From 5984e374cef089ba4cd9951dd5eb46aec6d969ba Mon Sep 17 00:00:00 2001 From: operator Date: Sun, 4 Oct 2026 22:43:27 +0000 Subject: [PATCH] docs(onboarding): document hard /access edge gate resolution via Meta Accounts Center and activate dev node --- ACCOUNTS.md | 1 + CLIENT-ONBOARDING-RUNBOOK.md | 21 +++++++++++++++++++++ INSTAGRAM-CRED-POOL.md | 12 ++++++++++++ 3 files changed, 34 insertions(+) diff --git a/ACCOUNTS.md b/ACCOUNTS.md index e935864..12537f0 100644 --- a/ACCOUNTS.md +++ b/ACCOUNTS.md @@ -31,6 +31,7 @@ node name, chrome-box profile, API `--account`, and the agent's display name. | 646 | 646 | 646 | phone_otp | Meta Account | - | yes | unknown | active | 104.28.195.181 | 9430 | 646 | Shares phone number with piparada's account. Logged in 2026-10-03 via phone OTP (first Meta Account option). Node created 2026-10-03 (warp-646, CDP 9430). Browser up, session active (verified 2026-10-03). | | def | def | def | email_otp | defnotabotnet@gmail.com | defnotabotnet@gmail.com | no | yes | active | 104.28.195.181 | 9450 | def | Full onboarding completed 2026-10-04; age verification cleared via Instagram linking (paradahub). Active chat session. | | opm | opm | opm | email_otp | Nico Parada | yourfriendnico@proton.me | no | unknown | active | 104.28.195.181 | 9440 | opm | Node created 2026-10-03 (warp-opm, CDP 9440). Browser up, session active. | +| dev | dev | dev | email_otp | paradaproduced@gmail.com | paradaproduced@gmail.com | no | yes | active | 104.28.195.181 | 9460 | dev | Full onboarding completed 2026-10-04; unlocked /access gate via Meta Accounts Center IG linking (veryraremeta). Active chat session. | ## Login Type Details diff --git a/CLIENT-ONBOARDING-RUNBOOK.md b/CLIENT-ONBOARDING-RUNBOOK.md index 9122430..7a1048a 100644 --- a/CLIENT-ONBOARDING-RUNBOOK.md +++ b/CLIENT-ONBOARDING-RUNBOOK.md @@ -88,6 +88,27 @@ If Instagram linking is not available, operator can complete the verification us --- +### Phase 4.1: Edge Gate — Hard Audience Lockout (`/access` vs `/access/verification`) +- **Observed Behavior**: If an account routes to `https://muse.ai/access` with the text `"Muse isn't available to all audiences."` instead of `https://muse.ai/access/verification`: + - The Meta account is temporarily unverified or lacks linked identity signals. + - The in-app endpoint (`/api/hatch/age-confirmation/linking-web-auth`) returns `403 Forbidden`. + - Reloading or navigating directly to `/` or `/access/verification` immediately redirects back to `/access`. +- **Root Cause**: + - Meta accounts without an active linked profile (Facebook or Instagram) trigger Meta's general audience filter on Muse before the conversational AI product can be initialized. + - In addition, attempting automated sign-in on low-reputation / unverified identities directly from server/VPN IPs will trigger Google reCAPTCHA Enterprise checkpoints (`auth_platform/recaptcha`). +- **Proven Unblocking SOP (The Direct Meta Accounts Center Flow)**: + 1. Open a clean browser session with the target Meta Account signed in (`https://accountscenter.meta.com/`). + 2. Navigate to **Accounts** → **Add Accounts** (`/add_accounts/`). + 3. Enter the Instagram credentials for an older/established IG profile (`veryraremeta`, `paradahub`, etc.) and submit any required 2FA/email OTP. + 4. If returned to Accounts Center, click **Add Instagram** again to initiate the OAuth handoff: + `https://www.instagram.com/fxcal/auth/login/?app_id=633385687760560...&flow=igcalcomet&entry_point=frl_web_settings` + 5. On the *"Meta needs to access info from your Instagram account"* prompt, click **[Continue]**. + 6. Accounts Center returns to the confirmation screen (`/add/?auth_flow=ig_linking&token=...