SubscribeSign In
Agent to Product

Composio Tool Registry for Programmatic Agent Integrations

Composio handles authentication and app integrations so agents can actually do work.

Senior Correspondent · · 9 min read
Cover illustration for “Composio Tool Registry for Programmatic Agent Integrations”
Integration at Scale · September 26, 2026 · 9 min read · 1,973 words

Advertisement

ORBITAnalytics built for editors.

An agent that can plan and reason but can't touch your actual apps is half-built. It's half-built.

Call it wiring. In practice, wiring means OAuth flows that redirect and exchange tokens correctly. It means API keys stored somewhere sane, refresh cycles that fire before a token dies mid-task, and permission scopes that keep an agent from doing more than it should. Each piece is its own small engineering project, with its own way of breaking at 2am. None of it is glamorous, and all of it is required.

Now multiply that by a normal company's stack: Gmail for email, Slack for chat, GitHub for code, Notion for docs, HubSpot for marketing, Salesforce for sales. The auth and plumbing work balloons past the actual agent logic fast. That's the quiet, unglamorous reason so many agent projects stall before they ship, and it's a reason that gets talked about far less than it should.

Model choice and prompt engineering get too much credit, or too much blame, relative to where the real bottleneck sits. A model can reason perfectly and still stop cold the moment it hits a missing authenticated connection. That's a systems problem, plain and simple, and it's the one Composio was built to solve.

What Composio is

Composio is an agent-integration platform, not a no-code automation builder, not an iPaaS, not a general-purpose workflow tool. Its whole reason for existing is giving AI agents authenticated, programmatic access to the outside apps a business actually runs on.

The company started in June 2023 out of San Francisco, founded by Soham Ganatra and Karan Vaidya, both IIT-Bombay graduates. By May 2026 the team had grown to 71 people https://automationatlas.io/tools/composio/. One source pegs headcount at 25 https://checkthat.ai/brands/composio.

The size of the catalogue is the headline fact here, and the exact numbers deserve attention rather than rounding. As of August 11, 2026, Composio's registry counted 1,089 toolkits, each one a single application, and those toolkits together exposed more than 20,000 individual tools https://automationatlas.io/tools/composio/. The browsable toolkits page on composio.dev showed a larger figure, 1,561 entries, around the same period. That reflects everything listed in the open registry, rather than the smaller set that passed a formal audit in August 2026. Know which number is in front of you, since the two measure different things.

Funding tells part of the growth story. Composio raised a $4 million seed from Elevation Capital and Together Fund, then a $25 million Series A led by Lightspeed Venture Partners in July 2025, putting total raised at $29 million https://automationatlas.io/tools/composio/. On GitHub, the project's repository has 26.6 thousand stars and 4.4 thousand forks https://www.augmentcode.com/mcp/composio. Pricing runs a free tier of 20,000 tool calls a month, stepping up to a Pro plan at $29 a month for 200,000 calls, with overage priced at $0.299 per thousand calls https://automationatlas.io/tools/composio/.

Tool registry structure: toolkits, tools, and categories

Two words get thrown around loosely in this space, and Composio draws a hard line between them. A toolkit is one application, full stop: Gmail is a toolkit, Slack is a toolkit, GitHub is a toolkit. A tool is one specific action inside that application, something like GMAIL_SEND_EMAIL or SLACK_POST_MESSAGE.

The real coverage is visible in the ratio between the two. With 1,089 toolkits producing more than 20,000 tools, the average app hands over dozens of distinct, individually callable actions rather than one generic connector. It's exposing dozens of distinct, individually callable actions. An agent limited to "use Gmail" in some vague sense can do almost nothing useful. One with separate send, search, label, archive, and draft functions can call each as its own function, which is the entire difference between a toy and a tool.

Coverage spreads unevenly across categories, and that unevenness says something real about where agent work is actually happening. Productivity and project management leads with 196 toolkits, just ahead of developer tools and DevOps at 192. Engineering and productivity tooling got built out first and deepest, which tracks with who's actually shipping agents right now. Finance and accounting trails behind at 91 toolkits, though that's still a meaningful footprint for a category agents have barely touched.

None of this means much until actual names are named. Gmail, Google Calendar, Google Drive, and Outlook cover inbox and calendar work. Slack handles chat. GitHub, Linear, and Jira sit in the developer and project-tracking world. Notion and Airtable cover docs and structured data. HubSpot and Salesforce run sales and marketing. Supabase shows up for backend data, and Firecrawl and Tavily bring in web search and scraping. Asana rounds out project management. AI & Machine Learning accounts for 136 toolkits. Data & Analytics accounts for 156 toolkits. Marketing & Social Media accounts for 128 toolkits. Document & File Management accounts for 121 toolkits.

Managed authentication: what Composio handles so developers don't have to

Authentication is the actual product on Composio. It's the actual product.

The behavioral model matters as much as the technical coverage does. Authentication triggers on user intent, mid-conversation, an agent saying something like "connect your Slack account" rather than a developer wiring it up in advance. That's a runtime-first design. The practical effect: developers stop building authorization flows by hand, stop storing tokens themselves, and stop writing refresh logic, because none of that lives in their codebase anymore.

Sessions: how Composio binds user, permissions, tools, and state into one runtime context

A session is where all of this actually comes together. It's probably the least visible piece of the design and the most load-bearing. Inside one session, Composio bundles user identity, the accounts that user has connected, the permissions scoped to that connection, tool discovery, the running execution state, and the auth layer itself, all in one place.

That's a meaningfully different idea than storing a credential somewhere and pulling it out when needed. A session works as the actual execution container for whatever the agent is doing on behalf of that specific person. Tool calls run inside a remote sandbox with a navigable filesystem, and the output routes back into the session with history intact, so the agent doesn't wake up amnesiac between one tool call and the next.

