AWS Builder Center
How Meta's Muse Agent Pays Without Your Real Card

How Meta's Muse Agent Pays Without Your Real Card

A look at how Meta's Muse agent handles payments, pricing, coding, and Bedrock availability, in agentic commerce security.

Cloud Engineer

What Meta announced

On September 8, 2026, Meta launched Muse, a personal AI agent available on iOS, Android, and web, with AI glasses support planned. It can send emails, book travel, and shop on a user's behalf. Basic features are free, with paid tiers at $20/month and $100/month for more autonomous use.
What stood out wasn't the agent itself, but how it moves money, what it costs to build on, and how far the Muse brand actually extends.

How Muse pays: one-time cards through Stripe Link

Muse never touches a user's real card details. Instead, it uses Link by Stripe to generate a disposable card number for each transaction. Once that number is used, it's dead. A leaked number after the fact has nothing left to exploit.
This pattern isn't new to agentic commerce:
  • Privacy.com and Capital One Eno issue virtual cards on demand for online purchases
  • Brex and Ramp give employees capped virtual cards for expense control
  • Free-trial signups often get a $0-limit virtual card to block silent auto-renewal
Muse applies the same idea to an agent making purchase decisions on its own, rather than a human filling out a checkout form.

Why not x402

There's another payment standard getting attention in the AI agent space: x402, created by Coinbase and now governed by the Linux Foundation. It uses the HTTP 402 status code to let an agent pay in stablecoin directly inside a request, with no account or login required.
Muse doesn't use it. Based on what's public so far, the entire payment flow stays on existing card rails through Stripe, with no onchain component. That tracks with adoption reality: most merchants still don't accept stablecoins, so building on the card network reaches far more places an agent might actually want to buy from today.

Where the security risk actually sits

Two questions came up when looking at this design.
Card collision. The issuer checks for uniqueness against active cards before issuing a new number, the same way traditional card issuance works. Two live cards sharing a number at the same time isn't a realistic scenario here.
Phishing. A disposable, transaction-locked card number is a poor phishing target on its own, since there's nothing left to reuse once it's spent. The more interesting detail is in Meta's own bug bounty structure: prompt injection has its own bounty tier, separate from the general pool. That's a signal that the real exposure isn't the card number leaking, it's the agent being manipulated into issuing a legitimate card to the wrong merchant in the first place.

The bug bounty program is open globally

Meta's bounty program pays up to $300,000 for valid reports, with a dedicated tier of up to $130,000 for successful prompt injection attacks. The program has already paid researchers across 45+ countries, with no nationality or residency restriction beyond standard US trade sanctions compliance. Reports go through bugbounty.meta.com.

Muse is a brand, not one product

Digging further, Muse turned out to be a brand covering several models and products, not a single agent app:
  • Muse Spark: the underlying multimodal reasoning model, now at version 1.3
  • Muse Image: an image generation model
  • Muse Video: a video generation model, coming soon
  • Muse Code: a terminal-based coding agent
The consumer-facing Muse app is one product built on top of Muse Spark, packaged for personal task automation.

API pricing sits outside the subscription

Separately from the app's $20/$100 monthly tiers, Muse Spark is available directly through the Meta Model API:
  • Standard: $1.25 per million input tokens, $4.25 per million output tokens
  • Cached input: $0.15 per million tokens, an 88% discount over standard input
  • Contributor tier: $0.10 input / $0.20 output per million tokens, in exchange for letting Meta use your prompts to improve the model

Muse Code handles the coding side

For coding specifically, Meta ships a separate product: Muse Code, a terminal coding agent positioned against Claude Code and Codex.
Instead of one agent working sequentially, Muse Code fans out to parallel sub-agents running in isolated git worktrees. Here's how it stacks up on benchmarks:
BenchmarkMuse Code (Spark 1.2)Claude Code (Opus 5)Codex (GPT-5.6 Terra)
Terminal-Bench 2.182.9%86.7%81.8%
DeepSWE 1.159.3%65.0%64.8%
It edges out Codex on Terminal-Bench 2.1 but trails both on DeepSWE 1.1, which measures agentic coding capability more directly. Muse Code itself is a free download, billed through the same Muse Spark API pricing above.

Is Muse Spark coming to Amazon Bedrock?

Worth checking, since Meta's previous Llama models did land on Bedrock: Muse Spark currently doesn't. It's only distributed through the Meta Model API, Muse Code, and OpenRouter, not through Amazon Bedrock, Azure AI, or Google Cloud Vertex AI.
That's a deliberate break from how Llama shipped. Llama models were released with open weights, which let AWS and Azure host them directly on their own infrastructure. Muse Spark, launched in April 2026 as Meta's first frontier model from Meta Superintelligence Labs, is Meta's first non-open-weight release, distributed only through private preview and API access.
There's a path back to Bedrock, though. In August 2026, Meta's Chief AI Officer Alexandr Wang said an open-weight version based on Muse Spark 1.2 would ship "soon." If that lands, it could reach Bedrock the same way Llama did. Getting the current proprietary 1.3 line onto Bedrock instead would require a direct hosting agreement between Meta and AWS, which hasn't been announced. Either way, there's no confirmed timeline yet.

Trying to sign up hit a region gate

Out of curiosity, I tried creating a Muse account myself.
The landing page's "Try Muse" button led to a phone number or email sign-up screen, then a birthdate confirmation step.
After confirming the birthdate, the flow stopped at "This account needs permission to view this page."
This raises a question worth addressing directly: if the app is region-locked, how does the "open to 45+ countries" bug bounty claim from earlier hold up?
Those are two separate axes. Bounty eligibility is about nationality and residency (barring US-sanctioned countries), while Muse's region lock is about product availability. Meta's bug bounty programs typically issue researchers test accounts precisely for this situation, letting them verify products from outside the public launch region. Whether that specific provision is documented for Muse isn't confirmed here, so anyone planning to actually test it should check the exact test-access procedure on bugbounty.meta.com/scope directly.
This lines up with Muse's stated launch scope: US-only at announcement. The error isn't about the email domain, it's an access gate tied to region (and likely age) verification. Routing around it with a VPN would risk violating the terms of service, so this one stays untested for now.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article