&blob=...`) → click **[Confirm]**. + 7. Meta sends security confirmation: *"Did you just move your profiles into the same Meta Account?"*. + 8. Once confirmed in Accounts Center, simply navigate back or reload `https://muse.ai/` inside the NetVM node. The `/access` lockout drops immediately, and the node enters active chat (*"Hey! I'm your personal agent..."*). + +--- + ### Phase 5: Vitality & Status Monitoring Query individual or fleet-wide health: diff --git a/INSTAGRAM-CRED-POOL.md b/INSTAGRAM-CRED-POOL.md index 0a3b259..112431c 100644 --- a/INSTAGRAM-CRED-POOL.md +++ b/INSTAGRAM-CRED-POOL.md @@ -45,6 +45,18 @@ stateDiagram-v2 - Newly created Instagram accounts without a mature age/identity verification tier or age signal trigger Meta Accounts Center to disable the **"Confirm"** action (`aria-disabled="true"` on `/add_accounts/?flow=HATCH_AGE_VERIFICATION_IG_UPSELL`). - Meta Accounts Center uses Instagram accounts for age verification by checking that the linked Instagram profile itself has established age signals. A freshly minted account created minutes prior lacks this profile history, leaving the age verification unsatisfied. - **Agency Recommendation**: Pre-aged or verified Instagram identities in the pool with established age badges/profiles, or using established client identities, rather than accounts created in the immediate transaction. +- **Dormant / "Ghost" Account Lockout Mode (`/access` Hard Exclusion & Resolution)**: + - An account that has chronological calendar age (e.g. created ~5 months ago) but has **zero posts, zero regular engagement, and no established social graph** can fail Meta's automated audience eligibility check completely upon Muse onboarding, routing to `https://muse.ai/access` (*"Muse isn't available to all audiences"*). + - Attempting automated sign-in on these low-reputation identities from datacenter/VPN egress IPs triggers Google reCAPTCHA Enterprise checkpoints. + - **The "Add Again" Two-Step Handoff Resolution**: + 1. Sign in to `https://accountscenter.meta.com/` using the cached Meta Account session. + 2. Add Account -> complete Instagram sign-on & OTP. + 3. Returning to Meta Accounts Center, click **Add Instagram a second time** (`ADD AGAIN`). + 4. Meta generates the OAuth handoff URL: + `https://www.instagram.com/fxcal/auth/login/?app_id=633385687760560&etoken=...&next=https%3A%2F%2Faccountscenter.meta.com%2Fadd%2F%3Fauth_flow%3Dig_linking%26background_page%3D%252Fmanage&flow=igcalcomet&entry_point=frl_web_settings&initiator_fbid=...` + 5. Prompt displays: `"[] Meta needs to access info from your Instagram account. [Continue] [Not You?]"`. + 6. Clicking **[Continue]** redirects to Accounts Center with query parameters `token` and `blob` (`/add/?auth_flow=ig_linking&token=...&blob=...`). + 7. Clicking **[Confirm]** completes the account merge, prompts Meta's confirmation email (*"Did you just move your profiles into the same Meta Account?"*), and **instantly clears the `/access` block on Muse**, transitioning the session into active chat. - **Session Bleed & OIDC Secondary Auth Trip (`auth.meta.com`)**: - When the link is opened in a browser that has existing Meta session cookies (e.g. from Facebook, Oculus, or another Meta account), selecting the new Instagram identity triggers a secondary OpenID Connect reconciliation trip (`https://auth.meta.com/?waterfall_id=...&redirect_uri=auth.meta.com/oidc/...&source_app_id=633385687760560`). - This prompts the user with **"Log in with your Meta account"** because the browser's ambient Meta session does not match the freshly authenticated Instagram identity.