We build the part of the agent stack that decides whether a credential should be used at all.
On 19 September 2026 Meta opened the Muse connector platform to developers. The pitch was simple: you bring the API, Muse brings the agent, the browser and the user's context. What the announcement did not bring was an authentication model, a credential-handling mechanism, or a review process for the connectors themselves.
That gap lands on the developer. If you publish a connector that touches a user's invoices, their inbox or their card, you are now the custodian of that user's credential — and the agent using it can read anything it puts in its own context, including a web page telling it to do something else.
Authentication is a solved problem and we do not intend to re-solve it. The open question for agents is authorisation with provenance: not just whether this agent may act, but whether this particular instruction came from the human who granted the permission. That distinction did not matter much when software only did what it was directly told. It matters now.