
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
@usecomposer/mcp
Advanced tools
Give your AI coding agent an architecture canvas. Design, visualize, and evolve software architecture diagrams from your IDE.
Composer MCP Server
Give your AI coding agent an architecture canvas.
Design, visualize, and evolve software architecture diagrams - right from your IDE.
Composer is a visual system design tool that lets AI coding agents create and modify interactive architecture diagrams through MCP (Model Context Protocol). Your agent gets tools to add services, databases, queues, and connections, and you get a live canvas at usecomposer.com that updates in real-time.
Your IDE <--> MCP Server (this package) <--> Composer API <--> Your Diagram
Try it now - no account needed:
npx @usecomposer/mcp --demoStarts the server with sample architecture data so you can explore all the tools.
Claude Code:
claude mcp add --transport http composer https://mcp.usecomposer.com
Cursor — create .cursor/mcp.json in your project root:
{
"mcpServers": {
"composer": {
"type": "http",
"url": "https://mcp.usecomposer.com"
}
}
}
Your browser will open for authorization on first use.
claude mcp add --transport http composer https://mcp.usecomposer.com
Add to claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json{
"mcpServers": {
"composer": {
"type": "http",
"url": "https://mcp.usecomposer.com"
}
}
}
Create .cursor/mcp.json in your project root:
{
"mcpServers": {
"composer": {
"type": "http",
"url": "https://mcp.usecomposer.com"
}
}
}
codex mcp add composer -- npx -y @usecomposer/mcp --stdio
Create .vscode/mcp.json in your project root:
{
"servers": {
"composer": {
"type": "http",
"url": "https://mcp.usecomposer.com"
}
}
}
Open Cline sidebar > Settings (gear icon) > MCP Servers > Add Remote Server:
{
"mcpServers": {
"composer": {
"type": "http",
"url": "https://mcp.usecomposer.com"
}
}
}
Add to .continue/config.yaml:
mcpServers:
- name: composer
url: https://mcp.usecomposer.com
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"composer": {
"serverUrl": "https://mcp.usecomposer.com"
}
}
}
Note: Windsurf uses
"serverUrl"instead of"url".
Create opencode.json in your project root:
{
"mcp": {
"composer": {
"type": "remote",
"url": "https://mcp.usecomposer.com"
}
}
}
| Tool | Description |
|---|---|
list_diagrams | List all your diagrams. Call this first to find which diagram to work on |
create_diagram | Create a new diagram and auto-select it for this session |
select_diagram | Select which diagram to work on for this session |
rename_diagram | Rename the currently selected diagram |
Note: Call
list_diagramsthenselect_diagram(orcreate_diagram) before using other tools.
| Tool | Description |
|---|---|
get_graph | Get the full architecture diagram - all nodes and edges |
get_node | Get details for a single node including connected edges |
search_graph | Search nodes and edges by keyword |
get_screenshot | Get a PNG thumbnail of the diagram from the last auto-save |
| Tool | Description |
|---|---|
upsert_node | Create or update a node (service, database, queue, etc.) |
upsert_edge | Create or update a connection between two nodes |
define_api | Define API endpoints on a backend service node |
delete_element | Delete a node or edge from the diagram |
link_path | Link a node to a file or folder in your codebase |
| Tool | Description |
|---|---|
verify_diagram | Check for issues like missing endpoints or orphaned nodes |
plan_import | Step-by-step workflow for importing an existing codebase |
get_guide | Reference guide for node types, protocols, and best practices |
client · frontend · backend · database · cache · queue · storage · external
REST · gRPC · GraphQL · WebSocket · TCP · UDP · async · event · internal
Once connected, try asking your AI agent:
| Prompt | What it does |
|---|---|
| "Import this codebase into Composer" | Scans your repo and builds the architecture diagram |
| "Create a new Composer diagram called Backend Architecture" | Creates and auto-selects a new diagram |
| "Add a Redis cache between the API and the database in Composer" | Adds a new node and edges to the diagram |
| "Add analytics monitoring to the Composer diagram" | Adds observability nodes and connections |
| "Update the APIs I defined in Composer" | Refreshes endpoint definitions on backend nodes |
| "Verify my Composer diagram" | Checks for missing endpoints, orphaned nodes, etc. |
| "Link each Composer node to its source code" | Associates diagram nodes with file paths |
Authentication is handled via OAuth 2.1 — your browser opens for a one-time consent flow, and you're connected. Tool calls are proxied to the Composer API at mcp.usecomposer.com. Your diagram data lives on Composer's servers. The MCP server itself is stateless.
Changes made through MCP are immediately visible on the Composer canvas via real-time WebSocket sync.
git clone https://github.com/olivergrabner/composer-mcp
cd composer-mcp
npm install
npm run dev # Watch mode (rebuilds on change)
npm run build # Production build
MIT
FAQs
Give your AI coding agent an architecture canvas. Design, visualize, and evolve software architecture diagrams from your IDE.
The npm package @usecomposer/mcp receives a total of 32 weekly downloads. As such, @usecomposer/mcp popularity was classified as not popular.
We found that @usecomposer/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.