Skip to content

Rank #1 of 6 in MCP Infrastructure & Registries

Composio logo

Composio

Composio (ComposioHQ, Inc.) · commercial

30.2k11.8k/yrnpm 631.3k/wk +106npm/wk -50.8kpypi/wk +11k

Access

Install

npmnpm install @composio/core
pippip install composio
installercurl -fsSL https://composio.dev/install | sh

Vendor-official, but review any script before piping it to a shell.

Compare head-to-head

Alternatives to Composio

Showcase

Composio homepage screenshot
homepage · captured Sep 2026 · view live ↗
Composio docs screenshot
docs · captured Sep 2026 · view live ↗

Try itExperimental

See what an agent can do with Composio before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'recorded session — replayed, not live
recorded 2026-09-05 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

51.2/100

Auth credentials — stories about auth credentials in this arenaAuth credentialsevidence →

Stories about auth credentials in this arena

40.3/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

18.8/100

Deployment self host — stories about deployment self host in this arenaDeployment self hostevidence →

Stories about deployment self host in this arena

0.0/100

Gateway controls — stories about gateway controls in this arenaGateway controlsevidence →

Stories about gateway controls in this arena

35.0/100

Hosted servers — stories about hosted servers in this arenaHosted serversevidence →

Stories about hosted servers in this arena

54.2/100

Observability analytics — stories about observability analytics in this arenaObservability analyticsevidence →

Stories about observability analytics in this arena

0.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

7.2/100

Pricing plans — plan structure and value — what each tier costs and what it unlocksPricing plansevidence →

Plan structure and value — what each tier costs and what it unlocks

0.0/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

0.0/100

Registry discovery — stories about registry discovery in this arenaRegistry discoveryevidence →

Stories about registry discovery in this arena

40.8/100

Sdk clients — stories about sdk clients in this arenaSdk clientsevidence →

Stories about sdk clients in this arena

30.0/100

Tool curation quality — stories about tool curation quality in this arenaTool curation qualityevidence →

Stories about tool curation quality in this arena

30.0/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 52/52 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full9/10T

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3full8/10T

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full9/10T

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full8/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full7/10T

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2full7/10C

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2disputed5/10D

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10C

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial±5/10X

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1none±0/10

Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform C

Catalog

developerHosted servers — stories about hosted servers in this arenaHosted servers3full9/10T

Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructure C

Connect

developerHosted servers — stories about hosted servers in this arenaHosted servers3full8/10T

Query the platform's registry or catalog through a documented API to discover servers and tools programmatically C

Api

ai agentRegistry discovery — stories about registry discovery in this arenaRegistry discovery3full8/10T

Maintain separate connected accounts and scoped tokens per end user of my product, so each user's agent acts only on that user's credentials C

Multi tenant

platform-engineerAuth credentials — stories about auth credentials in this arenaAuth credentials3full7/10C

Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agent C

Search

developerRegistry discovery — stories about registry discovery in this arenaRegistry discovery3partial6/10T

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3partial5/10C

Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refresh C

Oauth

developerAuth credentials — stories about auth credentials in this arenaAuth credentials3disputed4/10D

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3none0/10

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3noneuntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3noneuntestednone yet

Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my context C

Tool search

ai agentTool curation quality — stories about tool curation quality in this arenaTool curation quality2full9/10T

Restrict which servers and individual tools an agent may call through allowlists or per-tool access control C

Access control

platform-engineerGateway controls — stories about gateway controls in this arenaGateway controls2full7/10C

Subscribe my agent to events from connected downstream apps (triggers/webhooks) instead of polling them C

Triggers

developerHosted servers — stories about hosted servers in this arenaHosted servers2full7/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10T

Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapters C

Frameworks

developerSdk clients — stories about sdk clients in this arenaSdk clients2partial6/10T

Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to it C

Metadata

developerRegistry discovery — stories about registry discovery in this arenaRegistry discovery2partial5/10T

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial5/10X

Drive the publish-and-deploy workflow from an official CLI — authenticate, stage or build a server, push it, and install it into agents C

Cli

developerSdk clients — stories about sdk clients in this arenaSdk clients2partial4/10T

Publish my own MCP server on the platform for distribution, discovery, and installation by others C

Publish

developerHosted servers — stories about hosted servers in this arenaHosted servers2none0/10

