---
title: Composio
---

# Composio

## What it is

### Status

In-development (unreleased). Enable: set `AMC_SHOW_COMPOSIO=1` or toggle in Settings > Dev Features.

A connector that links Omniscio to [Composio](https://composio.dev) — an "auth-to-action" layer that manages logins for 1000+ external apps (Gmail, Slack, GitHub, Notion, Linear, …) and exposes them as agent tools. Path B (Omniscio-managed): you connect apps from a dedicated Composio screen, and Omniscio automatically injects your per-user Composio Tool Router MCP server into every spawned Claude session, so agents can act in those apps with no per-session setup.

User-brings-own-key: you paste your OWN free Composio API key. Omniscio stores it encrypted at rest and never returns it to the renderer.

## Where to find it

Once the feature is switched on, **Composio** is its own row in the left sidebar, and that screen is where you paste your key and browse the catalog of apps to connect. Each app's sign-in then happens in your normal browser rather than inside the app. Nothing else in the app needs to be opened or configured for the tools to reach your sessions.

## How it behaves

### How to use it

1. Enable the Composio feature (Settings > Dev Features or `AMC_SHOW_COMPOSIO=1`).
2. Open the Composio tab in the sidebar and paste your Composio API key (create one free at app.composio.dev).
3. Browse the app catalog and click Connect on an app (e.g. Gmail). Composio opens its own secure sign-in in your browser; complete it and return.
4. Connected apps' tools are automatically available in every new AI session.

### How the session tools work

- Omniscio mints a per-user Composio Tool Router MCP URL in the BACKGROUND and caches it — never during session startup, so the spawn hot path stays fetch-free.
- A dedicated layer in `mcp-config-orchestrator` injects `{ type: 'http', url: <tool-router url>, headers: { 'X-API-Key': <your key> } }` into the session's MCP config — but ONLY when the feature is on, a valid key is set, a URL is cached, and at least one app is connected.
- The key-bearing entry is never injected into secret-sensitive (KMS / secret-excluded) sessions, and any error building it simply omits Composio, so it can never break a spawn.

### Data & privacy

- Composio holds your connected accounts server-side (keyed by a stable per-user id). Omniscio stores only your encrypted API key + a small local cache (the user id, the minted URL, the connected-app list) — no cloud storage, no database migration.
- Tool calls run against your own Composio account and count toward your Composio quota (the free tier is generous).

## For agents

### CLI routes

- `GET /composio/status` — connection status (key set?, connected-app count, feature on?).
- `GET /composio/toolkits` — searchable catalog of Composio apps.
- `GET /composio/connections` — the user's connected apps.
- `POST /composio/connect` — begin connecting an app; returns the hosted sign-in URL to open.
- `DELETE /composio/connections/:toolkit` — disconnect an app.

All routes require bearer auth. The API key is write-only from the CLI (set in Settings) and is never returned.

### Architecture

- Settings slice (single source of truth): `src/shared/types/settings/composio-settings.ts`.
- Backend service (REST-direct, no SDK): `src/main/services/composio/`.
- Session injection: the Composio layer in `src/main/services/mcp/mcp-config-orchestrator.ts`.
- Panel: `src/renderer/src/features/composio/ComposioPanel.tsx`.

## Related

The mechanism this feature rides — a server being attached to each session so its tools show up — is described generally on the [MCP servers](mcp-servers.md) page. If what you want is a connector to one specific outside app rather than a hundred at once, [Zapier integration](zapier-integration.md) is the comparable approach, and the encrypted-at-rest treatment of the key you paste here is the same one described on [API keys](api-keys.md).
