Agentic Commerce Briefing (Crabstone)
A small robot shopper wearing a Meta Muse badge is stopped at an Amazon doorway by a long Conditions of Use scroll, while a seller carrying a laptop that shows the Claude logo is waved through a side entrance marked Seller Central.

Claude Got a Seller Central Plugin. Muse Got the Conditions of Use.

Amazon blocked Meta's Muse from shopping its store, then opened Seller Central to Anthropic's Claude three days later. The line runs between agents Amazon picks and agents customers bring, and Amazon enforces it through the customer's own contract.

Sir John Crabstone

Amazon does not mind AI agents acting for its customers, provided it picked them first. On Sunday night, shoppers sending Meta’s Muse to buy on Amazon met a warning: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” GeekWire noted that Amazon “has spent the past year trying to keep outside agents off its site.” On Wednesday Amazon opened Seller Central to one of them, Anthropic’s Claude.

Sellers are promised a choice. Amazon’s announcement, written by Mary Beth Westmoreland, its vice president of worldwide selling partner experience, says 90% of selling partners already use third-party AI tools. “Our vision,” it goes on, “is that sellers can use the AI agent of their choice.” The plugin connects in “roughly 60 seconds,” reads a seller’s listings and inventory, and can act on them. Every interaction comes with “clear boundaries on what it can access, human approval on actions, and complete audit trails.” Seller Assistant, the post adds, is built on Amazon Bedrock with Anthropic’s Claude models. Sellers may choose any agent they like, from a list of two.

Amazon means to remain the publisher, and it has its own reasons to favor this partner: Amazon is one of Anthropic’s largest investors. Westmoreland told GeekWire the design should be “modular enough for us to continue to publish plugins.” The vision was that sellers “would never have to log into Seller Central.” Muse made shoppers much the same offer, and did the logging in itself.

Amazon’s complaint, reported by GeekWire, is that Meta never said Muse was coming and did not leave Amazon out when asked. The agent does not identify itself when it browses, Amazon adds, and appears to capture and store customer credentials. Meta says Muse keeps credentials in “secure storage” and checks with the user before a purchase. Both agents, by their makers’ accounts, wait for a human’s approval. Only one had Amazon’s.

An agent is a product when Amazon installs it and a breach when the customer does.

The courtesy Amazon asks of Meta is one its own agent has not always extended. Mochi Kids, a Salt Lake City children’s label, had avoided Amazon on purpose, wary of resellers and counterfeits. In January 2026 Modern Retail reported that its catalogue of 4,000 products was for sale there anyway, through Buy for Me. Its founder had fulfilled some orders before realising they came from Amazon. The way out is an email to branddirect@amazon.com. Amazon expects notice before an agent arrives; brands get an address to write to once one has.

The warning repays a second reading. In August the Ninth Circuit vacated the injunction Amazon had won in March against Perplexity’s shopping agent. Its reasoning: “it is the user who ‘accesses’ Amazon’s computers,” and the agent, under the anti-hacking statute, is “a tool, not a person.” A footnote left Amazon free “to regulate access to Amazon.com via private terms of service.” Amazon’s warning does exactly that, charging the agent under a contract only the customer signed. The court handed the question to the contract. Amazon writes the contract.