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2none0/10

See a log of every tool call that passed through the platform, with enough detail to audit or replay what an agent did C

Audit

platform-engineerGateway controls — stories about gateway controls in this arenaGateway controls2none0/10

Turn an existing API definition (OpenAPI) or custom code into a hosted MCP server without writing protocol plumbing C

Generate

developerHosted servers — stories about hosted servers in this arenaHosted servers2none0/10

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Compare servers using published quality signals — usage counts, health or liveness checks, scores, or verification badges C

Signals

developerTool curation quality — stories about tool curation quality in this arenaTool curation quality2noneuntestednone yet

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Exercise an MCP server's tools from a browser-based inspector or playground before integrating it C

Playground

developerRegistry discovery — stories about registry discovery in this arenaRegistry discovery2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2noneuntestednone yet

Rely on the platform scanning or inspecting listed servers for malicious or vulnerable behavior before my agents use them C

Security

platform-engineerTool curation quality — stories about tool curation quality in this arenaTool curation quality2noneuntestednone yet

See transparent pricing per tool call or connection plus documented rate limits before committing to the platform G

Pricing

developerPricing plans — plan structure and value — what each tier costs and what it unlocksPricing plans2noneuntestednone yet

See usage analytics for the servers and tools my org consumes or publishes — call volumes, users, errors, and cost C

Analytics

platform-engineerObservability analytics — stories about observability analytics in this arenaObservability analytics2noneuntestednone yet

White-label the authorization flow with my own branding and my own OAuth app credentials C

White label

platform-engineerAuth credentials — stories about auth credentials in this arenaAuth credentials1partial6/10C

Bridge a locally running MCP server into the platform as a managed remote connection without deploying it C

Bridge

developerDeployment self host — stories about deployment self host in this arenaDeployment self host1none0/10

Prototype my agent's tool connections on a meaningful free tier before paying anything G

Pricing

developerPricing plans — plan structure and value — what each tier costs and what it unlocksPricing plans1noneuntestednone yet

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1noneuntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 33 stories with headroom

What would move Composio’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools

    nonemoves agent-readyimpact 45

    All evidence describes Composio exposing its own hosted MCP server/toolkits for agents to consume (composio-docs-4, composio-probe-3, composio-probe-rt-1) — the reverse of this story, which asks whether a user can plug external MCP servers INTO Composio so it can use their tools.

  2. Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave

    nonemoves PA Scoreimpact 30

    No evidence anywhere in the pack of a data export feature, open-format export, or account portability tooling; documentation covers sessions, MCP, auth, CLI, and triggers but nothing about exporting user data or configurations.

  3. Openness — open source, data portability, and self-hosting storiesSelf-host the core product

    nonemoves PA Scoreimpact 30

    All evidence describes Composio as a hosted/cloud SaaS (sessions, hosted MCP endpoint, cloud webhook delivery) with no documentation or mention of a self-hosted deployment option; community evidence even references 'your cloud solution.' Self-hosting is a fair axis for this type of platform product, but no evidence shows it is supported.

  4. Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models

    nonemoves PA Scoreimpact 30

    No evidence in the pack addresses data usage for AI model training, opt-out settings, or privacy controls related to training data; documentation covers sessions, MCP, auth, and CLI but nothing about training-data exclusion policies.

  5. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    Missing: dedicated interactive API explorer, runnable code snippets, evidence of a try-it-now console.

  6. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    Missing: any changelog, version-numbering scheme (e.g. v1/v2 endpoints), or explicit deprecation/sunset policy documentation.

  7. Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows

    nonemoves PA Scoreimpact 20

    Missing: any documented scheduler, cron syntax, or recurring-job API, and independent confirmation that scheduled workflows actually run.

  8. Registry discovery — stories about registry discovery in this arenaExercise an MCP server's tools from a browser-based inspector or playground before integrating it

    nonemoves PA Scoreimpact 20

    No evidence pack item describes a browser-based inspector or playground for exercising MCP tools; documentation covers SDK sessions, CLI, meta-tools, and hosted MCP endpoints but never a web UI for pre-integration testing.

