Signpath MCP for AI Agents

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with Signpath MCP or direct API to sign software artifacts, verify signed files, check project signing status, and automate release approvals through natural language.

Signpath logoSignpath
Api Key

Signpath is a code signing service that automates the secure signing of your software artifacts. It ensures authenticity and integrity for every release, right from your CI/CD pipeline.

5 Tools

Try Signpath now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
Signpath
Try asking
TOOLS

Supported Tools

Every Signpath action and event your agent gets out of the box.

Get Health Check

Tool to check if the SignPath API is healthy and operational.

List Certificates

Retrieve all certificates available in a SignPath organization.

List Projects

Tool to list all projects for an organization.

Retrieve Signing Policy Details

Retrieve signing policy details for code signing operations.

Retrieve System Info

Retrieves SignPath system information including the application version and the web UI base URL.

SETUP GUIDE

Connect Signpath MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/openai @ai-sdk/mcp
Install the Composio SDK and Claude Agent SDK
2

Create Tool Router Session

typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: 'your-api-key' });

console.log("Creating Tool Router session...");
const { mcp } = await composio.create('your-user-id');
console.log(`Tool Router session created: ${mcp.url}`);
Initialize the Composio client and create a Tool Router session
3

Connect to AI Agent

typescript
import { openai } from '@ai-sdk/openai';
import { experimental_createMCPClient as createMCPClient } from '@ai-sdk/mcp';
import { generateText, stepCountIs } from 'ai';

const client = await createMCPClient({
  transport: {
    type: 'http',
    url: mcp.url,
    headers: { 'x-api-key': 'your-composio-api-key' }
  }
});

const tools = await client.tools();

const { text } = await generateText({
  model: openai('gpt-4o'),
  tools,
  messages: [{ role: 'user', content: 'List all projects for my organization in Signpath' }],
  stopWhen: stepCountIs( 5 )
});

console.log(`Agent: ${text}`);
Use the MCP server with your AI agent
SETUP GUIDE

Connect Signpath API Tool with your Agent

1

Install Composio

typescript
npm install @composio/openai
Install the Composio SDK
2

Initialize Composio and Create Tool Router Session

typescript
import OpenAI from 'openai';
import { Composio } from '@composio/core';
import { OpenAIResponsesProvider } from '@composio/openai';

const composio = new Composio({
  provider: new OpenAIResponsesProvider(),
});
const openai = new OpenAI({});
const session = await composio.create('your-user-id');
Import and initialize Composio client, then create a Tool Router session
3

Execute Signpath Tools via Tool Router with Your Agent

typescript
const tools = session.tools;
const response = await openai.responses.create({
  model: 'gpt-4.1',
  tools: tools,
  input: [{
    role: 'user',
    content: 'List all certificates for my organization'
  }],
});
const result = await composio.provider.handleToolCalls(
  'your-user-id',
  response.output
);
console.log(result);
Get tools from Tool Router session and execute Signpath actions with your Agent

Why Use Composio?

AI Native Signpath Integration

  • Supports both Signpath MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for submitting signing jobs, checking signing status, and retrieving results

Managed Auth

  • Built-in API key management—no more exposing secrets
  • Central place to manage and revoke Signpath keys
  • Per user and per environment credentials, not hard-coded into your app

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access Signpath
  • Scoped, least privilege access to Signpath signing projects
  • Full audit trail of agent actions to support review and compliance
FAQ

Frequently asked questions

Yes, Signpath requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Composio is SOC 2 and ISO 27001 compliant with all data encrypted in transit and at rest. Learn more.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Start with Signpath.It takes 30 seconds.

Managed auth, hosted MCP servers, and every Signpath tool your agent needs.Free to start.

Start building