Rank #1 of 6 in MCP Infrastructure & Registries
Install
Showcase


Try itExperimental
See what an agent can do with Composio before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'recorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Auth credentials — stories about auth credentials in this arenaAuth credentialsevidence →
Stories about auth credentials in this arena
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Deployment self host — stories about deployment self host in this arenaDeployment self hostevidence →
Stories about deployment self host in this arena
Gateway controls — stories about gateway controls in this arenaGateway controlsevidence →
Stories about gateway controls in this arena
Hosted servers — stories about hosted servers in this arenaHosted serversevidence →
Stories about hosted servers in this arena
Observability analytics — stories about observability analytics in this arenaObservability analyticsevidence →
Stories about observability analytics in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Pricing plans — plan structure and value — what each tier costs and what it unlocksPricing plansevidence →
Plan structure and value — what each tier costs and what it unlocks
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Registry discovery — stories about registry discovery in this arenaRegistry discoveryevidence →
Stories about registry discovery in this arena
Sdk clients — stories about sdk clients in this arenaSdk clientsevidence →
Stories about sdk clients in this arena
Tool curation quality — stories about tool curation quality in this arenaTool curation qualityevidence →
Stories about tool curation quality in this arena
Story verdicts — every judged story with its evidenceStory verdicts
Follow the green: where the map greys out is where Composio stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓9/10
unlocks → Scoped API keys · Versioning policy · API sandbox · Full data export
Subscribe to events via webhooks
✓7/10
Build against official SDKs
✓8/10
Issue scoped/least-privilege API credentials for an agent
!5/10
Connect an agent via an official MCP server
✓8/10
Download a machine-readable API spec (OpenAPI or equivalent)
✓9/10
unlocks → Interactive API docs
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
—0/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
~5/10
Plug MCP servers into this product so it can use their tools
—0/10
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
~5/10
Auth credentials — stories about auth credentials in this arenaAuth credentials
Stories about auth credentials in this arena
Maintain separate connected accounts and scoped tokens per end user of my product, so each user's agent acts only on that user's credentials
✓7/10
Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refresh
!4/10
White-label the authorization flow with my own branding and my own OAuth app credentials
~6/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Deployment self host — stories about deployment self host in this arenaDeployment self host
Stories about deployment self host in this arena
Gateway controls — stories about gateway controls in this arenaGateway controls
Stories about gateway controls in this arena
Hosted servers — stories about hosted servers in this arenaHosted servers
Stories about hosted servers in this arena
Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform
✓9/10
Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructure
✓8/10
Turn an existing API definition (OpenAPI) or custom code into a hosted MCP server without writing protocol plumbing
—0/10
Publish my own MCP server on the platform for distribution, discovery, and installation by others
—0/10
Subscribe my agent to events from connected downstream apps (triggers/webhooks) instead of polling them
✓7/10
Observability analytics — stories about observability analytics in this arenaObservability analytics
Stories about observability analytics in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Pricing plans — plan structure and value — what each tier costs and what it unlocksPricing plans
Plan structure and value — what each tier costs and what it unlocks
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Registry discovery — stories about registry discovery in this arenaRegistry discovery
Stories about registry discovery in this arena
Query the platform's registry or catalog through a documented API to discover servers and tools programmatically
✓8/10
Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to it
~5/10
Exercise an MCP server's tools from a browser-based inspector or playground before integrating it
—–
Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agent
~6/10
Sdk clients — stories about sdk clients in this arenaSdk clients
Stories about sdk clients in this arena
Tool curation quality — stories about tool curation quality in this arenaTool curation quality
Stories about tool curation quality in this arena
Rely on the platform scanning or inspecting listed servers for malicious or vulnerable behavior before my agents use them
—–
Compare servers using published quality signals — usage counts, health or liveness checks, scores, or verification badges
—–
Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my context
✓9/10
Sorted by importance (agentic first) (high → low) · 52/52 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 9/10 | Tprobed⚿ | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed⚿ | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ⚿ | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 7/10 | Cclaimed | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | disputed | 5/10 | Dcontradicted | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial± | 5/10 | Xcommunity | |
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | none± | 0/10 | ||
Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform C Catalog | developer | Hosted servers — stories about hosted servers in this arenaHosted servers | 3 | full | 9/10 | Tprobed⚿ | |
Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructure C Connect | developer | Hosted servers — stories about hosted servers in this arenaHosted servers | 3 | full | 8/10 | Tprobed⚿ | |
Query the platform's registry or catalog through a documented API to discover servers and tools programmatically C Api | ai agent | Registry discovery — stories about registry discovery in this arenaRegistry discovery | 3 | full | 8/10 | Tprobed⚿ | |
Maintain separate connected accounts and scoped tokens per end user of my product, so each user's agent acts only on that user's credentials C Multi tenant | platform-engineer | Auth credentials — stories about auth credentials in this arenaAuth credentials | 3 | full | 7/10 | Cclaimed | |
Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agent C Search | developer | Registry discovery — stories about registry discovery in this arenaRegistry discovery | 3 | partial | 6/10 | Tprobed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refresh C Oauth | developer | Auth credentials — stories about auth credentials in this arenaAuth credentials | 3 | disputed | 4/10 | Dcontradicted | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | 0/10 | ⚿ | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | none | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my context C Tool search | ai agent | Tool curation quality — stories about tool curation quality in this arenaTool curation quality | 2 | full | 9/10 | Tprobed⚿ | |
Restrict which servers and individual tools an agent may call through allowlists or per-tool access control C Access control | platform-engineer | Gateway controls — stories about gateway controls in this arenaGateway controls | 2 | full | 7/10 | Cclaimed | |
Subscribe my agent to events from connected downstream apps (triggers/webhooks) instead of polling them C Triggers | developer | Hosted servers — stories about hosted servers in this arenaHosted servers | 2 | full | 7/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapters C Frameworks | developer | Sdk clients — stories about sdk clients in this arenaSdk clients | 2 | partial | 6/10 | Tprobed | |
Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to it C Metadata | developer | Registry discovery — stories about registry discovery in this arenaRegistry discovery | 2 | partial | 5/10 | Tprobed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Xcommunity | |
Drive the publish-and-deploy workflow from an official CLI — authenticate, stage or build a server, push it, and install it into agents C Cli | developer | Sdk clients — stories about sdk clients in this arenaSdk clients | 2 | partial | 4/10 | Tprobed | |
Publish my own MCP server on the platform for distribution, discovery, and installation by others C Publish | developer | Hosted servers — stories about hosted servers in this arenaHosted servers | 2 | none | 0/10 | ⚿ | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
See a log of every tool call that passed through the platform, with enough detail to audit or replay what an agent did C Audit | platform-engineer | Gateway controls — stories about gateway controls in this arenaGateway controls | 2 | none | 0/10 | ||
Turn an existing API definition (OpenAPI) or custom code into a hosted MCP server without writing protocol plumbing C Generate | developer | Hosted servers — stories about hosted servers in this arenaHosted servers | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Compare servers using published quality signals — usage counts, health or liveness checks, scores, or verification badges C Signals | developer | Tool curation quality — stories about tool curation quality in this arenaTool curation quality | 2 | none | untested | none yet | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Exercise an MCP server's tools from a browser-based inspector or playground before integrating it C Playground | developer | Registry discovery — stories about registry discovery in this arenaRegistry discovery | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | none | untested | none yet | |
Rely on the platform scanning or inspecting listed servers for malicious or vulnerable behavior before my agents use them C Security | platform-engineer | Tool curation quality — stories about tool curation quality in this arenaTool curation quality | 2 | none | untested | none yet | |
See transparent pricing per tool call or connection plus documented rate limits before committing to the platform G Pricing | developer | Pricing plans — plan structure and value — what each tier costs and what it unlocksPricing plans | 2 | none | untested | none yet | |
See usage analytics for the servers and tools my org consumes or publishes — call volumes, users, errors, and cost C Analytics | platform-engineer | Observability analytics — stories about observability analytics in this arenaObservability analytics | 2 | none | untested | none yet | |
White-label the authorization flow with my own branding and my own OAuth app credentials C White label | platform-engineer | Auth credentials — stories about auth credentials in this arenaAuth credentials | 1 | partial | 6/10 | Cclaimed | |
Bridge a locally running MCP server into the platform as a managed remote connection without deploying it C Bridge | developer | Deployment self host — stories about deployment self host in this arenaDeployment self host | 1 | none | 0/10 | ⚿ | |
Prototype my agent's tool connections on a meaningful free tier before paying anything G Pricing | developer | Pricing plans — plan structure and value — what each tier costs and what it unlocksPricing plans | 1 | none | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | none | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 33 stories with headroom
What would move Composio’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productPlug MCP servers into this product so it can use their tools
nonemoves agent-readyimpact 45
All evidence describes Composio exposing its own hosted MCP server/toolkits for agents to consume (composio-docs-4, composio-probe-3, composio-probe-rt-1) — the reverse of this story, which asks whether a user can plug external MCP servers INTO Composio so it can use their tools.
Openness — open source, data portability, and self-hosting storiesExport all of my data in open formats and leave
nonemoves PA Scoreimpact 30
No evidence anywhere in the pack of a data export feature, open-format export, or account portability tooling; documentation covers sessions, MCP, auth, CLI, and triggers but nothing about exporting user data or configurations.
Openness — open source, data portability, and self-hosting storiesSelf-host the core product
nonemoves PA Scoreimpact 30
All evidence describes Composio as a hosted/cloud SaaS (sessions, hosted MCP endpoint, cloud webhook delivery) with no documentation or mention of a self-hosted deployment option; community evidence even references 'your cloud solution.' Self-hosting is a fair axis for this type of platform product, but no evidence shows it is supported.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
No evidence in the pack addresses data usage for AI model training, opt-out settings, or privacy controls related to training data; documentation covers sessions, MCP, auth, and CLI but nothing about training-data exclusion policies.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Missing: dedicated interactive API explorer, runnable code snippets, evidence of a try-it-now console.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Missing: any changelog, version-numbering scheme (e.g. v1/v2 endpoints), or explicit deprecation/sunset policy documentation.
Automation depth — how much of the product can run unattendedSchedule recurring jobs or workflows
nonemoves PA Scoreimpact 20
Missing: any documented scheduler, cron syntax, or recurring-job API, and independent confirmation that scheduled workflows actually run.
Registry discovery — stories about registry discovery in this arenaExercise an MCP server's tools from a browser-based inspector or playground before integrating it
nonemoves PA Scoreimpact 20
No evidence pack item describes a browser-based inspector or playground for exercising MCP tools; documentation covers SDK sessions, CLI, meta-tools, and hosted MCP endpoints but never a web UI for pre-integration testing.
Showing the top 8 of 33 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 27 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
docs25 stories
- Run the product headlessly / in CI for automation
- Connect an agent via an official MCP server
- Use an official CLI
- Drive the product through a documented public API
- Issue scoped/least-privilege API credentials for an agent
- Build against official SDKs
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Maintain separate connected accounts and scoped tokens per end user of my product, so each user's agent acts only on that user's credentials
- Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refresh
- White-label the authorization flow with my own branding and my own OAuth app credentials
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Restrict which servers and individual tools an agent may call through allowlists or per-tool access control
- Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform
- Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructure
- Subscribe my agent to events from connected downstream apps (triggers/webhooks) instead of polling them
- Do everything through the API that I can do in the UI
- Query the platform's registry or catalog through a documented API to discover servers and tools programmatically
- Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to it
- Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agent
- Drive the publish-and-deploy workflow from an official CLI — authenticate, stage or build a server, push it, and install it into agents
- Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapters
- Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my context
OpenAPI spec8 stories
- Run the product headlessly / in CI for automation
- Drive the product through a documented public API
- Build against official SDKs
- Download a machine-readable API spec (OpenAPI or equivalent)
- Do everything through the API that I can do in the UI
- Query the platform's registry or catalog through a documented API to discover servers and tools programmatically
- Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to it
- Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapters
MCP docs6 stories
- Connect an agent via an official MCP server
- Drive the product through a documented public API
- Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform
- Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructure
- Query the platform's registry or catalog through a documented API to discover servers and tools programmatically
- Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my context
Hacker News6 stories
- Issue scoped/least-privilege API credentials for an agent
- Set up automations that run autonomously in the background
- Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refresh
- Perform bulk operations across many items at once
- Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform
- Do everything through the API that I can do in the UI
llms.txt4 stories
- Point an agent at llms.txt or agent-oriented docs
- Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platform
- Query the platform's registry or catalog through a documented API to discover servers and tools programmatically
- Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agent
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'reproduced$ curl -si -X POST https://connect.composio.dev/mcp -H 'Content-Type: application/json' -d '<jsonrpc initialize>'
HTTP/2 401
date: Sat, 05 Sep 2026 00:27:13 GMT
content-type: application/json
access-control-allow-headers: Authorization, Content-Type, MCP-Protocol-Version, Mcp-Session-Id, x-consumer-api-[redacted]
access-control-allow-methods: GET, POST, DELETE, OPTIONS
access-control-allow-origin: *
access-control-expose-headers: WWW-Authenticate, Mcp-Session-Id, X-Mcp-Auth-Failure-Reason
access-control-max-age: 600
cache-control: public, max-age=0, must-revalidate
content-security-policy: default-src 'self'; script-src 'self' 'unsafe-inline' 'wasm-unsafe-eval' va.vercel-scripts.com vercel.live www.googletagmanager.com connect.facebook.net unpkg.com app.getdecimal.ai www.dubcdn.com capi-automation.s3.us-east-2.amazonaws.com challenges.cloudflare.com www.google.com www.gstatic.com us.i.posthog.com us-assets.i.posthog.com snippet.meticulous.ai browser.sentry-cdn.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: vercel.live vercel.com logos.composio.dev *.composio.dev images.unsplash.com www.facebook.com www.google-analytics.com www.googletagmanager.com; font-src 'self' data:; connect-src 'self' *.composio.dev *.posthog.com us.i.posthog.com us-assets.i.posthog.com *.sentry.io vitals.vercel-insights.com va.vercel-scripts.com vercel.live wss: www.google-analytics.com *.google-analytics.com www.googletagmanager.com connect.facebook.net *.s3.eu-west-2.amazonaws.com *.launchdarkly.com *.getdecimal.ai api.dub.co www.dubcdn.com md-eecad2978f7a43f5b7838c919258e6de.ecs.us-east-2.on.aws challenges.cloudflare.com www.google.com www.gstatic.com api.workos.com *.workos.com cognito-identity.us-west-2.amazonaws.com user-events-v3.s3-accelerate.amazonaws.com; worker-src 'self' blob:; frame-src 'self' vercel.live www.facebook.com app.getdecimal.ai challenges.cloudflare.com www.google.com snippet.meticulous.ai; frame-ancestors 'none'; object-src 'none'; base-uri 'self'; form-action 'self' www.facebook.com
referrer-policy: strict-origin-when-cross-origin
server: cloudflare
strict-transport-security: max-age=63072000
vary: rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch
www-authenticate: Bearer error="unauthorized", error_description="No [redacted] header on request", resource_metadata="https://connect.composio.dev/.well-known/oauth-protected-resource"
x-content-type-options: nosniff
x-frame-options: DENY
x-matched-path: /mcp
x-mcp-auth-failure-reason: No [redacted] header on request
x-url: https://connect.composio.dev/mcp
x-vercel-cache: MISS
x-vercel-id: sfo1::iad1::wtfrt-1788568033165-d4f9bd684612
cf-cache-status: DYNAMIC
cf-ray: a3611b5f483bcf2a-SJC
{"error":"Authorization required","reason":"No [redacted] header on request"}
$mktemp -d && npm install @composio/core && node -e "console.log('PA_PROBE_OK Composio export:', typeof require('@composio/core').Composio)"reproduced$ mktemp -d && npm install @composio/core && node -e "console.log('PA_PROBE_OK Composio export:', typeof require('@composio/core').Composio)"
\|/
added 15 packages in 600ms
/PA_PROBE_OK Composio export: function
$mktemp -d && uv venv && uv pip install composio && python -c "import composio; print('PA_PROBE_OK composio', composio.__version__)"reproduced$ mktemp -d && uv venv && uv pip install composio && python -c "import composio; print('PA_PROBE_OK composio', composio.__version__)"
PA_PROBE_OK composio 0.21.1
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
7 of 12 testable claims verified · 1 contradicted → integrity 42/100
14 distinct capability claims found in Composio’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
7
Verified
4
Unverified
1
Contradicted
14
Undersold
Verified (10)
“Create a session via SDK call tied to a specific end user”
“Exposes a small set of meta-tools that let an agent discover, authorize, and execute tools across apps at runtime instead of loading every tool definition”
Search and load tools at runtime through meta-tools instead of having thousands of tool definitions stuffed into my contextfullproof ↗
“Sessions can expose a hosted MCP server by passing an mcp flag, giving a remote MCP endpoint without deploying infrastructure”
“Sessions can expose a hosted MCP server by passing an mcp flag, giving a remote MCP endpoint without deploying infrastructure”
Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructurefullproof ↗
“MCP flag can be combined with a direct-tools preset to serve one MCP URL limited to a specific list of tools”
Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructurefullproof ↗
“Official CLI gives coding agents and terminal users a local tool surface to connect apps, execute tools, inspect schemas, and debug”
“CLI can install a native plugin that integrates Composio directly into Codex or Claude Code”
Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapterspartialproof ↗
“Provider adapters convert Composio tools into the native tool format expected by a given agent framework, avoiding custom glue code”
Plug the platform's tools into major agent frameworks and SDKs (Vercel AI SDK, LangChain, CrewAI, OpenAI or Anthropic SDKs) with documented adapterspartialproof ↗
“Composio Connect lets any existing MCP-compatible client reach a shared hosted MCP URL without creating an SDK session”
Point my MCP-compatible client at a hosted remote server URL and reach downstream tools without deploying any infrastructurefullproof ↗
“Provides a remote sandbox tool to run Python for bulk operations or to process large tool responses”
Perform bulk operations across many items at oncepartialproof ↗
Unverified (5)
“Session creation can be scoped to specific toolkits to restrict which tools an agent can access”
Restrict which servers and individual tools an agent may call through allowlists or per-tool access controlfullproof ↗
“MCP flag can be combined with a direct-tools preset to serve one MCP URL limited to a specific list of tools”
Restrict which servers and individual tools an agent may call through allowlists or per-tool access controlfullproof ↗
“Connect/auth pages can be white-labeled with custom logo, name, and full restyling”
White-label the authorization flow with my own branding and my own OAuth app credentialspartialproof ↗
“Delivers every trigger event to a single registered webhook URL, signed for verification”
“Delivers every trigger event to a single registered webhook URL, signed for verification”
Subscribe my agent to events from connected downstream apps (triggers/webhooks) instead of polling themfullproof ↗
Contradicted (1)
“Agent can post a Connect Link in-conversation so the user authenticates and the tool call resumes, with no custom auth UI needed”
Let the platform run OAuth flows for downstream tools and vault the resulting credentials encrypted, with automatic token refreshdisputedproof ↗
Undersold (14)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Drive the product through a documented public APIfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Download a machine-readable API spec (OpenAPI or equivalent)fullproof ↗
Maintain separate connected accounts and scoped tokens per end user of my product, so each user's agent acts only on that user's credentialsfullproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Reach a deep catalog of third-party apps and APIs (hundreds to thousands of integrations) through the platformfullproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Query the platform's registry or catalog through a documented API to discover servers and tools programmaticallyfullproof ↗
Inspect a listed server's tools, input schemas, transport, and hosting attributes before connecting to itpartialproof ↗
Search and browse a large catalog of MCP servers and tools by capability before wiring anything into my agentpartialproof ↗
Drive the publish-and-deploy workflow from an official CLI — authenticate, stage or build a server, push it, and install it into agentspartialproof ↗
Claims outside our story set (1)
Real capability claims found in Composio’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Supports a callback_url to redirect users back to the host app after completing authentication”
source ↗
Business model
Managed tool platform: free developer tier to start, usage-based pricing on tool calls and connected accounts as you scale, plus enterprise plans adding SSO, governance, and audit controls.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime MCP 100% · llms.txt 100% · openapi.json 100% (30d, checked every 6h since Sep 8 '26)
