Composio
Tool platform for AI agents with pre-authenticated toolkits, per-user sessions, managed authentication, triggers, and a sandboxed workbench across a large app catalog.
Quick decision
What it does
Composio gives AI agents pre-authenticated toolkits, per-user sessions, authentication, triggers, and a sandbox so agents can turn intent into action. The GitHub monorepo describes 1000+ toolkits, tool search, context management, authentication, and a sandboxed workbench. The docs site frames the current product as tools, managed authentication, and secure execution across 1,500+ apps, with smart tool search that surfaces tools by intent and scope at the right time.
The core unit is a session scoped to one of your users. A session loads meta tools that discover, authenticate, and execute app tools at runtime, so the agent does not need hundreds of tool definitions in context. Sessions can be restricted by toolkits, tools, auth configs, and connected accounts, stored and reused across turns, and exposed through a hosted MCP endpoint when you want Claude, Cursor, or another MCP client to connect. Provider adapters translate Composio tools into native formats for OpenAI Agents, Anthropic, Claude Agent SDK, Vercel AI SDK, LangChain, LlamaIndex, CrewAI, AutoGen, and other frameworks listed in the repo.
Composio is an SDK plus hosted platform, not a sandbox computer. Its sandbox is a workbench for running tool backed code with connected accounts, alongside triggers that subscribe to events from connected apps and route them to an agent. Pricing starts free with included monthly tool calls and triggers, then moves to usage based Pro and custom Enterprise terms, with separate handling for Composio-managed apps, direct execution, proxy execution, sandbox execution, and Instant Tools from third party providers.
Verified capabilities
Tools
Pre-authenticated toolkits Source verified
Large catalog of toolkits for apps agents act on, described as 1000+ in the repo and 1,500+ apps on the docs home, with tool search by intent.
Triggers Source verified
Subscribe to events from connected apps, such as new email or new commit style events, and react through subscription handlers or production webhooks.
Sessions
Per-user sessions Source verified
Sessions are scoped to one end user, can be reused across turns, and can restrict toolkits, tools, auth configs, and connected accounts.
Auth
Managed authentication Source verified
OAuth, API keys, and tokens are handled per end user, with session meta tools that walk users through connection and authorization flows.
MCP
Hosted MCP per session Source verified
Every session can expose a hosted MCP endpoint, so MCP clients can use the same session tools and connected accounts.
Execution
Sandboxed workbench Source verified
A sandbox pre-wired with the user connected accounts and toolkit access for running tool backed code safely, described in repo and docs.
Frameworks
Framework provider adapters Source verified
Provider packages adapt session tools to OpenAI, OpenAI Agents, Anthropic, Claude Agent SDK, Vercel, Google, LangChain, LangGraph, LlamaIndex, CrewAI, AutoGen, and more.
Quick start
Create a Composio session in Python
Install the Python SDK, set your Composio API key, create a session for one user, and get OpenAI-format tools by default. This is a shortened version of the PyPI quickstart with placeholder user text.
pip install composio
from composio import Composio
composio = Composio()
session = composio.create(user_id="user_123")
tools = session.tools()
print(tools)Source: https://pypi.org/project/composio/. Examples use placeholders only. Never paste a real key into a profile, config file you share, or a ticket.
MCP support: Composio has a documented hosted MCP path. Every session can expose a hosted MCP endpoint when created with MCP enabled, and the docs link to sessions via MCP and connecting over MCP from clients such as Cursor.
Works with
Packages
TypeScript SDK @composio/core, Python SDK composio on PyPI, a composio CLI, and provider adapter packages for major agent frameworks.
MCP
Session based hosted MCP endpoint for Claude, Cursor, or any MCP client, using the session URL and auth headers.
Frameworks
Adapters listed for OpenAI Agents, Anthropic, Claude Agent SDK, Vercel AI SDK, LangChain, LangGraph, LlamaIndex, Mastra, CrewAI, AutoGen, Google, and others.
API
Sessions, tool execution, triggers, connected accounts, and dashboard managed auth configs through the Composio platform and API reference.
Only sourced support is listed. A missing framework means AgentsUse has not verified it yet, not that it cannot work.
Health and maintenance
30,465
Checked 2026-10-07
4,847
Checked 2026-10-07
Stars, forks, and MIT license read from the fetched GitHub repo page for ComposioHQ/composio. Package name and version read from the fetched PyPI page for composio, release files for 0.25.0. The repo also lists @composio/core as the TypeScript SDK. Weekly downloads were not read, so they are omitted.
Pricing and license
Free Hobby tier with included monthly tool calls, triggers, and team members, then usage based Pro with a monthly usage credit and custom Enterprise terms. Composio-managed apps, Instant Tools, and some execution modes are priced separately on the pricing page. See the pricing URL for current rates.
Limitations and safety
- The free tier is an included allowance, not unlimited use. Past the included amounts, tool calls, triggers, managed app usage, and Instant Tools can bill separately by mode.
- Composio-managed apps have lower allowances and count toward free tier limits on the pricing page, which advises using your own OAuth app for scaling.
- The platform is hosted and session centric. Teams wanting a fully self-hosted integration runtime or raw sandbox computers will find the model opinionated.
Browser and data tools can read pages, fill forms, and download files. Start with a test account or read-only access, keep credentials in environment variables, and review agent actions before connecting anything that can spend money, send messages, or delete data.
Alternatives to Composio
Arcade
Similar tool integration and managed OAuth territory, with a stronger enterprise actions runtime and governance pitch and an open-source MCP framework.
Tradeoff: Arcade is more focused on authorized action runtime, IdP policy, and MCP tools, while Composio is broader on sessions, tool search, triggers, and framework provider adapters.
Toolhouse
Toolhouse also connects agents to many tools and MCP servers and can run workers that deliver finished tasks.
Tradeoff: Toolhouse is now pitched more as AI workers and done-for-you task delivery, while Composio is a developer tool platform with SDK sessions and framework adapters.
Common questions
What does Composio do for an AI agent?
Tool platform for AI agents with pre-authenticated toolkits, per-user sessions, managed authentication, triggers, and a sandboxed workbench across a large app catalog.
Is Composio open source?
Yes. This profile records the license as MIT from the official repository.
Does Composio support MCP?
Composio has a documented hosted MCP path. Every session can expose a hosted MCP endpoint when created with MCP enabled, and the docs link to sessions via MCP and connecting over MCP from clients such as Cursor.
Sources and freshness
- GitHub repo ComposioHQ/composio: https://github.com/ComposioHQ/composio
- Composio documentation: https://docs.composio.dev
- PyPI package composio: https://pypi.org/project/composio/
- Composio pricing: https://composio.dev/pricing
Last checked 2026-10-07. Verification label: source verified, which means public claims trace to the sources above. It does not mean AgentsUse ran the tool. Spotted an error? Send a correction. Back to the tools directory.