Composio
Composio is an action layer for AI agents: it offers 1,500+ toolkits with managed per-user OAuth, sessions with tool search and a code sandbox, app triggers, full tool-execution logging and VPC or self-hosted deployment.
Composio is the action layer for AI agents: it holds the connections to other software so an agent can do things in a user's own accounts rather than only talk about them. The unit of work is a session, created for one of the customer's users, which scopes who the agent acts for, which toolkits and tools it can see, how it authenticates, and the state it accumulates during the run.
More than 1,500 toolkits are available, and Composio manages the OAuth redirects, token exchange and refresh behind them. When a tool needs an account that is not connected, the agent can pause, send the user a connect link and retry once the user has authorized; the connection then persists for later sessions.
Tools execute server-side with the credential injected, so tokens never reach the model, and meta tools let the agent search the catalog and run several calls at once. Triggers deliver events from connected apps to the customer's webhook, so an agent can react when an email or ticket arrives.
A persistent sandbox gives the agent a Python environment with helpers for running tools, calling a model, uploading files, making direct API calls and searching the web, for tasks too involved for single calls.
For production, Composio logs every tool execution and trigger event with arguments and responses, retained for up to a year and pullable through a Logs API into a SIEM, with payload storage switchable off.
Security controls include project isolation, scoped API keys with IP allowlists, MFA, encrypted credentials, SOC 2 Type II with reports in a trust center, and deployment options that run Composio in a private VPC, self-hosted with Helm, or with credential keys held in the customer's own KMS. Composio does not run the agent: the model, the reasoning loop and the branching stay with the customer. Pricing is published, from a free tier of 100,000 tool calls a month to a $29 plan plus metered usage.
Vendor details
Canonical URL
https://composio.dev
Category
Agent infrastructure
Company status
independent
Use cases & customers
Target customers
Deployment options
Integrations
Composio offers more than 1,500 toolkits across apps such as Slack, GitHub, Gmail, Notion, Jira, Linear, HubSpot and Salesforce, exposed to an agent through a session with managed OAuth per end user, tool search and multi-execute meta tools. It also ships Python and TypeScript SDKs with provider adapters for the major agent frameworks, sessions over MCP and single-toolkit MCP servers, a CLI and agent plugins for Claude Code and Codex, triggers delivered to the customer's webhook, and a Logs API for streaming tool execution records to a SIEM.
In practice
Your agent needs to act in Slack, GitHub, and Gmail on behalf of each user, and the OAuth and token-refresh work is eating your roadmap. Composio handles managed, per-user authentication and exposes those apps as ready-to-call tools.
You want Claude Code or Cursor to do real work across your apps, not just answer questions. Composio's universal MCP server, Rube, connects the client to over a thousand pre-authenticated tools through a single setup.
You're putting an agent into production and worry it could take an action it shouldn't. Composio adds least-privilege scopes, policy controls on what the agent can do, audit trails, and usage tracking to keep it in bounds.
