just as robots.txt speaks to crawlers, an agent policy file declares which actions are allowed, which require a partner credential, and how to opt out. Third, practice credential hygiene. Do not capture and store users' raw credentials; let the user's side mint a scoped, capped, expiring delegated token instead.
# Delegated payment without credential capture: pass a scoped,
# single-use token instead of storing the customer's card.
def build_payment(agent, user):
token = agent.payments.mint(
principal=user.id,
merchant="example-retailer",
max_amount=250.00,
scope=["one_time_purchase"],
expires_in_minutes=15,
)
return {
"authorization": f"Bearer {token}", # merchant never sees raw PAN
"on_behalf_of": user.opaque_ref, # no raw account id in transit
}
# Amazon said Muse "appears to capture and store customer credentials."
# The fix is architectural: never hold what you can delegate.5. In Practice: Five Pieces of Code You Can Copy
The first snippet is what an agent's request should carry: an identifiable User-Agent with a policy URL, a Signature-Agent header pointing at its key directory, an opaque principal reference instead of an account ID, a declared purpose, and a signature the retailer can verify. The second is a machine-readable policy file, stating which actions such as browse, price_compare, and checkout are allowed, along with rate limits and an opt-out mechanism. The third is the retailer's gateway logic: verify the signature, load the policy, and only then decide. Do not reduce human versus bot to heuristics. The fourth is delegated payment: a single-use token scoped to one merchant, one amount, and one purpose, so the merchant never sees a raw card number. The fifth is a consent audit record: who authorized what, when, with which declared purpose, and what the verification and outcome were. When a dispute lands, that record is the distance between a paragraph and a legal letter.
// Keep a consent record per agent action. When a dispute lands,
// this is the difference between a paragraph and a lawsuit.
await audit.write({
ts: new Date().toISOString(),
agentId: "muse-personal-agent",
principal: "user-hash-7f3a9c",
merchant: "example-retailer",
action: "checkout_attempt",
userConsent: { granted: true, source: "in-app", at: "2026-09-21T14:02:00Z" },
declaredPurpose: "shopping-assist",
signatureVerified: true,
outcome: "denied-by-merchant-policy",
});6. A Checklist for Both Camps
If you build an agent, answer one question before launch: why should the other side trust you? Carry verifiable identity, state who you act for and why, honor opt-out signals, never capture raw credentials, and keep a consent record for every action taken on a user's behalf. If you run a website or a storefront, treat blanket bot-blocking as a last resort rather than a first reflex, because the traffic you block may contain purchases users genuinely wanted to make. The more durable move is to treat agents as a new class of client: give them a verifiable door, a declared policy, and an opt-in partner API. There is real commercial tension underneath the Amazon and Meta standoff. Amazon generated more than $68 billion in ad revenue last year, a business that depends on people browsing its pages, while blocking shopping agents can also mean missing real orders. The rules are not finished. The direction is clear: prove who you are first, and only then argue about what you may do.
Verify, load policy, then decide
📌 Frequently Asked Questions
Why exactly did Amazon block Muse?
According to Amazon's statements to the press: it was not told in advance and did not authorize the access, Muse does not identify itself when browsing, it appears to capture and store customer credentials, and it scrapes account data. Amazon requested that Meta remove Amazon from the Muse experience.
Why a popup instead of a lawsuit this time?
Because the litigation path stumbled. Amazon won a preliminary injunction against Perplexity in March 2026, but on August 4 the Ninth Circuit ruled that under anti-hacking law the user, not the AI company, accesses Amazon's computers, and it denied rehearing on September 10. That leaves contract and terms of service.
Do AI agents need to identify themselves?
On this evidence, yes. Amazon's position is that third-party apps purchasing on a user's behalf should operate openly and respect a merchant's decision to participate; its own Buy for Me identifies itself and allows brands to opt out. In practice that means verifiable signatures, a traceable User-Agent, and a clear purpose declaration.
How do you avoid storing user credentials?
Replace raw credentials with a delegated token that is scoped, capped, and short-lived: one merchant, one amount, one purpose, single-use or expiring in minutes, so the merchant never sees a raw card number or account ID.
If I run a website, how should I treat agent traffic?
Keep blanket blocking as a last resort and treat agents as a new client class: offer a verifiable entrance, a machine-readable policy (which actions are allowed, rate limits, how to opt out), and a partner API for agents you want to work with.
🔧 Recommended Tools
📚 Sources
- GeekWire — Amazon blocks Meta's Muse AI assistant, citing security and privacy concerns (September 20, 2026)
- Business Insider — Amazon blocks Meta's Muse AI agent from shopping on its site (September 2026)
- TechCrunch — Meta's AI agent has been blocked from using Amazon.com (September 21, 2026)
- Meta — Introducing Muse, a personal AI agent (September 8, 2026)
- U.S. Court of Appeals for the Ninth Circuit — Opinion in the Amazon v. Perplexity appeal (August 4, 2026)
- IETF RFC 9421 — HTTP Message Signatures