Authenticating to Composio

Scoped Project API Key

A scoped project API key lets you choose which project resources the key can access. Reach for one when a key needs only a subset of your project, such as executing tools, reading logs, or managing connected accounts.

You pick a key's permissions when you create it, and they can't be changed afterward. To adjust them, create a new key and rotate your application to use it.

Default project API keys keep full project API key access. Scoped keys use the permission areas and access levels on this page.

Create a scoped API key

Create a scoped key from the dashboard:

Select Platform.

Select your project.

Go to Settings.

Open the API Keys tab.

Click Create API Key, then choose the permission areas and access levels below.

Access levels

Access levelWhat it allows
No accessThe key cannot use routes in that permission area.
Read onlyThe key can use read routes in that permission area.
Write onlyThe key can use write routes in that permission area.
Read and writeThe key can use both read and write routes in that permission area.

Some read routes use POST because the request body carries filters or lookup input. The access level is based on what the route does, not only the HTTP method.

The REST tables show paths relative to the API base URL, with each operation listed once. Use the API reference for the full request URL and endpoint availability. MCP transports use the URL returned when you create a session or MCP server.

Permission areas

Jump to each permission area to see the routes it covers.

Permission areaAvailable levelsRoutes
Auth configsNo access, Read only, Write only, Read and writeView routes
Connected accountsNo access, Read only, Write only, Read and writeView routes
ToolsNo access, Read onlyView routes
Session managementNo access, Read only, Write only, Read and writeView routes
Session tool executionNo access, Write onlyView routes
ToolkitsNo access, Read onlyView routes
TriggersNo access, Read only, Write only, Read and writeView routes
WebhooksNo access, Read only, Write only, Read and writeView routes
ObservabilityNo access, Read onlyView routes
MCP (Legacy)No access, Read only, Write only, Read and writeView routes
Tool execution (Legacy)No access, Write onlyView routes
Proxy execute (Legacy)No access, Write onlyView routes

Auth configs

View and modify auth configs.

AccessMethodRoute
ReadGET/auth_configs
ReadGET/auth_configs/{nanoid}
WritePOST/auth_configs
WritePATCH/auth_configs/{nanoid}
WriteDELETE/auth_configs/{nanoid}
WritePATCH/auth_configs/{nanoid}/{status}

Connected accounts

View and manage connected accounts.

AccessMethodRoute
ReadGET/connected_accounts
ReadGET/connected_accounts/{nanoid}
WritePOST/connected_accounts
WritePOST/connected_accounts/link
WritePATCH/connected_accounts/{nanoid}
WritePATCH/connected_accounts/{nanoid}/status
WritePOST/connected_accounts/{nanoid}/refresh
WriteDELETE/connected_accounts/{nanoid}
WritePOST/connected_accounts/{nanoid}/revoke

Tools

View tool definitions, inputs, scopes, and versions.

AccessMethodRoute
ReadGET/tools
ReadGET/tools/enum
ReadGET/tools/{tool_slug}
ReadGET/tools/{tool_slug}/get_latest_version
ReadGET/tools/scopes/required
ReadGET/tools/get_scopes_required
ReadPOST/tools/execute/{tool_slug}/input

Session management

Create, view, configure, and delete sessions. This permission does not allow tool execution.

The Session config read routes below are experimental and require Session configs to be enabled for your project.

AccessMethodRoute
ReadGET/session_configs
ReadGET/session_configs/{session_config_id}
ReadGET/tool_router/session/{session_id}
ReadGET/tool_router/session/{session_id}/toolkits
ReadGET/tool_router/session/{session_id}/tools
ReadGET/tool_router/session/{session_id}/mounts/{mount_id}/items
ReadGET/tool_router/session/{session_id}/config_history
WritePOST/tool_router/session
WritePOST/tool_router/session/{session_id}/link
WritePATCH/tool_router/session/{session_id}
WritePOST/tool_router/session/{session_id}/mounts/{mount_id}/upload_url
WritePOST/tool_router/session/{session_id}/mounts/{mount_id}/download_url
WritePOST/tool_router/session/{session_id}/mounts/{mount_id}/delete
WritePOST/tool_router/session/{session_id}/attach
WriteDELETE/tool_router/session/{session_id}

Session tool execution

Search and execute tools through sessions and session-linked MCP servers. Session proxy execution is not included; grant Proxy execute for that.