Sources & related URLs
Research sources
Agentic Index coverage score
8.5 / 14 capabilities · 61%
| Integrations & Tool Calling | Full |
|---|---|
|
Composio's session gives an agent tools from more than 1,500 toolkits, scoped to one of the customer's users, and Composio manages the OAuth redirects, token exchange and refresh behind them: the agent can pause mid-chat, send the user a Connect Link, then retry the tool once the account is connected, and the connected account persists for later sessions. Tools execute server-side with the credential injected, never handed to the model. Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22 |
|
| Workflow Orchestration | Partial |
|
Composio's sandbox is a persistent Python environment where the agent writes code that calls tools programmatically, with helpers for tool execution, LLM calls, file uploads, direct API calls and web search, error correction on generated code, and state that persists across calls, and a MULTI_EXECUTE meta tool runs several tool calls together. No workflow definition, versioned flow, or sequencing and branching that combine deterministic workflow nodes with autonomous agent steps is documented. Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22 |
|
| Knowledge Grounding & RAG | Unable to verify |
|
No retrieval structure that Composio maintains over the customer's own documents is documented. Composio's search surfaces the right tools for a task, and its sandbox can extract text from files an agent is working on. Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22 |
|
| Human Oversight & Guardrails | Partial |
|
Composio constrains what an agent may do: the customer chooses which toolkits, tools and tags a session exposes, project API keys are scoped so that session management and tool execution are separate permissions with per-key IP allowlisting, connected-account scopes limit each user's reach, and the agent pauses for the user to connect an account before a tool runs. No mechanism where a person reviews, approves or must validate an agent action before it commits is documented. Sourcedocs.composio.dev/docs/security/overviewread 2026-09-22 |
|
| Security, Identity & Governance | Full |
|
Composio states SOC 2 Type II compliance with the report and sub-processor list in its Trust Center at trust.composio.dev, and the access surface is specific: organization and project isolation, scoped project API keys that separate session management from tool execution with per-key IP allowlisting, MFA enforceable by an organization admin, credentials encrypted at rest with AES-256-GCM and redacted by default in API responses, and signed webhook deliveries; the pricing page adds SAML or OIDC SSO with SCIM provisioning and customer-managed keys on Enterprise. Sourcedocs.composio.dev/docs/security/overviewread 2026-09-22 |
|
| Observability & Auditability | Full |
|
Composio logs every tool execution and trigger event with the toolkit and action, status, connection and auth-config IDs, the supplied user ID, timing and source, and by default the request arguments and response data, retained for up to one year. A Logs API and both SDKs expose search with filters by user, tool and status, cursor pagination and single-record retrieval, and Composio documents pulling those records into a SIEM or observability platform. Sourcedocs.composio.dev/docs/poc-to-prod/stream-logs-to-a-siemread 2026-09-22 |
|
| Memory & State Persistence | Partial |
|
A Composio session scopes execution state for the run: logs, tool memory, MCP state and sandbox files, with sandbox variables and runtime state persisting across calls and cleared after roughly 12 hours of inactivity, and sessions can be reused, updated and deleted. The scope (the session and its user) and a lifetime are stated. This is state carried through one task, and no memory layer the agent draws on across runs is documented. Sourcedocs.composio.dev/docs/security/data-retentionread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Composio documents four deployment options with their credential boundaries: Composio Cloud, a private VPC deployment inside the customer's network boundary, a self-hosted deployment run in the customer's environment with Helm support, and a customer-managed key deployment where a proxy in the customer's cloud holds credential plaintext under keys in its own KMS (AWS KMS, Google Cloud KMS or HashiCorp Vault Transit). Sourcedocs.composio.dev/docs/security/token-custodyread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Unable to verify |
|
No agent or workflow a buyer adopts whole is documented. Composio ships toolkits and meta tools that let an agent find and run actions, plus examples showing how to build applications, but a tool catalog is a set of integrations rather than ready-made workflows, templates or role-specific agents. Sourcedocs.composio.dev/docs/how-composio-worksread 2026-09-22 |
|
| Triggers & Channel Coverage | Full |
|
Composio triggers react to events in connected apps and deliver them to the customer's webhook as structured payloads, with documented pages for activating a trigger for a user, receiving events through an SDK subscription or in production, and listing, enabling, disabling and deleting trigger instances; a worked example runs an agent when an email arrives. Sourcedocs.composio.dev/docs/triggersread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
Composio states that the agent and its model stay entirely the customer's: it never proxies the customer's LLM or runs an agent on its behalf, and its provider adapters serve tools to whatever framework and model the customer runs. The model is the customer's choice throughout. Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Composio ships Python and TypeScript SDKs, a CLI, a current REST API (v3.1) with a published reference, provider adapters for the major agent frameworks, sessions exposed over MCP, single-toolkit MCP servers and an agent skill for wiring Composio into a coding agent. Sourcedocs.composio.dev/llms.txtread 2026-09-22 |
|
| Testing, Debugging & Optimization | Unable to verify |
|
No evaluation harness, scored test cases, quality gate or post-deployment optimization loop for the customer's agent is documented. Composio's documentation covers building, authenticating and running tools, with production readiness and rate-limit guidance, but no gate or debugging path for agent behavior. Sourcedocs.composio.dev/llms.txtread 2026-09-22 |
|
| Browser & Computer Use | Unable to verify |
|
No browser, desktop or remote computer session that Composio drives for an agent is documented. Composio acts through authenticated APIs, and its sandbox runs code, which is code execution rather than computer use; no headless fetch or browser engine of Composio's own is documented either. Sourcedocs.composio.dev/docs/sandbox/remoteread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
A per project option to skip data logging is now Zero Data Retention, an organization add on at Composio that an admin can switch on for every project at once. With it on, tool calls run without storing request arguments, responses or error text, and logs keep only metadata such as IDs, timing and status.
