Access versus impact: Arcade, Composio and Anlyon
As of 2026-10-03, Arcade and Composio give an agent thousands of tools and keep the user's token away from the model, by their public pages. Anlyon does something narrower. It puts a shared limit, an exact approval and a graded receipt on the actions an agent takes through it.
Two questions, not one
Arcade and Composio connect an agent to a large catalog of tools. They run the sign-in flow, store the user's token and keep it out of the model. That is hard, useful work, and both companies are far larger than we are.
The controls we found in their docs on 2026-10-03 answer an access question. Who holds the token. Which tools an agent may see. How many calls land per minute.
Anlyon answers an impact question. How much may all your agents change. Was this exact change approved. Did it happen.
If you need a catalog and sign-in for your end users, use one of them. This page is for the reader who has the tools and now needs a limit on what they change.
Checked 2026-10-03 against Arcade docs home and Arcade rate limiting and Composio enterprise page and Composio session tool policies.
If this page has gone stale, tell us at support@anlyon.com and we will fix it.
The same six questions, asked of each
Arcade and Composio cells quote or summarise their own public pages, with the page and the date under each one. Where we looked for something and did not find it, the cell says that and nothing stronger.
| Question | Arcade | Composio | Anlyon |
|---|---|---|---|
| Approval unit | A set of OAuth scopes. The docs say a user approves once, and the same tool then runs without a new prompt until the authorization expires or is revoked. A per-call approval request with a named approver was not found in Arcade's docs as of 2026-10-03. Checked 2026-10-03 against Auth tool calling and Contextual Access. | The enterprise page lists human-in-the-loop review policies. A docs page that says how they are configured, or what they bind to, was not found as of 2026-10-03. The catalog has a HITL toolkit that wraps a third-party service, HITL.sh. Checked 2026-10-03 against Composio enterprise page and HITL toolkit. | One exact request. The approval is bound to a SHA-256 digest of the request, target, versions, preconditions and expiry. Anlyon recomputes it before dispatch and refuses on any difference. Any workspace member can decide an approval today. There are no approver groups. |
| Limit scope | An organization and project. The docs say every user and agent calling through the bound scope shares one counter. They also say a toolkit or global matcher caps each matched tool independently, not the combined total across tools. Checked 2026-10-03 against Rate limiting. | An organization, for API rate limits. A session, for which tools an agent can discover and execute. A limit that adds up across sessions was not found in Composio's docs as of 2026-10-03. Checked 2026-10-03 against Rate limits and Session tool policies. | One environment. Every agent, session and key in the environment draws from the same limit, reserved before dispatch. A new session or key does not get a new allowance. A limit is not shared across environments. |
| Limit unit | Tool calls. The docs say rate limits measure tool invocations exclusively, counted in fixed windows aligned to the clock. A limit counted in money or another business unit was not found in Arcade's docs as of 2026-10-03. Checked 2026-10-03 against Rate limiting. | API requests per minute, and spend controls on Composio usage. The pricing page says usage pauses when you reach a cap. A cap on the money or quantity an action moves at the provider was not found in Composio's docs as of 2026-10-03. Checked 2026-10-03 against Rate limits and Pricing. | Money, or any unit you declare, such as emails or rows. An amount that cannot be evaluated is refused under an applicable limit and runs when no limit applies. |
| What happens on a lost response | The docs describe retries as a fixed number of attempts, with repeat safety declared by the developer in tool metadata. Execution logs record success or failure for each attempt. An unknown outcome state, or reconciliation against the provider's record, was not found in Arcade's docs as of 2026-10-03. Checked 2026-10-03 against Is Arcade a single point of failure? and Tool executions. | Current SDKs do not automatically retry a non-idempotent write after a timeout. The docs tell the developer to inspect the execution log or provider state before retrying a send, create, update or delete. The Logs API status filter is success or failed. An unknown outcome state, or automatic reconciliation against the provider, was not found in Composio's docs as of 2026-10-03. Checked 2026-10-03 against SDK tool execution retries and Observability. | Recorded unknown, never failed. Anlyon does not send the request again and settles it from the provider's own record. An operation the lookup cannot find stays unknown, with its allowance held, until a replay or an operator resolves it. A declared action with no verify rule has nothing to read back, so it stays unknown until an operator resolves it. |
| Receipt content | An execution log entry for each attempt, with that attempt's success or failure, timing and error. Inputs and outputs are limited to project admins. On Arcade Cloud the retention window is 7 days by default and can be raised to 90. Checked 2026-10-03 against Tool executions and Execution Tool Logs post. | A log record for each tool call, with status, tool, user, connected account and duration. A detail endpoint returns the request and response payloads. Logs are retained for up to one year. Checked 2026-10-03 against Observability and Data retention. | A grade and provider evidence. Confirmed means a read-back matched. Acknowledged means the provider accepted the request and nothing read it back. Unknown means no usable response, and Anlyon does not send it again. It stays unknown until a read-back or an operator settles it. Failed, refused and denied mean it did not run. A receipt is a database record. It is not signed and not tamper-evident. |
| Where the gate runs | In Contextual Access hooks, at three points: when tools are listed, before each execution and after it. A hook can allow, deny or modify. Rate limits are enforced at the pre-execution hook. The docs describe tool code that receives the user's token and calls the provider itself, which leaves reading the provider's result back to the tool developer. Checked 2026-10-03 against Contextual Access and Server-level vs tool-level auth. | In Composio, for session tool filters, which are enforced at discovery and at execution. The docs describe before-execution modifiers that run in your SDK and change the arguments, which leaves an approve or deny step to the developer. A deny or approve return path was not found on that page as of 2026-10-03. Checked 2026-10-03 against Session tool policies and Before-execution modifiers. | In Anlyon, at dispatch. The limit is reserved and the digest is recomputed in the step that claims the dispatch. This covers actions routed through Anlyon that carry an adapter or a declaration. A tool your own code calls directly is not routed through Anlyon and is not governed by it. |
You can run both
This is not a choice between them and us. An Arcade tool or a Composio toolkit is an HTTP target, and an HTTP target can sit behind an Anlyon action.
They connect the account and hold the user's token. Anlyon counts what the action changes against the shared limit, binds the approval to the exact request and grades the receipt.
Two limits travel with that setup. The call to the vendor is an action you declare, so it has no provider idempotency and no replay of a lost write. A read-back goes to the same host as the action, so it reads the vendor's API and not the provider behind it.
More detail in Actions, or the governed actions docs.