AccessMethodRoute
WritePOST/tool_router/session/{session_id}/execute
WritePOST/tool_router/session/{session_id}/execute_meta
WritePOST/tool_router/session/{session_id}/search

For session-linked MCP access, use session.mcp.url and session.mcp.headers unchanged. POST requests require Session tool execution with Write only access. The transport does not support GET (SSE) or DELETE; granting additional permissions does not enable those methods.

Toolkits

View toolkits.

AccessMethodRoute
ReadGET/toolkits
ReadGET/toolkits/{slug}
ReadGET/toolkits/categories
ReadGET/toolkits/changelog
ReadPOST/toolkits/{toolkit_slug}/scopes/recommended
ReadGET/toolkits/{toolkit_slug}/scopes/grant_context
ReadPOST/toolkits/multi

Triggers

View trigger types, manage trigger instances, and subscribe to trigger events. The realtime routes are called by the SDK (triggers.subscribe()) and the CLI to receive trigger events.

AccessMethodRoute
ReadGET/triggers_types
ReadGET/triggers_types/{slug}
ReadGET/triggers_types/list/enum
ReadGET/trigger_instances/active
ReadGET/cli/realtime/credentials
ReadPOST/cli/realtime/auth
ReadGET/internal/sdk/realtime/credentials
ReadPOST/internal/sdk/realtime/auth
WritePOST/trigger_instances/{slug}/upsert
WritePATCH/trigger_instances/manage/{triggerId}
WriteDELETE/trigger_instances/manage/{triggerId}

Webhooks

View and manage webhook endpoints and subscriptions.

AccessMethodRoute
ReadGET/webhook_endpoints
ReadGET/webhook_endpoints/{nano_id}
ReadGET/webhook_endpoints/schema
ReadGET/webhook_subscriptions
ReadGET/webhook_subscriptions/{id}
ReadGET/webhook_subscriptions/event_types
WritePOST/webhook_endpoints
WritePOST/webhook_endpoints/{nano_id}
WritePATCH/webhook_endpoints/{nano_id}
WriteDELETE/webhook_endpoints/{nano_id}
WritePOST/webhook_subscriptions
WritePATCH/webhook_subscriptions/{id}
WriteDELETE/webhook_subscriptions/{id}
WritePOST/webhook_subscriptions/{id}/rotate_secret

Observability

View execution logs and project usage summaries.

AccessMethodRoute
ReadPOST/logs/tool_execution
ReadGET/logs/tool_execution/{id}
ReadPOST/project/usage/{entity_type}
ReadPOST/project/usage/summary

MCP (Legacy)

Create, manage, and connect to MCP servers. Transport access grants every capability exposed by the configured MCP server.

AccessMethodRoute
ReadGET/mcp/servers
ReadGET/mcp/{id}
ReadGET/mcp/app/{app_key}
ReadGET/mcp/servers/{server_id}/instances
WritePOST/mcp/servers
WritePOST/mcp/servers/generate
WritePOST/mcp/servers/custom
WritePATCH/mcp/{id}
WriteDELETE/mcp/{id}
WritePOST/mcp/servers/{server_id}/instances
WriteDELETE/mcp/servers/{server_id}/instances/{instance_id}

For MCP transport access, use the returned MCP server URL unchanged. POST and DELETE requests require MCP (Legacy) with Write only or Read and write access.

Tool execution (Legacy)

Execute predefined Composio tools.

AccessMethodRoute
WritePOST/tools/execute/{tool_slug}
WritePOST/files/upload/request
WritePOST/files/upload/response
WriteGET/files/list

Proxy execute (Legacy)

Execute raw proxy requests against connected accounts.

Proxy execute is separate from tool execution and from Session tool execution. It is the only permission that grants the session proxy route below, whether the call comes from session.proxyExecute() or from code running in that session's sandbox. Grant it only when your application needs to call a connected account API through the raw proxy path.

AccessMethodRoute
WritePOST/tools/execute/proxy
WritePOST/tool_router/session/{session_id}/proxy_execute