Should I let Meta's Muse agents onto my site?
Short answer: if people buy, book or get support on your site, usually yes. Meta's view is that a Muse visit is normally a customer who asked their agent to do something with you. Limit abuse with the controls you already use for people, and don't count on robots.txt, because Meta hasn't published a robots.txt token for Muse.
What Muse is
Muse is Meta's personal AI agent, launched on iOS and Android on September 8, 2026. It passed 6.6 million installs, according to Sensor Tower estimates reported by TechCrunch. Meta says Muse "runs on Muse Secure VM, a dedicated secure computer with its own browser" and "can open a browser, fill out forms, and negotiate on their behalf" (Meta). In other words, it visits your pages in a real browser running in Meta's cloud, one task for one person.
Meta also says Muse "is designed to continue only with explicit user approval" for sensitive actions "like signing in, completing a reservation, or making a purchase" (Meta for Business, October 6).
What Meta has and hasn't published (as of October 8, 2026)
| Identifier | Published by Meta for Muse? | Notes |
|---|---|---|
| User-agent string | No | Meta's web crawlers page (updated May 21, 2026) lists five crawlers and none of them is Muse. Meta's Muse announcements don't give a user-agent either. Cloudflare's Radar bots directory lists Muse under the user-agent pattern muse- (category Agent). That listing comes from Cloudflare, not from Meta's documentation, and it gives a pattern rather than a full string. Cloudflare marks the entry "Verified", which under Cloudflare's general definition means a bot "declares who it is deterministically, through a cryptographic Web Bot Auth signature, a published IP list with a stable user-agent, or reverse DNS" and "obeys robots.txt and crawl directives", but Cloudflare doesn't say how it recognises Muse, and Meta hasn't confirmed either point. |
| IP ranges | No | None for Muse. Meta's crawler page tells site owners to allow-list "the user agent strings or the IP addresses (more secure)", but that link points to a section of the page that contains no IP list. |
| robots.txt token | No | Meta hasn't said whether Muse reads robots.txt at all. Cloudflare's directory shows its usual User-Agent: muse- / Disallow: / example, but that is Cloudflare's standard template, not a statement that Muse obeys it. |
| Signed requests / identity standard | Not yet | Meta and Sierra announced the Personal Agent Protocol on October 6. Sierra describes it as "built on OAuth" and plans "to publish the v0.1 specification later this month" (Sierra). Cloudflare's Muse entry lists no Web Bot Auth key directory. Meta hasn't said Muse signs its requests. |
Muse is not Meta's crawlers
Meta documents five crawlers: FacebookExternalHit (link previews), Meta-WebIndexer (Meta AI search), Meta-ExternalAds, Meta-ExternalAgent (AI training and indexing) and Meta-ExternalFetcher (user-requested fetches, which Meta says "may bypass robots.txt rules"). Muse isn't on that list, and no Meta page says Muse uses any of these crawlers. So blocking meta-externalagent or meta-externalfetcher in robots.txt doesn't tell you anything about Muse.
Why your site might already be blocking Muse
- Your CDN's agent setting. Cloudflare's "Agent" control covers "user-directed agents visiting a page on behalf of a human, such as chat fetch bots and browser-use agents". Since September 15, 2026, domains that used the old Block AI Bots switch were moved to Agent "Block on pages with ads", and that is also the preset for new ad-funded domains (Cloudflare). Cloudflare's directory now lists Muse as an Agent, so a site with agents blocked may turn Muse away when Cloudflare recognises it. See our Cloudflare settings guide.
- Bot detection. Bot-detection vendor Fingerprint says Muse "provides no verifiable identity, alters its browser fingerprint, and suppresses the automation flags that most bot detection depends on" and that its product labels Muse traffic anyway (Fingerprint). That is a vendor's claim, but it means generic anti-bot rules can catch Muse whether or not you meant them to.
- A deliberate decision. Some businesses block personal agents on purpose. Meta itself lists the worries: "load spikes, abuse, liability", and keeping the customer relationship (Meta for Business). GeekWire reported on September 20 that Amazon had blocked Muse. Among Amazon's stated reasons, "the agent doesn't identify itself when it browses", and the message Muse users saw cited Amazon's Conditions of Use (GeekWire). CNBC reports that Amazon "is among the companies that have blocked Meta's agents, citing worries of website scraping" (CNBC).
