This PR:
- wraps `pysher.Pusher` in `_ComposioPusher`, whose channel-auth POST
carries a `(5, 15)` connect/read timeout and raises
`TriggerSubscriptionAuthError` (a `TriggerSubscriptionError`) on a
transport failure, a non-200, or a response without an `auth` token —
pysher 1.0.8 sent it with no timeout and turned a non-200 into a bare
`AssertionError` on the websocket thread, on every (re)subscribe
- keeps that POST a plain `requests.post(..., timeout=...)` rather than
routing it through `safe_request`: the endpoint is built from the
configured Composio API base URL, a fixed trusted host, not a value from
a response, and the SSRF guard would refuse a local dev base URL
- validates `pusher_cluster` against `^[a-z0-9-]+$` (non-empty, at most
64 chars) before pysher formats it into `ws-{cluster}.pusher.com`,
raising `InvalidPusherClusterError` that names the shape violation
without echoing the value
- replaces the `unittest.mock.MagicMock` stand-in for pysher's
connection logger with a dedicated `logging.Logger` (`NullHandler`,
`propagate=False`, disabled), so `unittest` leaves the runtime import
graph while raw frames stay out of user logs; a test asserts the module
source no longer mentions `unittest`
- strips `Authorization`, `Proxy-Authorization`, and `Cookie` from the
next hop when `ssrfSafeFetch` or `safe_request` follows a redirect to a
different origin; same-origin hops keep them. Manual redirect following
bypasses both `fetch`'s cross-origin rule and `requests`'
`rebuild_auth`, so neither guard applied it before — the gap #4387 left
out
- `@composio/slim` has no mirrored source (its build copies
`core/dist`), so the changeset covers `@composio/core` and
`@composio/slim` as patches
Verified with `pytest tests/test_triggers.py tests/test_url_safety.py
tests/test_path_join_guardrail.py` (192 passed), `ruff check` / `ruff
format --check` on the changed files, `mypy --config-file
config/mypy.ini` on the three changed modules with the noxfile's stub
pins (no issues), `vitest run test/utils/ssrfGuard.test.ts` in
`@composio/core` (42 passed), `pnpm typecheck` at the root (14 tasks
successful), and `oxlint` + `prettier --check` on the changed TypeScript
files.
https://claude.ai/code/session_016ZuBv7JhVdSYTLYcTy2VJr
Composio Python SDK
Composio gives your AI agents 1000+ pre-authenticated toolkits, per-user sessions, authentication, triggers, and a sandbox. This package is the Python SDK.
- Documentation
- Quickstart
- Changelog
- Dashboard (grab your
COMPOSIO_API_KEYfrom Settings)
Install
Requires Python 3.10+.
pip install composio
Quickstart
Create a session for one of your users and hand its tools to your agent:
from composio import Composio
composio = Composio() # reads COMPOSIO_API_KEY, or pass api_key=...
session = composio.create(user_id="user_123")
tools = session.tools() # OpenAI-format tool definitions by default
By default a session gets meta tools that discover, authenticate, and execute app tools at runtime, so you don't load hundreds of tool definitions into context. Store session.session_id and reuse the session across turns:
session = composio.use(session_id)
See how Composio works for sessions and meta tools, and configuring sessions for restricting toolkits, tools, auth_configs, and connected_accounts on composio.create().
Use with an agent framework
Provider packages adapt session.tools() to your framework's native tool format. With OpenAI Agents:
pip install composio composio-openai-agents openai-agents
from composio import Composio
from composio_openai_agents import OpenAIAgentsProvider
from agents import Agent, Runner
composio = Composio(provider=OpenAIAgentsProvider())
session = composio.create(user_id="user_123")
tools = session.tools()
agent = Agent(
name="Personal Assistant",
instructions="You are a helpful assistant. Use Composio tools to take action.",
tools=tools,
)
result = Runner.run_sync(starting_agent=agent, input="Summarize my emails from today")
print(result.final_output)
Other Python providers: composio-openai, composio-anthropic, composio-claude-agent-sdk, composio-langchain, composio-langgraph, composio-llamaindex, composio-crewai, composio-autogen, composio-gemini, composio-google, composio-google-adk. Don't see yours? Build a custom provider.
MCP
Every session also exposes a hosted MCP endpoint. Pass mcp=True and point Claude, Cursor, or any MCP client at it:
from composio import Composio
composio = Composio()
session = composio.create(user_id="user_123", mcp=True)
print(session.mcp.url) # MCP endpoint for this session
print(session.mcp.headers) # auth headers for the endpoint
See sessions via MCP.
Authentication
Sessions manage connections for you by default; the agent walks the user through OAuth with the session's meta tools. To drive the flow yourself, authorize a toolkit from the session:
connection_request = session.authorize("gmail")
print(connection_request.redirect_url) # send the user here to approve access
connection_request.wait_for_connection()
See authentication for auth configs, custom OAuth apps, and connection lifecycle.
Triggers
Subscribe to events from connected apps (new email, new commit, and so on) and react to them:
from composio import Composio
composio = Composio()
trigger = composio.triggers.create(
slug="GITHUB_COMMIT_EVENT",
user_id="user_123",
trigger_config={"owner": "composiohq", "repo": "composio"},
)
subscription = composio.triggers.subscribe()
@subscription.handle(trigger_id=trigger.trigger_id)
def handle_event(data):
print("Event received:", data)
subscription.wait_forever()
subscribe() streams events over a WebSocket for local development. In production, register a webhook URL and parse deliveries with composio.triggers.parse(). See setting up triggers.
Development
This package lives in the Composio SDK monorepo under python/. See the contribution guidelines to get set up.