Multi-tenancy falls out of this almost for free. Each session ties to one user ID, so a product serving many different users gets natural separation between them without anyone on the engineering team writing isolation logic by hand. That's not a minor convenience: building safe multi-tenant credential isolation from scratch is its own hard problem, and here it ships as a default behavior of the session model rather than a feature someone has to remember to bolt on.

The MCP gateway: one endpoint for the full toolkit catalogue

The design decision here is almost stubbornly simple: one MCP endpoint for the entire 1,089-toolkit catalogue, not one server per app. Most integration platforms would have gone the other way, standing up a separate server or a separate connection per toolkit. Composio didn't.

The reason comes down to how agents actually discover what they need. A Tool Router searches across the full catalogue at run time and only loads what the current task actually requires. That sidesteps the obvious failure mode: pre-loading every integration into context and drowning the model in tool definitions it will never touch for this particular task.

Current setup guidance reflects the shift too. The recommended path is to create a session with MCP enabled and use that session's hosted MCP URL, since the older standalone MCP management API has been deprecated. On the client side, this plugs into Claude Desktop, Cursor, Windsurf, and any other MCP-compatible client. The OpenAI Agents SDK connects through a direct SDK provider integration instead of acting as a standalone MCP client.

Agent runtimes that work with Composio

Composio was built to support basically every major agent harness in active use, extending the same integration to each rather than picking a favorite. Claude Code, Codex, Cursor, OpenClaw, Hermes, and others can each install it with a single command and start calling tools like GMAIL_SEND_EMAIL or SEARCH_CONFLUENCE right away, without their teams standing up OAuth handling or hosting infrastructure themselves.

For teams working in TypeScript, the official packages are @composio/openai-agents or @composio/anthropic. In Python, it's composio-openai-agents or composio-anthropic.

Four runtimes occupy genuinely different niches rather than competing head-on, and picking the wrong one for the job is an easy way to waste a quarter.

OpenClaw is open-source and channel-agnostic, running across Slack, Discord, Telegram, and iMessage, with support for self-hosted sub-agent orchestration. It can dispatch Claude Code, Codex CLI, and Cursor as sub-tasks and then coordinate the results, functioning less like a single agent and more like a meta-orchestrator sitting on top of other tools. Its GitHub project has crossed 384,000 stars.

Its API server works as an HTTP backend that any OpenAI-compatible frontend can call. It has around 248,000 GitHub stars, and it fits best for inbox management, research tasks, and internal ops work that benefits from an agent remembering what happened last week. In these cases, speed and memory determine performance more than raw orchestration depth does.

Claude Code is built tightly around Claude's own models, with CLAUDE.md files, Skills, and Hooks forming its operating harness. The research behind this piece holds it up as the strongest default option for production engineering teams, a claim resting on how deeply its harness integrates with the model it's built for, not on raw popularity.

OpenAI Codex took a real turn on July 9, 2026, when it merged into the ChatGPT desktop app. Each task it runs spins up in its own cloud environment, preloaded with the user's repository, and it works through read, edit, test, and check cycles on its own before handing results back for review. Reuters reported that competitive pressure from Claude Code pushed OpenAI to redirect resources toward Codex and its enterprise tooling, a data point worth keeping in mind for how fast this category moves. Composio's framework support list, per the research, includes OpenAI, OpenAI Agents, Anthropic, Claude Agent SDK, Vercel AI SDK, Google ADK, LangChain, LlamaIndex, Mastra, Cloudflare, LangGraph, CrewAI, and AutoGen.

Setting up Composio programmatically: the actual steps

Getting a Composio integration running doesn't take much in the way of infrastructure.

Installation is a single line either way. TypeScript pulls in npm install @composio/core. Python uses pip install composio. Targeting OpenAI Agents specifically, TypeScript needs npm install @composio/core ai @ai-sdk/mcp @ai-sdk/openai, while Python uses composio-openai-agents. For Anthropic, it's @composio/anthropic on the TypeScript side and composio-anthropic on the Python side.

From there, the pattern for standing up a working session follows a consistent shape. Start by initializing the Composio client with the API key. Next, create a session scoped to a specific user ID and one or more toolkits, turning on MCP if that's the transport in use. Then pull either the session's MCP URL and headers, or call session.tools() directly to get back a list ready for function calling. From that point it's standard agent-loop work: pass the tools in, let the agent call them, handle the outputs, and keep looping until the task is done.

Adding a specific integration follows its own short path, and Slack is a good one to walk through. Running composio integrations:add slack --scopes channels:read,chat:write kicks off an OAuth link to follow, and once that's done, tokens get stored server-side and auto-injected on every future tool call. Authenticate once, and the agent calls forever after: no re-prompting, no manual refresh, no token sitting in some developer's own database quietly going stale. Prerequisites are light: Node.js for the TypeScript SDK or Python 3.10+ for the Python SDK, plus a Composio API key from composio.dev/dashboard. Composio was founded in June 2023 by Soham Ganatra and Karan Vaidya https://automationatlas.io/tools/composio/. Rube is a pre-built Model Context Protocol server that connects AI tools to 500+ apps https://www.augmentcode.com/mcp/composio. And the Composio MCP server itself provides 25 tools in the Tool Router playground https://composio.dev/toolkits/composio.

Sources

  1. Composio: Agent Integration Platform Review 2026 | Automation Atlas
  2. Composio MCP by ComposioHQ | AI Tool Integrations
  3. Composio MCP Server | Composio
  4. Composio: Details, Reviews, Pricing, & Features
  5. Composio toolkits | MCP and API Integrations for AI Agents
  6. docs.composio.dev
  7. docs.composio.dev
  8. docs.composio.dev

More in Integration at Scale