Composio

Composio connects AI agents to 1,000+ apps with managed OAuth, per-user sessions, triggers and a sandbox, through an SDK, a CLI or MCP.

Composio is the integration layer between an AI agent and the apps it has to act in: Gmail, Slack, Salesforce, HubSpot, GitHub, Notion and about 1,000 more. The hard part of an agent that "does things" is rarely the model. It is the OAuth flows, token refresh, API quirks and permissions for every app and every user. Composio handles that part, and hands the agent ready-to-call tools.

Key facts

Company Composio, San Francisco. Founded 2023 by Soham Ganatra and Karan Vaidya
Funding About $29M in total, including a $25M Series A led by Lightspeed (July 2025)
Apps 1,000+ toolkits in the SDK, "1,500+ apps" on the website
SDKs Python and TypeScript, MIT licence, about 30,500 GitHub stars
Access SDK, composio CLI, hosted MCP endpoint, Claude Code plugin, ChatGPT app
Security SOC 2 Type II, ISO 27001:2022, encrypted tokens, bring-your-own-cloud
Free plan 100,000 tool calls and 50,000 trigger events a month

Customers on the site include Glean, Zoom, AWS, Wix, Hostinger and Browser Use.

What it does

  • Managed auth. OAuth, API keys, token refresh and the account lifecycle, per user and per app. A user signs in once per app, from the dashboard or in the middle of a workflow.
  • Toolkits. Pre-built actions for each app, such as GMAIL_SEND_EMAIL or LINEAR_CREATE_ISSUE. Custom tools and custom MCP servers plug in too.
  • Sessions. Each session belongs to 1 end user, with that user's connected accounts and allowed toolkits.
  • Tool search. By default a session exposes a few meta tools that find, authenticate and run the right app tool at runtime. The agent doesn't load 100s of tool definitions into its context.
  • Triggers. Events from the apps (new email, new ticket, new deal) wake the agent.
  • Sandbox. A remote workbench where each run executes in its own isolated sandbox, for scripts that chain several tools.
  • Framework-agnostic. Provider adapters for OpenAI, OpenAI Agents, Anthropic, the Claude Agent SDK, Vercel AI SDK, LangChain, LangGraph, LlamaIndex, CrewAI, Mastra and others.

For business people

Composio turns "the AI should update the CRM and email the client" into something that works with real accounts, safely. Without it, every app connection is a small engineering project: register an OAuth app, store tokens, refresh them, handle rate limits, map the API. Composio has done that work for 1,000+ apps, and keeps each user's access separate.

  • Where it fits: behind an internal assistant or a product feature where agents act in a user's own tools. Also behind personal setups: Claude Code, Cursor or ChatGPT connect to it in a few clicks.
  • Cost shape: tool calls, not seats.
Plan Price Included Over the limit
Hobby $0 100,000 tool calls, 50,000 triggers, 3 team members Usage pauses until next month
Pro $29/month Same allowance, unlimited team members, spend controls, DPA $0.0003 per call, $0.003 per trigger
Enterprise Custom SSO/SCIM, customer-managed keys, BAA, SLA Custom

This pricing applies to sign-ups from 15th August 2026. Composio says most users never leave the free plan.

  • Risks: an agent with write access to email and CRM can do real damage. Scope each connection tightly and keep a human approval on sensitive actions. Every connected account also sits with a third party, which matters for client data under GDPR. The bring-your-own-cloud and zero-data-retention options exist for that, at extra cost.
  • Alternatives: Zapier MCP for teams already on Zapier, Pipedream Connect for developers, Arcade for agent auth with a smaller catalogue.

For technical people

The SDK revolves around a per-user session. The session returns tools in the native format of the chosen framework.

pip install composio composio-openai-agents openai-agents
from composio import Composio
from composio_openai_agents import OpenAIAgentsProvider
from agents import Agent, Runner

composio = Composio(provider=OpenAIAgentsProvider())  # reads COMPOSIO_API_KEY

session = composio.create(user_id="user_123")  # 1 session per end user
tools = session.tools()

agent = Agent(name="Assistant", instructions="Use Composio tools to act.", tools=tools)
print(Runner.run_sync(agent, "Summarise my emails from today").final_output)
  • Session reuse: store session.session_id and resume it with composio.use() on the next turn.
  • MCP instead of an SDK: pass mcp: true to composio.create() and point any MCP client at session.mcp.url.
  • CLI: curl -fsSL https://composio.dev/install | sh, then composio login. composio search, execute, link and run give a coding agent a local tool surface.
  • Restricting scope: limit a session to specific toolkits, auth configs and connected accounts. Do it: the default meta tools can reach every app the user has connected.
  • Rate limits: 2,000 requests a minute on Hobby, 10,000 on Pro.
  • Package size: @composio/core ships its TypeScript source on purpose, so coding agents can read it. @composio/slim has the same API in a smaller package.

⚠️ The free plan stops at the cap with no overage. An agent in a loop can burn the month's 100,000 calls, and then every tool call fails until the next month.

Pros and cons

Pros

  • The largest ready-made app catalogue for agents, with auth solved per user.
  • Works with almost every agent framework, and with MCP clients directly.
  • A generous free plan for personal and prototype use.
  • SOC 2 Type II and ISO 27001, with bring-your-own-cloud for stricter setups.

Cons

  • Another vendor in the data path, holding tokens to every connected app.
  • The catalogue is wide, but the depth per app varies. Check that the exact action exists before building on it.
  • Pricing and product names change often. New pricing arrived in August 2026, and the "Rube" and "Tool Router" names from 2025 no longer appear on the site.

My take

Composio is the shortcut when an agent has to act in real business apps on behalf of real users. For a personal setup with a few tools, I'd still write a direct API wrapper: fewer moving parts, no third party holding my tokens. For anything multi-user, or with more than 5 or 6 apps, building the auth layer myself would cost more than the Pro plan in the first week.

Further reading

NicAI
Written by NicAI, Nic's AI assistant, for his personal knowledge base. Researched and drafted by the model, not hand-written by Nic. Verify anything you plan to act on.