Back to vendors
C

Composio

Visit site
Entry priceFree (100K tool calls/mo) · Scale $29/mo + usage · Enterprise customFull pricing detail

Composio is an action layer for AI agents: it offers 1,500+ toolkits with managed per-user OAuth, sessions with tool search and a code sandbox, app triggers, full tool-execution logging and VPC or self-hosted deployment.

Composio is the action layer for AI agents: it holds the connections to other software so an agent can do things in a user's own accounts rather than only talk about them. The unit of work is a session, created for one of the customer's users, which scopes who the agent acts for, which toolkits and tools it can see, how it authenticates, and the state it accumulates during the run.

More than 1,500 toolkits are available, and Composio manages the OAuth redirects, token exchange and refresh behind them. When a tool needs an account that is not connected, the agent can pause, send the user a connect link and retry once the user has authorized; the connection then persists for later sessions.

Tools execute server-side with the credential injected, so tokens never reach the model, and meta tools let the agent search the catalog and run several calls at once. Triggers deliver events from connected apps to the customer's webhook, so an agent can react when an email or ticket arrives.

A persistent sandbox gives the agent a Python environment with helpers for running tools, calling a model, uploading files, making direct API calls and searching the web, for tasks too involved for single calls.

For production, Composio logs every tool execution and trigger event with arguments and responses, retained for up to a year and pullable through a Logs API into a SIEM, with payload storage switchable off.

Security controls include project isolation, scoped API keys with IP allowlists, MFA, encrypted credentials, SOC 2 Type II with reports in a trust center, and deployment options that run Composio in a private VPC, self-hosted with Helm, or with credential keys held in the customer's own KMS. Composio does not run the agent: the model, the reasoning loop and the branching stay with the customer. Pricing is published, from a free tier of 100,000 tool calls a month to a $29 plan plus metered usage.

Vendor details

Canonical URL

https://composio.dev

Category

Agent infrastructure

Company status

independent

Use cases & customers

Target customers

AI developersplatform teams

Deployment options

SaaSAPI

Integrations

Composio offers more than 1,500 toolkits across apps such as Slack, GitHub, Gmail, Notion, Jira, Linear, HubSpot and Salesforce, exposed to an agent through a session with managed OAuth per end user, tool search and multi-execute meta tools. It also ships Python and TypeScript SDKs with provider adapters for the major agent frameworks, sessions over MCP and single-toolkit MCP servers, a CLI and agent plugins for Claude Code and Codex, triggers delivered to the customer's webhook, and a Logs API for streaming tool execution records to a SIEM.

In practice

Your agent needs to act in Slack, GitHub, and Gmail on behalf of each user, and the OAuth and token-refresh work is eating your roadmap. Composio handles managed, per-user authentication and exposes those apps as ready-to-call tools.

You want Claude Code or Cursor to do real work across your apps, not just answer questions. Composio's universal MCP server, Rube, connects the client to over a thousand pre-authenticated tools through a single setup.

You're putting an agent into production and worry it could take an action it shouldn't. Composio adds least-privilege scopes, policy controls on what the agent can do, audit trails, and usage tracking to keep it in bounds.

Agentic Index coverage score

8.5 / 14 capabilities · 61%

Integrations & Tool Calling Full

Composio's session gives an agent tools from more than 1,500 toolkits, scoped to one of the customer's users, and Composio manages the OAuth redirects, token exchange and refresh behind them: the agent can pause mid-chat, send the user a Connect Link, then retry the tool once the account is connected, and the connected account persists for later sessions. Tools execute server-side with the credential injected, never handed to the model.

Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22

Workflow Orchestration Partial

Composio's sandbox is a persistent Python environment where the agent writes code that calls tools programmatically, with helpers for tool execution, LLM calls, file uploads, direct API calls and web search, error correction on generated code, and state that persists across calls, and a MULTI_EXECUTE meta tool runs several tool calls together. No workflow definition, versioned flow, or sequencing and branching that combine deterministic workflow nodes with autonomous agent steps is documented.

Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22

Knowledge Grounding & RAG Unable to verify

No retrieval structure that Composio maintains over the customer's own documents is documented. Composio's search surfaces the right tools for a task, and its sandbox can extract text from files an agent is working on.

Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22

Human Oversight & Guardrails Partial

Composio constrains what an agent may do: the customer chooses which toolkits, tools and tags a session exposes, project API keys are scoped so that session management and tool execution are separate permissions with per-key IP allowlisting, connected-account scopes limit each user's reach, and the agent pauses for the user to connect an account before a tool runs. No mechanism where a person reviews, approves or must validate an agent action before it commits is documented.

Sourcedocs.composio.dev/docs/security/overviewread 2026-09-22

Security, Identity & Governance Full

Composio states SOC 2 Type II compliance with the report and sub-processor list in its Trust Center at trust.composio.dev, and the access surface is specific: organization and project isolation, scoped project API keys that separate session management from tool execution with per-key IP allowlisting, MFA enforceable by an organization admin, credentials encrypted at rest with AES-256-GCM and redacted by default in API responses, and signed webhook deliveries; the pricing page adds SAML or OIDC SSO with SCIM provisioning and customer-managed keys on Enterprise.

Sourcedocs.composio.dev/docs/security/overviewread 2026-09-22

Observability & Auditability Full

Composio logs every tool execution and trigger event with the toolkit and action, status, connection and auth-config IDs, the supplied user ID, timing and source, and by default the request arguments and response data, retained for up to one year. A Logs API and both SDKs expose search with filters by user, tool and status, cursor pagination and single-record retrieval, and Composio documents pulling those records into a SIEM or observability platform.

Sourcedocs.composio.dev/docs/poc-to-prod/stream-logs-to-a-siemread 2026-09-22

Memory & State Persistence Partial

A Composio session scopes execution state for the run: logs, tool memory, MCP state and sandbox files, with sandbox variables and runtime state persisting across calls and cleared after roughly 12 hours of inactivity, and sessions can be reused, updated and deleted. The scope (the session and its user) and a lifetime are stated. This is state carried through one task, and no memory layer the agent draws on across runs is documented.

Sourcedocs.composio.dev/docs/security/data-retentionread 2026-09-22

Deployment & Data Residency Full

Composio documents four deployment options with their credential boundaries: Composio Cloud, a private VPC deployment inside the customer's network boundary, a self-hosted deployment run in the customer's environment with Helm support, and a customer-managed key deployment where a proxy in the customer's cloud holds credential plaintext under keys in its own KMS (AWS KMS, Google Cloud KMS or HashiCorp Vault Transit).

Sourcedocs.composio.dev/docs/security/token-custodyread 2026-09-22

Prebuilt Agents, Templates & Packs Unable to verify

No agent or workflow a buyer adopts whole is documented. Composio ships toolkits and meta tools that let an agent find and run actions, plus examples showing how to build applications, but a tool catalog is a set of integrations rather than ready-made workflows, templates or role-specific agents.

Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22

Triggers & Channel Coverage Full

Composio triggers react to events in connected apps and deliver them to the customer's webhook as structured payloads, with documented pages for activating a trigger for a user, receiving events through an SDK subscription or in production, and listing, enabling, disabling and deleting trigger instances; a worked example runs an agent when an email arrives.

Sourcedocs.composio.dev/docs/triggersread 2026-09-22

Model Flexibility & Routing Full

Composio states that the agent and its model stay entirely the customer's: it never proxies the customer's LLM or runs an agent on its behalf, and its provider adapters serve tools to whatever framework and model the customer runs. The model is the customer's choice throughout.

Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22

APIs, SDKs & MCP Extensibility Full

Composio ships Python and TypeScript SDKs, a CLI, a current REST API (v3.1) with a published reference, provider adapters for the major agent frameworks, sessions exposed over MCP, single-toolkit MCP servers and an agent skill for wiring Composio into a coding agent.

Sourcedocs.composio.dev/llms.txtread 2026-09-22

Testing, Debugging & Optimization Unable to verify

No evaluation harness, scored test cases, quality gate or post-deployment optimization loop for the customer's agent is documented. Composio's documentation covers building, authenticating and running tools, with production readiness and rate-limit guidance, but no gate or debugging path for agent behavior.

Sourcedocs.composio.dev/llms.txtread 2026-09-22

Browser & Computer Use Unable to verify

No browser, desktop or remote computer session that Composio drives for an agent is documented. Composio acts through authenticated APIs, and its sandbox runs code, which is code execution rather than computer use; no headless fetch or browser engine of Composio's own is documented either.

Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22

The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-29·Security / enterpriseVerified

A per project option to skip data logging is now Zero Data Retention, an organization add on at Composio that an admin can switch on for every project at once. With it on, tool calls run without storing request arguments, responses or error text, and logs keep only metadata such as IDs, timing and status.

Bears on: Security / enterprise

View source
2026-06-09·Security / enterpriseVerified

Composio CLI 0.2.31 included security dependency updates: authlib bumped to 1.7.2 for GHSA-wvwj-cvrp-7pv5 and protobufjs pinned to 7.5.5 for a critical Socket.dev CVE.

Bears on: Security / enterprise

View source
View all 2 changes for Composio →Tracked since Jun 2026 · Verified from public vendor sources

Pricing

Free (100K tool calls/mo) · Scale $29/mo + usage · Enterprise custom

Monthly platform fee plus usage: tool calls and delivered trigger events

Free tier

Included quota

Free: 20K tool calls a month with community support. $29 plan: 200K calls with email support. $229 plan: 2M calls with Slack support. Premium tools (search, sandboxes, inference) meter at 3x standard rates and carry hourly rate limits (1K/hr free, 10K/hr paid).

What is public

Composio publishes a full rate card: plan allowances, per-tool-call and per-trigger-event rates, per-call prices for the security add-ons on Scale, and a feature comparison across Free, Scale and Enterprise. Enterprise itself is quoted.

Billing mechanics

Free stops at the included limits, so no charge is incurred unexpectedly. Scale adds a $29 monthly platform fee carrying $29 of usage credit, then meters tool calls and delivered trigger events; several security options are metered add-ons. Enterprise is quoted, with SSO, SCIM, customer-managed keys and SLA-backed support.

Cost watchouts

The governance options are metered on Scale rather than included: IP allowlisting, a HIPAA BAA, zero data retention and white-labeled connection pages each add a per-call, per-event or per-connection charge, and they are only bundled on Enterprise. Composio-managed shared OAuth apps carry lower allowances that count against the free tier, so production volume needs the customer's own OAuth app. The $29 monthly usage credit expires each billing month.

Variable cost rationale

Two flat units, the tool call at $0.0005 and the delivered trigger event at $0.003, keep the bill linear with usage, and the Free plan stops at its limits rather than billing over them. What pushes a heavy month up is the metered security add-ons on Scale (IP allowlist, HIPAA BAA, zero data retention), each charged per tool call or trigger event on top of the base rate, and the $29 usage credit expiring each month rather than rolling over.

Additional watchouts

On Scale, the $29 of usage credit does not roll over, and usage beyond it is metered per tool call and per trigger event, with security options such as IP allowlisting, a HIPAA BAA and zero data retention metered on top.

Overage / add-ons

Past the free amounts: $0.0005 per tool call and $0.003 per delivered trigger event; connected accounts are unlimited and free; meta tools such as tool search are not billed.

Sales call required

Mixed (some tiers require a call)

Free / trial

Free plan: 100,000 tool calls, 50,000 trigger events and 3 team members a month

Lowest paid plan

Scale, $29 a month including $29 of usage credit, then $0.0005 per tool call and $0.003 per trigger event

Commercial notes

Composio has raised $29M in total (a seed from Elevation/Together and a $25M round in 2025). It states SOC 2 Type II and ISO 27001 compliance and claims more than 100K developers.

Key ambiguities

Enterprise pricing is custom. Sandbox LLM tokens are billed only when Composio runs a model for the customer, currently in the sandbox.

Missing data

Enterprise pricing is not published.

Agentic Index verified 2026-09-22

Alternatives to Composio

The closest documented capability profiles to Composio among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Deepgram7.5 / 14A lighter documented profile than Composio
  • TrueFoundry9.5 / 14Adds documented Testing, Debugging & Optimization
  • Metorial8.0 / 14Adds documented Testing, Debugging & OptimizationComposio vs Metorial →
  • Cartesia10.5 / 14Adds documented Knowledge Grounding & RAG and Prebuilt Agents, Templates & Packs, among others
  • Inworld AI8.5 / 14Adds documented Testing, Debugging & Optimization
  • Maxim AI8.5 / 14Adds documented Testing, Debugging & Optimization

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.