Skip to main content
Composio Keyring adds your infrastructure to the security path for every credential use. Keyring runs in your infrastructure, uses your KMS for customer-controlled protection, and stores no credential database. Credentials for custom auth configs stay encrypted beyond Composio’s reach. Composio-managed credentials are unusable at rest and must pass through your Keyring before use. Requests forwarded through Keyring are separately restricted to approved destinations.
Your tool calls stay the same. Composio Connect URLs and hosted web flows seal credentials automatically. Direct SDK support for credential submission and auth config changes is coming soon.

What you gain

  • Monitoring: See everything entering and leaving Keyring. Send logs and audit events to your monitoring stack.
  • Control: Disable specific toolkits or projects and add custom request rules for your organization.
  • Credential protection: Credentials for custom auth configs stay encrypted beyond Composio’s reach. Composio-managed credentials must pass through your Keyring before Composio can use them, making them unusable at rest.
  • Breach impact: Composio cannot open stored credentials by itself, while Keyring stores no credential database. Compromising either system alone does not expose credentials at rest.
Keyring will be open sourced. Customers can inspect its safeguards, including the origin manifest that defines approved provider destinations.

Get started

Understand Keyring

See what changes in the credential trust model and follow a tool call from Composio to a provider.

Deploy Keyring

Deploy one Keyring instance for your Composio organization, register its URL, and enable projects.