Create a custom toolkitv3.1
Experimental: custom toolkit access control is in pilot and this contract may change. Creates a custom MCP toolkit for the project and returns its slug, derived from app_url (CUSTOM_NOTION for a toolkit shared with all users, CUSTOM_NOTION_K7F2Q for a private one). user_id decides who can use it: "all" shares it with every user in the project, a user_id makes it private to that user. Access cannot be changed after create. For a private toolkit the response carries connect_link, a hosted connect page for that user (callback_url sets where it returns them); it is null for a shared toolkit, a NO_AUTH toolkit, or when the link could not be made. Returns 409 when the user_id can already use another private toolkit for the same MCP URL; the error names that toolkit. Change the name, logo or API key input copy later with PATCH /api/v3.1/custom/toolkits/{slug}.
Project API key authentication
In: header
Request Body
application/json
Toolkit to create
Human readable name for your application
App URL for the toolkit. For MCP apps, please provide the MCP URL here
uriSquare logo image (PNG or JPEG, 256-1024px, max 3MB) shown for this toolkit in the dashboard and on connect pages. Uploaded to Composio-hosted storage; defaults to the Composio logo when omitted.
Authentication schemes for the toolkit
Who can use the toolkit: "all" shares it with every user in the project, a user_id makes it private to that user. Cannot be changed after create.
Where the connect page sends the user after they connect, e.g. back to your app. Only used for a private toolkit's connect_link; defaults to Composio's connected page.
uriResponse Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/v3.1/custom/toolkits" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "app_url": "http://example.com", "auth_schemes": [ { "mode": "NO_AUTH" } ], "user_id": "all" }'{ "slug": "CUSTOM_NOTION_K7F2Q", "connect_link": { "redirect_url": "string", "expires_at": "string", "connected_account_id": "string" }}