## Summary Refreshes the safe TypeScript, Python, and GitHub Actions dependency surface in one maintainer-owned change. Effect 4 rc.115, Vitest 5, the vendored Effect source, CLI migrations, and agent guidance move together, while known incompatible boundaries stay pinned. The Effect v4 config schemas preserve unknown fields across `config.json` and `user_data.json` read-update-write cycles. Fixes #4535 ## Changes - Keeps Cloudflare Workers fixtures on Vitest 4 until `@cloudflare/vitest-pool-workers` supports Vitest 5. - Keeps Mastra on the Workers-compatible versions and AG2 below 1.0 because AG2 1.x no longer ships the imported `autogen` module. - Removes the unused package-level `pnpm` dependency instead of changing the repository's pinned pnpm 11 toolchain. - Migrates the Effect CLI APIs, Eve callback contract, provider peer ranges, and repository skills required by the selected upgrades. - Preserves unknown CLI settings when `config.json` and `user_data.json` are read, updated, and written back. - Uses immutable SHA pins for the refreshed Claude Code actions and adds release metadata for the affected published TypeScript packages. ## Type of change - [x] Bug fix - [ ] New feature - [x] Refactor/Chore - [x] Documentation - [ ] Breaking change ## How Has This Been Tested? - `pnpm install --frozen-lockfile` with pnpm 11.8.0 - `pnpm typecheck` - `pnpm build:packages` - `pnpm --filter @composio/cli test` — 1,400 passed, 1 skipped, including targeted persistence regressions for `config.json` and `user_data.json` - Package tests — 28 workspace tasks passed - Example typechecks/tests and all Cloudflare dry-runs - Provider compatibility, experimental/Eve, Mastra, CLI keyring, and JSON-schema Effect checks - Agent-skill validation, routing validation, Effect skill example compilation, and peer-dependency checks - All three Python `uv lock --check` runs - `nox -s tst_autogen`, `nox -s snt`, and `nox -s chk type_inference` - Production dependency audit completed with the repository's three existing ignored advisories Docker CLI E2E was not run locally because the Docker daemon is unavailable. The exact root lint command also enters the vendored Effect submodule, whose checkout does not install its `@effect/oxc/oxlint` plugin; scoped lint over the changed non-vendor files passed. ## Screenshots (if applicable) Not applicable. ## Checklist - [x] I have read the Code of Conduct and this PR adheres to it - [ ] I ran linters/tests locally and they passed - [x] I updated documentation as needed - [x] I added tests or explain why not applicable - [x] I added a changeset if this change affects published packages The dependency migrations are covered by the focused and workspace suites. Two targeted regression tests verify that CLI updates preserve unknown fields in `config.json` and `user_data.json`. ## Additional context The Connect client sync retains its existing `Bash(curl *)` permission while moving the removed `allowed_tools` input to `claude_args`. A separate hardening change should move logo downloads outside the model-controlled shell boundary. --- [](https://github.com/EveryInc/compound-engineering-plugin)
Composio Python SDK
Composio gives your AI agents 1000+ pre-authenticated toolkits, per-user sessions, authentication, triggers, and a sandbox. This package is the Python SDK.
- Documentation
- Quickstart
- Changelog
- Dashboard (grab your
COMPOSIO_API_KEYfrom Settings)
Install
Requires Python 3.10+.
pip install composio
Quickstart
Create a session for one of your users and hand its tools to your agent:
from composio import Composio
composio = Composio() # reads COMPOSIO_API_KEY, or pass api_key=...
session = composio.create(user_id="user_123")
tools = session.tools() # OpenAI-format tool definitions by default
By default a session gets meta tools that discover, authenticate, and execute app tools at runtime, so you don't load hundreds of tool definitions into context. Store session.session_id and reuse the session across turns:
session = composio.use(session_id)
See how Composio works for sessions and meta tools, and configuring sessions for restricting toolkits, tools, auth_configs, and connected_accounts on composio.create().
Use with an agent framework
Provider packages adapt session.tools() to your framework's native tool format. With OpenAI Agents:
pip install composio composio-openai-agents openai-agents
from composio import Composio
from composio_openai_agents import OpenAIAgentsProvider
from agents import Agent, Runner
composio = Composio(provider=OpenAIAgentsProvider())
session = composio.create(user_id="user_123")
tools = session.tools()
agent = Agent(
name="Personal Assistant",
instructions="You are a helpful assistant. Use Composio tools to take action.",
tools=tools,
)
result = Runner.run_sync(starting_agent=agent, input="Summarize my emails from today")
print(result.final_output)
Other Python providers: composio-openai, composio-anthropic, composio-claude-agent-sdk, composio-langchain, composio-langgraph, composio-llamaindex, composio-crewai, composio-autogen, composio-gemini, composio-google, composio-google-adk. Don't see yours? Build a custom provider.
MCP
Every session also exposes a hosted MCP endpoint. Pass mcp=True and point Claude, Cursor, or any MCP client at it:
from composio import Composio
composio = Composio()
session = composio.create(user_id="user_123", mcp=True)
print(session.mcp.url) # MCP endpoint for this session
print(session.mcp.headers) # auth headers for the endpoint
See sessions via MCP.
Authentication
Sessions manage connections for you by default; the agent walks the user through OAuth with the session's meta tools. To drive the flow yourself, authorize a toolkit from the session:
connection_request = session.authorize("gmail")
print(connection_request.redirect_url) # send the user here to approve access
connection_request.wait_for_connection()
See authentication for auth configs, custom OAuth apps, and connection lifecycle.
Triggers
Subscribe to events from connected apps (new email, new commit, and so on) and react to them:
from composio import Composio
composio = Composio()
trigger = composio.triggers.create(
slug="GITHUB_COMMIT_EVENT",
user_id="user_123",
trigger_config={"owner": "composiohq", "repo": "composio"},
)
subscription = composio.triggers.subscribe()
@subscription.handle(trigger_id=trigger.trigger_id)
def handle_event(data):
print("Event received:", data)
subscription.wait_forever()
subscribe() streams events over a WebSocket for local development. In production, register a webhook URL and parse deliveries with composio.triggers.parse(). See setting up triggers.
Development
This package lives in the Composio SDK monorepo under python/. See the contribution guidelines to get set up.