# Composio connector

[Product](https://paperclip.ing/product/) / [Connectors](https://paperclip.ing/product/connectors/) / Composio

Discover app tools and execute authorized actions.

Category: [Productivity](/product/connectors/?category=productivity)
Tools from: [Composio](https://docs.composio.dev/docs/composio-connect)
Sign-in: Choose a supported connection method
Works as: Agent tool

Source recorded: Sep 30, 2026

## Overview

Paperclip’s Composio MCP connector gives your AI agents tools to discover app tools and execute authorized actions. Each tool can be Allowed, Ask first or Off.

Reach depends on Composio’s upstream app accounts and selected endpoint. A permission on an execution action governs that exposed call, not each nested app operation.

## What agents can do with Composio

- Find an app operation and inspect its inputs (`COMPOSIO_SEARCH_TOOLS`, `COMPOSIO_GET_TOOL_SCHEMAS`)
- Find a tool before executing it (`COMPOSIO_SEARCH_TOOLS`, `COMPOSIO_MULTI_EXECUTE_TOOL`)
- Set up an upstream connection (`COMPOSIO_MANAGE_CONNECTIONS`, `COMPOSIO_WAIT_FOR_CONNECTIONS`)

## How to connect Composio

These setup instructions follow the documentation. They have not been tested with a live connection.

1. In Paperclip, open Connectors and select Composio.
2. On the Access step, choose the identity and which agents may use the connection.
3. Choose Composio Connect and complete browser sign-in at the default endpoint or paste an externally configured session URL and its required headers. Review separate upstream app authorizations.

[Setup guide](https://docs.paperclip.ing/connectors/composio/)

## Composio tools for agents (7)



### Read (2)

<div data-tool-name="COMPOSIO_GET_TOOL_SCHEMAS" data-tool-class="read">
<code>COMPOSIO_GET_TOOL_SCHEMAS</code>
<p class="c4-description-summary">Fetch full input schemas for tool slugs returned by search.</p>
</div>

<div data-tool-name="COMPOSIO_SEARCH_TOOLS" data-tool-class="read">
<code>COMPOSIO_SEARCH_TOOLS</code>
<p class="c4-description-summary">Search the Composio catalog and return relevant tools for a user request, along with a suggested execution plan.</p>
</div>

### Write (5)

<div data-tool-name="COMPOSIO_MANAGE_CONNECTIONS" data-tool-class="write">
<code>COMPOSIO_MANAGE_CONNECTIONS</code>
<p class="c4-description-summary">Create, list, rename, or remove OAuth connections to upstream apps.</p>
</div>

<div data-tool-name="COMPOSIO_MULTI_EXECUTE_TOOL" data-tool-class="write">
<code>COMPOSIO_MULTI_EXECUTE_TOOL</code>
<p class="c4-description-summary">Execute one or more discovered tools in parallel across connected apps (up to 50 per call).</p>
</div>

<div data-tool-name="COMPOSIO_REMOTE_BASH_TOOL" data-tool-class="write">
<code>COMPOSIO_REMOTE_BASH_TOOL</code>
<p class="c4-description-summary">Run bash in a remote sandbox for file processing and large data handling.</p>
</div>

<div data-tool-name="COMPOSIO_REMOTE_WORKBENCH" data-tool-class="write">
<code>COMPOSIO_REMOTE_WORKBENCH</code>
<p class="c4-description-summary">Run Python in a remote sandbox for bulk operations or processing large tool responses.</p>
</div>

<div data-tool-name="COMPOSIO_WAIT_FOR_CONNECTIONS" data-tool-class="write">
<code>COMPOSIO_WAIT_FOR_CONNECTIONS</code>
<p class="c4-description-summary">Wait for a user to complete an OAuth flow before the agent continues.</p>
</div>

This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.

These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.

This list covers the fixed Connect tools. Actions discovered from connected apps are separate and can vary. Registration and account connections can limit availability.



### Connection policies

Discovered actions follow the connection’s policies. Review their permissions and set actions to Ask first or Off as needed. Set broad execute and sandbox tools to Ask first or Off and restrict upstream app authorizations in Composio too.

## Composio connector FAQ

### Can I require approval for actions?

Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.

### What can agents reach in Composio?

Reach depends on Composio’s upstream app accounts and selected endpoint. A permission on an execution action governs that exposed call, not each nested app operation.

### What do I need before connecting?

Use a Composio account and access to the intended apps or a configured session URL and required headers. Setup has not been tested live.


Ways to connect

- Composio Connect
  - Follow the provider-specific setup in the linked guide.

[Composio connector](https://docs.paperclip.ing/connectors/composio/)

[Set action permissions](https://docs.paperclip.ing/connectors/action-permissions/)

## Related connectors

- [Arcade](https://paperclip.ing/product/connectors/arcade/): Connect your Arcade gateway.
- [Asana](https://paperclip.ing/product/connectors/asana/): Find tasks, add comments and update task details.
- [Executor](https://paperclip.ing/product/connectors/executor/): Connect your Executor endpoint.

## Give your agents Composio.

Join the Paperclip waitlist to connect Composio and choose what your agents can do.

[Join the waitlist](https://paperclip.ing/waitlist/)
