How Meta Muse and Stripe Link handle autonomous purchases

Muse gets a user-approved Link spend request, then uses a one-time card or Link Pay Token while the agent never sees the user's real card details.

Meta Muse buys on a user's behalf through Stripe Link's wallet for agents. The user approves the purchase total, then Link returns either a one-time-use card for a regular card form or a Link Pay Token for a supported Stripe checkout. Muse does not see the user's underlying card details.

  • On 2026-09-08, Stripe announced that Meta had integrated Link's wallet for agents with Muse.
  • At more than 1 million businesses that accept Link, Muse can use the payment method saved in a US consumer's Link account. Other merchants receive a single-use virtual card scoped to the approved purchase.
  • Stripe said on 2026-09-29 that agentic purchases made with Link had grown 38x over the previous month. It named Muse, Grok Bot, and Instinct as agents using the wallet.
  • Link's support page says eligible purchases may receive free protections. The listed maximums are 500 USD for damage, loss, and theft; 250 USD for no-fee returns; 500 USD for price protection; and 1,000 USD for a refund guarantee.
  • Meta says Muse runs in a dedicated Muse Secure VM. A separate Sentinel service evaluates actions and network egress, and sends approval requests to the Muse client rather than asking the model to interpret consent from its own chat.

1. Muse isolates the action

Meta describes a dedicated virtual machine for each Muse user. Payment credentials are stored outside the agent's runtime. Sentinel controls connector actions and network requests, and can stop execution while it asks the user to approve a sensitive action. The approval dialog is sent directly to the client, not through the Muse conversation.

For purchases, Meta says the credential is tied to the merchant, the approved dollar amount, and a limited validity period. If a one-time card were exposed, those limits would reduce what it could be used for. They do not remove the need for user approval.

Stripe models each purchase as a spend request. It records the amount, seller, and a description of what the agent wants to buy. The --context value must be at least 100 characters and must name the item, seller, and reason for the purchase. The customer sees that text while deciding whether to approve.

The Stripe documentation uses a command shaped like this:

link-cli spend-request create \
  --amount 3500 \
  --context "Purchasing trail running shoes from example.com. The customer selected these after comparing three options with the shopping assistant." \
  --merchant-name "Example Store" \
  --merchant-url "https://example.com"

The agent must also supply an idempotency key in a production integration so a retry does not create a second request for the same purchase intent.

For a Stripe-hosted checkout with Link enabled, the agent can use a Link Pay Token. The token completes the payment step and can fill billing and shipping details without exposing the consumer's normal card number to the agent. Stripe's documentation says the token is valid for up to 30 minutes or until the spend request expires.

For a regular card form, Link returns a one-time-use virtual card. Hosted agents should write card details to a file instead of stdout:

link-cli spend-request retrieve lsrq_... \
  --include card \
  --output-file /tmp/link-card.json

The documented output file uses 0600 permissions. That keeps the full PAN, CVC, and billing address out of model context, terminal output, and application logs. It does not make the file safe to share: the host still has to protect and delete it.

Checkout often reveals shipping or tax after the first approval. Link supports incremental authorization, so the agent can request a higher total on an already approved spend request instead of immediately creating a second hold. The customer must approve the revised amount again. Stripe says the safe fallback is to cancel and create a new request if the increase fails.

Link also returns a next_action block when payment needs more work. The documented examples include sending the customer to a 3D Secure URL, asking for another payment method after a decline, and waiting for identity verification before creating a new spend request.

Stripe's 2026-09-29 update says consumers may be eligible for free purchase protections when an agent uses Link for an eligible purchase. Link's support page says the program is offered with XCover through Cover Genius Insurance Services LLC and lists these per-claim maximums:

Protection

Maximum per claim

Damage, loss, and theft

500 USD

No-fee returns

250 USD

Price protection

500 USD

Refund guarantee

1,000 USD

These are eligibility limits, not an unconditional promise for every transaction. Link says coverage depends on the purchase, the information submitted, the terms of service, and regional availability. The protection is part of the Link payment path. It is not a substitute for the approval boundary or for checking the merchant's own return policy.

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.