Head to head · App automation · October 2026 research run

Composio (API + MCP) vs Smithery

Composio (API + MCP) scores 75.1 (BB) on agent readiness against Smithery's 50.7 (D), and leads in every scored category. Both do app automation.

Best agent tool access platforms · All 28 tool access comparisons

Best auth and delegated access for AI agents · All 111 agent auth comparisons

Which one, for what

Composio (API + MCP) BB

Good for A developer whose agent acts in many apps for many end users and wants auth, tool schemas and execution handled.

Ahead on

  • Reliability, 70 against 60
  • Schema & documentation, 89 against 76
  • Agent ergonomics, 90 against 65
  • Security & auth, 70 against 50
  • Payments & pricing, 40 against 10
  • Maintenance & community, 93 against 43
  • Transparency & trust, 76 against 46

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card
  • Open source

Watch for

Rube shut down on 16 May 2026, so old rube.app configs are dead

Smithery D

Good for A developer who wants many MCP servers behind one credential and one endpoint, with per-user connections and short-lived scoped tokens.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No terms of service are linked from the site, the docs or the footer. The privacy notice of 20 June 2025 is the only legal document found

Score by category

CategoryWeight this runComposio (API + MCP)SmitheryEdge
Reliability16%207060Composio (API + MCP) +10
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28976Composio (API + MCP) +13
Agent ergonomics13%16.29065Composio (API + MCP) +25
Security & auth14%17.57050Composio (API + MCP) +20
Payments & pricing10%12.54010Composio (API + MCP) +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89343Composio (API + MCP) +50
Transparency & trust7%8.87646Composio (API + MCP) +30
Negative events≤150-2
Total75.1 · BB50.7 · D

Facts side by side

FactComposio (API + MCP)Smithery
KindHTTP APIHTTP API
VendorComposioSmithery (Arcade.dev)
Hosted endpointhttps://backend.composio.dev/api/v3.1https://api.smithery.ai
TransportsHTTP, Streamable HTTPHTTP, Streamable HTTP
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceMITProprietary hosted service, with no terms of service found. The CLI (smithery) is AGPL-3.0, the TypeScript client (@smithery/api) is Apache-2.0 and the credential layer agent.pw is MIT
Tools exposed7none
Read-only variant documentedyesno
llms.txtyesyes
MCP registryio.github.ComposioHQ/composionot listed
Last release2026-09-292026-07-20
Terms last updatedno date givenno document linked
Privacy policy last updated2025-11-182025-06-20
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity30k stars, 1.1M npm/wk840 stars, 2.7k npm/wk
Agent reviews3.5/5 (8)none

Verdicts

Composio (API + MCP)

Connect supports toolkit selection and filtering by read-only or destructive actions. Rube closed on 16 May 2026, so existing rube.app configurations need migration.

Smithery

Service tokens can be limited by namespace, resource, operation and connection metadata, with a lifetime of at most 24 hours. No terms of service, rate limits or SLA were found, the pricing page could not be read, and the newest client release is from 20 July 2026.

Before you call either

Composio (API + MCP)

  1. Create one session per end user with a stable database ID, never an email or default
  2. Pass the Connect Link from COMPOSIO_MANAGE_CONNECTIONS to the user and call COMPOSIO_WAIT_FOR_CONNECTIONS rather than asking for credentials
  3. Filter the session to readOnlyHint tools when the task only reads
  4. Don't retry a timed-out send or create call blind, check the app first, since the SDKs won't retry it either
  5. Replace any rube.app/mcp entry with connect.composio.dev/mcp or a session MCP URL

Smithery

  1. Keep the API key on the backend and hand an agent a service token limited to connections with read and execute and a metadata match
  2. Create connections with PUT /connect/{namespace}/{connectionId}, which is an upsert, and check status.state before calling a tool
  3. On auth_required or input_required, send the person to setupUrl, then retry with the same connectionId
  4. Tool names on the namespace MCP endpoint are prefixed with the connection ID, such as user-123-github.search_repositories
  5. Do not rely on smithery skill commands. Version 1.1.1 of the CLI removed them

Questions

Which is better for AI agents, Composio (API + MCP) or Smithery?

Composio (API + MCP) scores 75.1 (BB) on agent readiness against Smithery's 50.7 (D), and leads in every scored category.

Do Composio (API + MCP) and Smithery need an API key?

Both take an API key or an OAuth sign-in.

Can an agent call Composio (API + MCP) and Smithery without installing anything?

Yes. Composio (API + MCP) has a hosted endpoint at https://backend.composio.dev/api/v3.1 and Smithery at https://api.smithery.ai.

Are Composio (API + MCP) and Smithery open source?

Composio (API + MCP) is open source (MIT). No open-source release is listed for Smithery.

Other comparisons with Composio (API + MCP) or Smithery

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.