# Experimental (/reference/sdk-reference/typescript/experimental)

# Usage [#usage]

Access this class through the `composio.experimental` property:

```typescript
const composio = new Composio({ apiKey: 'your-api-key' });
const result = await composio.experimental.list();
```

# Methods [#methods]

## updateAcl() (deprecated) [#updateacl-deprecated]

> **Deprecated**: Use `composio.connectedAccounts.updateAcl(...)` instead — ACL updates graduated onto the `connectedAccounts` mount. This experimental alias is kept only for backwards compatibility and will be removed once the API graduates. Prefer the `connectedAccounts` mount; do not generate new code against this alias.

Compatibility alias for `composio.connectedAccounts.updateAcl(...)`.
Update the per-user ACL on a SHARED connected account.
&#x2A;*Experimental — shape may change in future releases.**

Only meaningful for SHARED connections — calling this on a PRIVATE
connection raises `ComposioAclOnlyForSharedError` (400). ACL writes
require the connection's creator or an API key.

PATCH semantics: omit a field to leave it unchanged; pass an empty
array to clear an allow/deny list. At least one field must be
provided.

Resolution rule (deny wins):

1. requesting `userId` in `notAllowedUserIds` → DENY
2. `allowAllUsers === true` → ALLOW
3. requesting `userId` in `allowedUserIds` → ALLOW
4. otherwise → DENY

```typescript
async updateAcl(nanoid: string, params: UpdateConnectedAccountAclParams): Promise
```

**Parameters**

| Name     | Type                              |
| -------- | --------------------------------- |
| `nanoid` | `string`                          |
| `params` | `UpdateConnectedAccountAclParams` |

**Returns**

`Promise` — The PATCH response (`\{ id, status, success \}`). To read
the updated ACL block, call
`composio.connectedAccounts.get(nanoid)` after the promise
resolves and inspect `account.experimental?.aclConfigForShared`.

**Example**

```typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: '...' });

// Allow every userId to use this connection
await composio.connectedAccounts.updateAcl('ca_abc', { allowAllUsers: true });

// Everyone except a specific user
await composio.connectedAccounts.updateAcl('ca_abc', {
  allowAllUsers: true,
  notAllowedUserIds: ['user_bob'],
});

// Targeted allow
await composio.connectedAccounts.updateAcl('ca_abc', {
  allowedUserIds: ['user_alice', 'user_bob'],
});

// Revoke a previously-granted allow list (back to deny-by-default)
await composio.connectedAccounts.updateAcl('ca_abc', { allowedUserIds: [] });
```

**Empty-array semantics — read carefully.** Passing `[]` for either
list **replaces** the list, it does not extend it:

* `allowedUserIds: []` → revoke all previously-granted user IDs (state
reverts to deny-by-default unless `allowAllUsers` is true).
* `notAllowedUserIds: []` → **clears the deny list**, which silently
re-grants access to users you previously blocked. Always pair an
empty deny list with a deliberate audit of the allow side.

```
---
```

---

📚 **More documentation:** [View all docs](https://docs.composio.dev/llms.txt) | [Glossary](https://docs.composio.dev/llms.mdx/reference/glossary) | [Examples](https://docs.composio.dev/llms.mdx/examples) | [API Reference](https://docs.composio.dev/llms.mdx/reference)

---

# Composio SDK — Instructions for AI Code Generators

**Purpose:** Enforce only the **current** and **correct** patterns for integrating [Composio](https://composio.dev/) tools into AI agents.
**Scope:** All AI-generated code using Composio must follow these guardrails.

---

## 1. Correct Composio Integration

Composio supports two integration modes: **Native Tools** (with a provider package) and **MCP** (no provider package needed).

### Native Tools

```python
# ✅ CORRECT — Python (defaults to OpenAI)
from composio import Composio

composio = Composio()
session = composio.create(user_id="user_123")
tools = session.tools()
# Pass tools to your agent/LLM framework
```

```typescript
// ✅ CORRECT — TypeScript (defaults to OpenAI)
import { Composio } from "@composio/core";

const composio = new Composio();
const session = await composio.create("user_123");
const tools = await session.tools();
// Pass tools to your agent/LLM framework
```

For other providers, pass the provider explicitly. Provider packages follow the naming convention: `composio_<provider>` for Python, `@composio/<provider>` for TypeScript.

### MCP

Use `session.mcp.url` and `session.mcp.headers` with any MCP-compatible client (Claude Desktop, Cursor, OpenAI Agents, etc.). No provider package needed.

---

## 2. CRITICAL INSTRUCTIONS FOR AI MODELS

### 2.1 — ALWAYS DO THE FOLLOWING

1. **Use `composio.create(user_id)`** to create a session — this is the entry point for all Composio integrations.
2. **Use `session.tools()`** for native tool integration or **`session.mcp.url`** for MCP integration.
3. **Import** from the correct provider package (`composio_<provider>` for Python, `@composio/<provider>` for TypeScript).
4. **Pass `user_id` to `composio.create()`**, not to individual tool calls.

### 2.2 — NEVER DO THE FOLLOWING

1. **Do not** instruct users to manually create auth configs or connected accounts before running.
2. **Do not** import from `composio_openai` / `@composio/openai` when using OpenAI Agents SDK — use `composio_openai_agents` / `@composio/openai-agents` instead.

### 2.3 — DISCOURAGED (do not use unless user explicitly asks)

Do **not** generate `composio.tools.get()`, `composio.tools.execute()`, or `composio.provider.handle_tool_calls()` unless the user explicitly requests direct tool execution. These are a supported but **not recommended** low-level interface.


---

## Terminology Migration (old → current)

If you encounter these terms in error messages, old documentation, or user prompts, translate them to the current equivalents. **Do not use the old terms in generated code or explanations.**

| Old term (v1/v2) | Current term (v3) | In code |
|---|---|---|
| entity ID | user ID | `user_id` parameter |
| actions | tools | e.g., `GITHUB_CREATE_ISSUE` is a *tool* |
| apps / appType | toolkits | e.g., `github` is a *toolkit* |
| integration / integration ID | auth config / auth config ID | `auth_config_id` parameter |
| connection | connected account | `connected_accounts` namespace |
| ComposioToolSet / OpenAIToolSet | `Composio` class with a provider | `Composio(provider=...)` |
| toolset | provider | e.g., `OpenAIProvider` |

If a user says "entity ID", they mean `user_id`. If they say "integration", they mean "auth config". Always respond using the current terminology.