Showing the top 8 of 33 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 27 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

docs25 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'reproduced
$ curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'
HTTP/2 401

date: Sat, 05 Sep 2026 00:27:13 GMT

content-type: application/json

access-control-allow-headers: Authorization, Content-Type, MCP-Protocol-Version, Mcp-Session-Id, x-consumer-api-[redacted]

access-control-allow-methods: GET, POST, DELETE, OPTIONS

access-control-allow-origin: *

access-control-expose-headers: WWW-Authenticate, Mcp-Session-Id, X-Mcp-Auth-Failure-Reason

access-control-max-age: 600

cache-control: public, max-age=0, must-revalidate

content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' va.vercel-scripts.com vercel.live www.googletagmanager.com connect.facebook.net unpkg.com app.getdecimal.ai www.dubcdn.com capi-automation.s3.us-east-2.amazonaws.com challenges.cloudflare.com www.google.com www.gstatic.com us.i.posthog.com us-assets.i.posthog.com snippet.meticulous.ai browser.sentry-cdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: vercel.live vercel.com logos.composio.dev *.composio.dev images.unsplash.com www.facebook.com www.google-analytics.com www.googletagmanager.com; font-src 'self' data:; connect-src 'self' *.composio.dev *.posthog.com us.i.posthog.com us-assets.i.posthog.com *.sentry.io vitals.vercel-insights.com va.vercel-scripts.com vercel.live wss: www.google-analytics.com *.google-analytics.com www.googletagmanager.com connect.facebook.net *.s3.eu-west-2.amazonaws.com *.launchdarkly.com *.getdecimal.ai api.dub.co www.dubcdn.com md-eecad2978f7a43f5b7838c919258e6de.ecs.us-east-2.on.aws challenges.cloudflare.com www.google.com www.gstatic.com api.workos.com *.workos.com cognito-identity.us-west-2.amazonaws.com user-events-v3.s3-accelerate.amazonaws.com; worker-src 'self' blob:; frame-src 'self' vercel.live www.facebook.com app.getdecimal.ai challenges.cloudflare.com www.google.com snippet.meticulous.ai; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self' www.facebook.com

referrer-policy: strict-origin-when-cross-origin

server: cloudflare

strict-transport-security: max-age=63072000

vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch

www-authenticate: Bearer error="unauthorized", error_description="No [redacted] header on request", resource_metadata="https://connect.composio.dev/.well-known/oauth-protected-resource"

x-content-type-options: nosniff

x-frame-options: DENY

x-matched-path: /mcp

x-mcp-auth-failure-reason: No [redacted] header on request

x-url: https://connect.composio.dev/mcp

x-vercel-cache: MISS

x-vercel-id: sfo1::iad1::wtfrt-1788568033165-d4f9bd684612

cf-cache-status: DYNAMIC

cf-ray: a3611b5f483bcf2a-SJC

{"error":"Authorization required","reason":"No [redacted] header on request"}
$mktemp -d && npm install @composio/core && node -e "console.log('PA_PROBE_OK Composio export:', typeof require('@composio/core').Composio)"reproduced
$ mktemp -d && npm install @composio/core && node -e "console.log('PA_PROBE_OK Composio export:', typeof require('@composio/core').Composio)"
\|/
added 15 packages in 600ms
/PA_PROBE_OK Composio export: function
$mktemp -d && uv venv && uv pip install composio && python -c "import composio; print('PA_PROBE_OK composio', composio.__version__)"reproduced
$ mktemp -d && uv venv && uv pip install composio && python -c "import composio; print('PA_PROBE_OK composio', composio.__version__)"
PA_PROBE_OK composio 0.21.1

Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence

7 of 12 testable claims verified · 1 contradictedintegrity 42/100

14 distinct capability claims found in Composio’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.

7

Verified

4

Unverified

1

Contradicted

14

Undersold

Verified (10)
Unverified (5)
Contradicted (1)
Undersold (14)
Claims outside our story set (1)

Real capability claims found in Composio’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.

  • Supports a callback_url to redirect users back to the host app after completing authentication

    source ↗
Suggest a story for these →

Business model

free-tierusage-basedenterprise-custom

Managed tool platform: free developer tier to start, usage-based pricing on tool calls and connected accounts as you scale, plus enterprise plans adding SSO, governance, and audit controls.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 5 '26 — no movement recorded yet
Agent-readytracked since Sep 5 '26 — no movement recorded yet

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data

⚿ auth1 auth-gated probe

Agent surface uptime MCP 100% · llms.txt 100% · openapi.json 100% (30d, checked every 6h since Sep 8 '26)