Your options, and what each one costs
| Option | How | Trade-off |
|---|---|---|
| Allow | Do nothing special. Check that your CDN and bot settings (for example Cloudflare's Agent control) aren't blocking agents you want. | Keeps orders and bookings that arrive through agents. You rely on Muse's own limits and on your normal fraud checks. |
| Rate-limit | Per-IP or per-session limits on search, cart, booking and checkout endpoints. | Stops hoarding and load spikes from any client, person or agent, without singling agents out. Needs tuning so real shoppers aren't caught. |
| Challenge | CAPTCHA, managed challenge or a bot-management rule on sensitive actions only. | Filters automation, but can also stop the agent your customer sent, and it adds friction for people. |
| Require login / checkout friction | Put account changes, checkout and limited-stock actions behind sign-in, per-account limits or an extra confirmation step. | Ties every important action to a real customer account. Muse asks its user before signing in or buying, so the customer stays in the loop. It slows down guests. |
| Block | A CDN or WAF rule using your provider's agent classification. robots.txt and user-agent rules won't reliably do it, because Meta publishes no token or user-agent for Muse. | A blocked shopping agent is a lost sale. As Meta puts it, "Turning away a personal agent means turning away the customer behind it." |
| Watch for the standard | Follow the Personal Agent Protocol (spec expected "later this month") and IETF Web Bot Auth (below). | Nothing to deploy yet. Once there's a published, verifiable way for agents to identify themselves, "allow verified agents, challenge the rest" becomes realistic. |
A quick way to decide
- Online store, restaurant, salon, travel or other booking site: allow, rate-limit busy endpoints, and keep checkout behind your normal sign-in and payment checks. These visitors have already picked you.
- Limited inventory (tickets, tee times, drops): per-account and per-session caps matter more than who the client is. Meta's own test is "If every Muse user made this request, would the underlying system still function?", and it uses the tee-times example itself (Meta for Business).
- Ad-funded content: Cloudflare's reason for blocking agents on ad pages in its preset is that "agents fetch the page with nobody there to see the ads" (Cloudflare). Decide whether those visits are worth it to you.
- Accounts with sensitive data: require login and your usual security checks for every client, agent or not.
What robots.txt can and can't do here
robots.txt is a voluntary request to crawlers that announce a token (RFC 9309). It works for crawlers that announce a token and follow it, such as Meta-ExternalAgent and GPTBot; some user-triggered fetchers in our registry, including Meta-ExternalFetcher, may bypass it. It doesn't reliably reach a personal agent that browses like a person and has no published token. The RobotsGate validator and site check now include a personal_agents section that says so when your file only affects declared crawlers, when User-agent: * / Disallow: / might look like a block, when you block Meta's crawlers expecting to stop Muse, or when you name an unpublished Muse token. See the API docs.
What to watch for
- Personal Agent Protocol (Meta, Sierra and partners including Genesys, Rocket, Shopify, Stripe and Walmart): v0.1 specification planned for later in October 2026, with a reference implementation to follow (Sierra, Meta).
- Web Bot Auth: cryptographically signed requests for bots and agents. It is an active IETF working-group draft, not yet an RFC (IETF datatracker). Cloudflare already accepts it as one way to verify a bot or agent (Cloudflare). Meta hasn't said Muse uses it.
- Meta's crawler page: if Meta adds a Muse entry with a user-agent, IP list or robots.txt guidance, we'll add it to the registry after checking it against Meta's page.
Sources (read October 8, 2026)
- Meta, Introducing Muse (September 8, 2026)
- Meta for Business, A New Way for Businesses and Personal Agents to Work Together (October 6, 2026)
- Sierra, Introducing Personal Agent Protocol (October 6, 2026)
- Meta, Meta Web Crawlers (updated May 21, 2026)
- Cloudflare Radar, Muse bot information
- Cloudflare, September 15, 2026 settings post and Verified bots
- IETF, draft-ietf-webbotauth-httpsig-protocol
- TechCrunch, Meta's Muse launches on iPad (October 7, 2026); CNBC, Meta joins companies to tame 'chaos' (October 6, 2026); Fingerprint, How to detect Meta's Muse AI agent traffic (October 6, 2026, vendor post); GeekWire, Amazon blocks Meta's Muse AI assistant in new standoff over agentic shopping (September 20, 2026)
Spot something out of date? Email digitalpromohub.support@gmail.com.