Vercel is useful when your organization already standardizes on its managed functions and wants a
low-operations deployment with automatic scaling. It is a supported source deployment and does not use
the composiohq/keyring:alpha container image.
Vercel does not provide ECS- or Cloud Run-style KMS workload identity. Plan credential rotation
and test provider streaming, timeout, header, and payload limits before production use.
Set these values separately for each Vercel environment:
ENCRYPTION_CONFIG must be inline JSON. Mark it and all collector or provider credentials as sensitive
project variables.
Vercel cannot run a collector sidecar. Choose a remote collector or compatible public endpoint using
the telemetry delivery guide.
2. Choose KMS authentication
Vercel does not expose an ECS-compatible credential endpoint. For AWS, provide temporary or rotated
AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and optional AWS_SESSION_TOKEN values through Vercel
secrets.
For GCP or Vault, use a supported non-file authentication method and an external rotation process. The
preferred ECS and Cloud Run deployments are a better fit when infrastructure identity is mandatory.
3. Deploy with Node 24
4. Verify and connect
Restrict the production endpoint to the Composio egress addresses
using your Vercel network controls or an approved upstream edge, then
connect it to Composio.
Vercel request size, response size, duration, and header limits apply around Keyring. Validate your
chosen plan against expected provider uploads, streaming responses, and slow token endpoints.
Keyring remains stateless on Vercel. Logs go to the configured Vercel log destination, while traces,
metrics, and required audit events are exported to your OTLP collector.