Paperclip’s Composio MCP connector gives your AI agents tools to discover app tools and execute authorized actions. Each tool can be Allowed, Ask first or Off.
Reach depends on Composio’s upstream app accounts and selected endpoint. A permission on an execution action governs that exposed call, not each nested app operation.
What agents can do with Composio
- Find an app operation and inspect its inputs
COMPOSIO_SEARCH_TOOLS·COMPOSIO_GET_TOOL_SCHEMAS - Find a tool before executing it
COMPOSIO_SEARCH_TOOLS·COMPOSIO_MULTI_EXECUTE_TOOL - Set up an upstream connection
COMPOSIO_MANAGE_CONNECTIONS·COMPOSIO_WAIT_FOR_CONNECTIONS
How to connect Composio
These setup instructions follow the documentation. They have not been tested with a live connection.
- In Paperclip, open Connectors and select Composio.
- On the Access step, choose the identity and which agents may use the connection.
- Choose Composio Connect and complete browser sign-in at the default endpoint or paste an externally configured session URL and its required headers. Review separate upstream app authorizations.
Composio tools for agents7
Read 2
COMPOSIO_GET_TOOL_SCHEMASFetch full input schemas for tool slugs returned by search.
COMPOSIO_SEARCH_TOOLSSearch the Composio catalog and return relevant tools for a user request, along with a suggested execution plan.
Write 5
COMPOSIO_MANAGE_CONNECTIONSCreate, list, rename, or remove OAuth connections to upstream apps.
COMPOSIO_MULTI_EXECUTE_TOOLExecute one or more discovered tools in parallel across connected apps (up to 50 per call).
COMPOSIO_REMOTE_BASH_TOOLRun bash in a remote sandbox for file processing and large data handling.
COMPOSIO_REMOTE_WORKBENCHRun Python in a remote sandbox for bulk operations or processing large tool responses.
COMPOSIO_WAIT_FOR_CONNECTIONSWait for a user to complete an OAuth flow before the agent continues.
Tool availability and permissions
This list describes the reviewed tools. Your selected method, provider access and action permissions determine what agents can use.
These lists use a conservative permission policy. Read requires a provider read-only hint or a reviewed Paperclip read rule. Evidence that an action changes data or submits information elsewhere puts it in Write. Write also includes actions we cannot verify as read-only. Read describes the reviewed evidence; it does not guarantee that an action has no side effects. A connected account can group actions differently.
This list covers the fixed Connect tools. Actions discovered from connected apps are separate and can vary. Registration and account connections can limit availability.
Connection policies
Discovered actions follow the connection’s policies. Review their permissions and set actions to Ask first or Off as needed. Set broad execute and sandbox tools to Ask first or Off and restrict upstream app authorizations in Composio too.
Composio connector FAQ
Can I require approval for actions?
Set an action to Ask first to require human approval of each call or Off to prevent calls. Allowed actions run without approval. Read and Write grouping is separate from these settings.
What can agents reach in Composio?
Reach depends on Composio’s upstream app accounts and selected endpoint. A permission on an execution action governs that exposed call, not each nested app operation.
What do I need before connecting?
Use a Composio account and access to the intended apps or a configured session URL and required headers. Setup has not been tested live.