Bears on: Security / enterprise
View sourceComposio CLI 0.2.31 included security dependency updates: authlib bumped to 1.7.2 for GHSA-wvwj-cvrp-7pv5 and protobufjs pinned to 7.5.5 for a critical Socket.dev CVE.
Bears on: Security / enterprise
View sourcePricing
Free (100K tool calls/mo) · Scale $29/mo + usage · Enterprise custom
Monthly platform fee plus usage: tool calls and delivered trigger events
Included quota
Free: 20K tool calls a month with community support. $29 plan: 200K calls with email support. $229 plan: 2M calls with Slack support. Premium tools (search, sandboxes, inference) meter at 3x standard rates and carry hourly rate limits (1K/hr free, 10K/hr paid).
What is public
Composio publishes a full rate card: plan allowances, per-tool-call and per-trigger-event rates, per-call prices for the security add-ons on Scale, and a feature comparison across Free, Scale and Enterprise. Enterprise itself is quoted.
Billing mechanics
Free stops at the included limits, so no charge is incurred unexpectedly. Scale adds a $29 monthly platform fee carrying $29 of usage credit, then meters tool calls and delivered trigger events; several security options are metered add-ons. Enterprise is quoted, with SSO, SCIM, customer-managed keys and SLA-backed support.
Cost watchouts
The governance options are metered on Scale rather than included: IP allowlisting, a HIPAA BAA, zero data retention and white-labeled connection pages each add a per-call, per-event or per-connection charge, and they are only bundled on Enterprise. Composio-managed shared OAuth apps carry lower allowances that count against the free tier, so production volume needs the customer's own OAuth app. The $29 monthly usage credit expires each billing month.
Variable cost rationale
Two flat units, the tool call at $0.0005 and the delivered trigger event at $0.003, keep the bill linear with usage, and the Free plan stops at its limits rather than billing over them. What pushes a heavy month up is the metered security add-ons on Scale (IP allowlist, HIPAA BAA, zero data retention), each charged per tool call or trigger event on top of the base rate, and the $29 usage credit expiring each month rather than rolling over.
Additional watchouts
On Scale, the $29 of usage credit does not roll over, and usage beyond it is metered per tool call and per trigger event, with security options such as IP allowlisting, a HIPAA BAA and zero data retention metered on top.
Overage / add-ons
Past the free amounts: $0.0005 per tool call and $0.003 per delivered trigger event; connected accounts are unlimited and free; meta tools such as tool search are not billed.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free plan: 100,000 tool calls, 50,000 trigger events and 3 team members a month
Lowest paid plan
Scale, $29 a month including $29 of usage credit, then $0.0005 per tool call and $0.003 per trigger event
Commercial notes
Composio has raised $29M in total (a seed from Elevation/Together and a $25M round in 2025). It states SOC 2 Type II and ISO 27001 compliance and claims more than 100K developers.
Key ambiguities
Enterprise pricing is custom. Sandbox LLM tokens are billed only when Composio runs a model for the customer, currently in the sandbox.
Missing data
Enterprise pricing is not published.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Composio
The closest documented capability profiles to Composio among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Deepgram7.5 / 14A lighter documented profile than Composio
- TrueFoundry9.5 / 14Adds documented Testing, Debugging & Optimization
- Metorial8.0 / 14Adds documented Testing, Debugging & OptimizationComposio vs Metorial →
- Cartesia10.5 / 14Adds documented Knowledge Grounding & RAG and Prebuilt Agents, Templates & Packs, among others
- Inworld AI8.5 / 14Adds documented Testing, Debugging & Optimization
- Maxim AI8.5 / 14Adds documented Testing, Debugging & Optimization
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded