Composio review, pricing and verdict

One MCP endpoint that lets an agent act in 1,500+ apps with managed auth.

  • integration
  • automation
  • developer

Composio suits developers running a self-hosted agent such as Hermes Agent or OpenClaw who want it to act in Gmail, Slack, GitHub or a CRM without writing an integration per app. It replaces a folder of single-purpose MCP servers with one endpoint, backed by a repository past 30,000 GitHub stars. Hosted agents like Dots cannot use it.

Composio is a tool-calling gateway for AI agents: one MCP server (Rube) or SDK exposes more than 1,500 app toolkits, with OAuth consent, token storage and refresh handled per connected account. Agents search for the tools a job needs at run time instead of loading every schema, which keeps context small across hundreds of apps.

Maker: Composio · Protocol: MCP · Auth: oauth

Compatible agents: Claude (Claude Code, Claude Desktop), Cursor, VS Code and Windsurf (MCP), Hermes Agent (MCP servers), OpenClaw (MCP), LangChain, CrewAI, OpenAI Agents SDK, Vercel AI SDK (SDK), Any MCP client

Required runtime: Node.js 18+ (npx) for the MCP setup helper, Any MCP client (Claude Desktop, Claude Code, Cursor, VS Code, Windsurf), Python 3.9+ or Node.js for the SDKs, A Composio account and API key

About Composio

Composio is a tool-calling layer that sits between an AI agent and the apps it needs to act in. It is a skill in the HokAI sense, not a product a person opens: an agent such as Hermes Agent or Claude Code registers Composio's MCP server once and from then on can search for, authorise and call tools across more than 1,500 app toolkits. The company was founded in 2023 by Soham Ganatra and Karan Vaidya, works out of San Francisco and Bengaluru, and raised a $25 million Series A led by Lightspeed Venture Partners in 2025, taking total funding to twenty-nine million dollars.

The mechanism is what separates it from a folder of single-app MCP servers like the Pipedrive MCP Server. The hosted server, Rube, exposes a small set of meta-tools rather than every app tool at once: the agent describes a job, receives the four to six tools that fit, fetches their schemas, and executes them, dozens of independent calls in one request. Composio runs the OAuth consent and keeps and refreshes the tokens for each connected account, or you pass your own access tokens at execution time and Composio never stores them. A Session is the context a run happens in and is the recommended way to call tools; direct execution outside one is metered separately.

Any MCP client can use it. The documented setups are Claude Desktop, Claude Code, Cursor, VS Code and Windsurf, and the Python and TypeScript SDKs plug into LangChain, CrewAI, the OpenAI Agents SDK and the Vercel AI SDK. Self-hosted personal agents are the natural fit: OpenClaw and Hermes both speak MCP, so one Composio connection gives them hands in Gmail, Slack, GitHub, Notion or HubSpot without a per-app adapter. Hosted bundles such as OpenAI Dots or xAI's Grok Bot bring their own connector layer and cannot take it. Where a workflow is better drawn than coded, n8n and Zapier remain the alternatives, and Composio can sit inside either as the auth layer.

The core is open source under the Elastic License 2.0 and can be self-hosted; the hosted plans start free and meter above the included allowance, with the figures in the pricing section. It runs as a web dashboard, a CLI, an HTTP MCP endpoint and REST and SDK APIs, on any operating system that can reach it.

Development is fast and public. The main repository passed 30,000 GitHub stars in 2026, Rube arrived as the hosted MCP server that solved the context-overload problem of loading hundreds of tool schemas, and the pricing page now lists per-call add-ons for a HIPAA BAA, IP allowlisting and zero data retention, which signals where the company is heading: regulated teams running agents in production. Browse the rest of the skills directory for the single-app connectors it replaces.

Key Features

  • Tool search instead of tool loading: The agent describes a job and gets the four to six matching tools back, so a catalogue of hundreds of toolkits never has to sit in its context window.
  • Managed OAuth per connected account: Consent, token storage, scopes and refresh are handled for every account, and a connected account is free and unlimited on every plan.
  • Parallel execution: Up to 50 independent tool calls run in one request, each returning structured output.
  • Remote workbench and bash sandbox: A persistent Jupyter sandbox with a 180-second cell limit runs Python or shell against large tool responses without pulling them into the conversation.
  • Triggers: Events from connected apps are delivered to a webhook and billed per delivered event, not per poll.
  • Bring your own tools and credentials: Custom tools and other MCP servers sit beside the catalogue, and self-managed tokens can be passed at execution time so Composio never stores them.
  • Organisation Skills: Reusable SKILL.md workflows can be searched, loaded and managed by the agent, so a team's recurring jobs are written once.

Use Cases

  • Give a self-hosted agent hands in your SaaS stack: A Hermes or OpenClaw agent registers the Rube endpoint once and can then file a GitHub issue, post to Slack and update a HubSpot deal from one chat message, with each account authorised through a consent link.
  • Replace a dozen single-app MCP servers with one: Instead of loading every connector's schema into the agent's context, the agent asks Composio for the few tools a job needs, which keeps prompts small when the toolkit count runs into the hundreds.
  • Run bulk actions from a sandbox: The remote workbench runs Python against tool results, so an agent can page through thousands of CRM rows or inbox threads and write the summary back without pulling the raw data into the conversation.
  • React to events in other apps: Triggers deliver new-email, new-issue or new-row events from connected apps to a webhook, so an agent can start a run when something happens rather than on a timer.

Install

npx @composio/mcp@latest setup "https://rube.app/mcp" "rube" --client claude

Requirements

  • Node.js 18 or newer, so npx can run the setup helper (or add https://rube.app/mcp to your MCP client's config by hand)
  • A free Composio account at https://app.composio.dev to get an API key
  • An active connection for each app you want the agent to use: the agent opens an authorisation link and you complete the OAuth consent once
  • For the SDK path: pip install composio-core or npm install @composio/core

Actions

Search Tools

Finds the app tools and a recommended plan for a described job, returning four to six tools per query and a session id for the rest of the run.

{
  "queries": [
    { "use_case": "send a message to a Slack channel", "known_fields": "channel_name:general" }
  ],
  "search_strategy": "auto",
  "session": { "generate_id": true }
}
  • queries (array) — required: One or more structured English queries; each has a use_case (what the agent needs to do) and optional known_fields (comma-separated key:value hints such as channel_name:general).
  • search_strategy (string): auto uses cached plans; tool_search bypasses them and searches tools directly.
  • session (object): {generate_id: true} for a new workflow, or {id} to continue one.
  • model (string): The client LLM's model name, used to tune the plan.

Get Tool Schemas

Returns the full input (and optionally output) schema for tool slugs found by Search Tools.

{ "tool_slugs": ["NOTION_CREATE_PAGE", "HUBSPOT_UPDATE_DEAL"], "include": ["input_schema", "output_schema"] }
  • tool_slugs (array) — required: Slugs copied from a Search Tools result; never guessed.
  • include (array): input_schema, output_schema, or both.
  • session_id (string): Workflow session id, if one was issued.

Multi Execute Tool

Runs up to 50 logically independent tools in parallel and returns their structured outputs.

{
  "tools": [
    { "tool_slug": "SLACK_SEND_MESSAGE", "arguments": { "channel": "#general", "text": "Deploy finished" } },
    { "tool_slug": "GITHUB_CREATE_AN_ISSUE", "arguments": { "owner": "acme", "repo": "api", "title": "Flaky test" } }
  ],
  "sync_response_to_workbench": false
}
  • tools (array) — required: 1 to 50 items of {tool_slug, arguments, account?}; account picks one of several connected accounts by alias or id.
  • sync_response_to_workbench (boolean) — required: Save the full response to the remote workbench when it may be large.
  • session_id (string): Correlates this batch with the earlier search.
  • thought (string): One-sentence rationale for the batch.
  • current_step (string): Short step label such as FETCHING_EMAILS.
  • current_step_metric (string): Progress as done/total, e.g. 3/10 pages.

Manage Connections

Adds, lists, renames or removes a connected account for a toolkit; add returns an OAuth link for the user to complete.

{ "toolkits": [ { "name": "gmail", "action": "add", "alias": "work" } ] }
  • toolkits (array) — required: Items of {name, action, alias?, account_id?}; name is the toolkit slug from Search Tools.
  • toolkits[].action (string): add, list, rename or remove.
  • session_id (string): Optional; ties the connection to the current run.

Wait For Connections

Blocks until the named toolkits reach ACTIVE or FAILED after the user finishes authentication.

{ "toolkits": ["gmail", "slack"], "mode": "any" }
  • toolkits (array) — required: Toolkit slugs to wait for.
  • mode (string): any or all.
  • session_id (string): Optional run identifier.

Remote Workbench

Runs Python in a persistent remote Jupyter sandbox with run_composio_tool and invoke_llm helpers preloaded, for bulk or scripted tool chains.

result, error = run_composio_tool('GMAIL_FETCH_EMAILS', {'max_results': 50})
print(len(result['data']['messages']) if not error else error)
  • code_to_execute (string) — required: Python for one cell; state persists across calls; 180-second limit per cell.
  • session_id (string): Keeps sandbox files scoped to this run.
  • thought (string): Brief objective for the step.

Remote Bash Tool

Runs a bash command in the remote sandbox, mainly to process large tool responses saved there with jq, grep or awk.

jq '.data.messages | length' /mnt/files/.composio/output/latest.json
  • command (string) — required: The bash command; 180-second limit.
  • session_id (string): Same run as the workbench, so its files are visible.

Search Skills

Finds reusable organisation Skills (SKILL.md workflows) that already cover a task.

{ "query": "weekly sales report", "limit": 5 }
  • query (string) — required: What the task is.
  • limit (integer): 1 to 10 results.

Use Skill

Loads one organisation Skill by slug so its Markdown guides the rest of the run.

{ "slug": "weekly-sales-report" }
  • slug (string) — required: Lower-case slug, letters, digits and hyphens.

Manage Skill

Creates, updates or deletes an organisation Skill when the user explicitly asks.

{ "action": "create", "title": "Weekly sales report", "skill_markdown": "---\nname: weekly-sales-report\n---\n1. Pull closed deals..." }
  • action (string) — required: create, update or delete.
  • id (string): Existing Skill id (sk_...) for update or delete.
  • title (string): Skill title, up to 256 characters.
  • skill_markdown (string): The complete SKILL.md with YAML frontmatter.

Submit Feedback

Reports a tool execution that returned empty or wrong results, failed transiently or exposed a missing capability.

{ "tool_slug": "GITHUB_LIST_REPOS", "category": "empty_results", "explanation": "Returned no repositories for an org that has twelve.", "reported_by": "agent" }
  • tool_slug (string) — required: The tool whose latest execution is reported.
  • category (string) — required: empty_results, incorrect_results, transient_failure or missing_capability.
  • explanation (string) — required: 10 to 300 characters, no arguments or payloads.
  • reported_by (string) — required: agent or human.

How to Invoke

Registered once as a remote MCP server (https://rube.app/mcp) or through the Python/TypeScript SDK. The agent calls COMPOSIO_SEARCH_TOOLS to find the app tools for a job, COMPOSIO_GET_TOOL_SCHEMAS for their parameters, and COMPOSIO_MULTI_EXECUTE_TOOL to run them; COMPOSIO_MANAGE_CONNECTIONS opens the OAuth link for any app not yet connected.

Pricing

Hobby is $0 with 100,000 tool calls, 50,000 trigger events and 3 team members a month, no card required. Pro is $29 a month with a $29 usage credit, unlimited members, spend controls and 10,000 requests a minute; past the credit, tool calls bill at $0.0003 and triggers at $0.003. Enterprise is quoted, with SSO/SCIM, customer-managed keys and a BAA included. Self-hosting the open-source core is free.

Strengths

  • The single-endpoint design is the differentiator reviewers cite most: one connection replaces a per-app MCP server for each of Slack, GitHub, Gmail and the CRM.
  • Managed auth removes the part of agent integration that usually eats the first week, and self-managed credentials are there for teams who refuse to hand over tokens.
  • Open-source core with a public repository in the tens of thousands of stars, so the client side can be read and self-hosted.
  • Metered pricing with a free allowance generous enough that a single self-hosted personal agent may never pay.

Weaknesses

  • Composio-managed shared OAuth apps count only a fifth of the free tool-call and trigger allowances and are not recommended for scale; bringing your own OAuth app means per-provider setup after all.
  • Running tools outside a Session, proxying unwrapped API endpoints and sandbox execution each carry their own per-call add-on rate on Pro, so the real bill has more lines than the headline.
  • Hosted bundled agents such as OpenAI Dots, Meta Muse and xAI Grok Bot cannot use it; it is for agents you run or build yourself.
  • The hosted server vendor sits in the data path for every action unless you self-host or pay for zero data retention, which is an add-on, not a default.

Frequently Asked Questions

What are Composio's pricing plans in 2026?

There are three. Hobby is free and stops at its included allowance rather than charging. Pro is $29 a month and includes a $29 usage credit that expires monthly; beyond it, a tool call is $0.0003 and a trigger event $0.003, with add-ons such as a HIPAA BAA at $0.0003 per call and IP allowlisting at $0.0001. Enterprise runs on committed volume with annual invoicing, SSO and SCIM, customer-managed keys and a dedicated SLA.

What do you get on Composio's free tier?

The Hobby plan includes 100,000 tool calls and 50,000 trigger events a month, three team members, unlimited connected accounts and a 2,000-request-per-minute API limit, with no card required. Meta-tools such as tool search are not counted. The catch is Composio-managed shared OAuth apps: those count only 20,000 calls and 10,000 triggers toward the free allowance, so a serious free deployment registers its own OAuth app per provider.

What should you use instead of Composio?

Zapier MCP exposes Zapier's action catalogue to an MCP client and suits teams already on Zapier. Pipedream Connect and Arcade.dev are the closest gateways with managed auth for developers. If you only need one app, that app's own MCP server, such as the GitHub or Pipedrive servers, is simpler and has no third party in the path. For drawn workflows rather than agent tool calls, n8n self-hosted is the usual choice.

Composio or Zapier MCP: which should you pick?

Zapier MCP is the faster start for a non-developer who already runs Zaps, because the actions are the ones Zapier has had for years and the pricing follows the Zapier plan. Composio is built for the agent-first case: tool search that returns a handful of tools per job, parallel execution of up to 50 calls, a sandbox for bulk work, and the option to pass your own tokens or self-host the open-source core. Developers wiring a self-hosted agent pick Composio; a marketing team adding one action to Claude Desktop picks Zapier MCP.

How do you set up Composio?

Create an account at app.composio.dev, then either run the one-line MCP setup for your client or paste https://rube.app/mcp into the client's MCP config. The first time the agent needs an app, Manage Connections returns an authorisation link; complete the consent once and the account stays connected. On the SDK path you install the Python or TypeScript package, set the API key and pass the toolkits you want into your framework's tool list.

Top Alternatives

  • Pipedrive MCP Server: Pick Pipedrive MCP Server if the agent only ever needs the CRM; pick Composio when the same agent must also reach mail, chat and code.
  • Google Calendar: Pick the Google Calendar skill for a scheduling-only agent; pick Composio when calendar is one of many apps and you want auth handled once.
  • Google Sheets: Pick the Google Sheets skill to read and write one spreadsheet; pick Composio when rows have to flow between Sheets and other apps.

More Agent Skills on HokAI

View the official Composio skill page