# Overview

Connect supported applications through Composio, expose selected actions as tools, and manage account access without putting credentials in prompts.

![Plugins in Foxora v5.0.3](/docs/images/v5.0.3/settings/plugins-catalog.webp)

## Where this lives

Open **studio → Plugins** or **Settings → Plugins**.

Plugins connect Foxora to third-party applications through Composio. Composio manages the application authorization, and Foxora exposes the approved actions as tools for selected agents, bots, or workflows.

> **Safety:** Never paste application passwords or access tokens into a prompt. Review Composio authorization scopes and disconnect unused accounts from Foxora and the provider when necessary.

## Steps

1. Open **studio → Plugins** or **Settings → Plugins**.
2. Connect supported applications through Composio, expose selected actions as tools, and manage account access without putting credentials in prompts.
3. Open the catalog, filter more than 1,000 supported apps by OAuth, API key, user/password, or no sign-in, choose the intended provider, review scopes, and test one harmless action after connecting.
4. **Confirm the result.** Run a read-only tool first, verify the connected account and returned record, then test any write action in a safe destination with approvals enabled.

## Choose the right path

- Use a plugin for a supported SaaS application.
- Use MCP for a custom tool server or internal service.
- Use a provider connection or BYOK only for AI model access.

## Choose the integration path

| Need | Use |
| --- | --- |
| A supported third-party application | A Composio-managed plugin in Settings → Plugins. |
| A custom tool or private service | An MCP server with narrowly scoped capabilities. |
| A different AI model provider | Settings → Models, then assign BYOK to the intended agent. |
| Messages from an external communication surface | A Channel routed to an agent or bot. |


## Confirm it worked

- Run a read-only tool first, verify the connected account and returned record, then test any write action in a safe destination with approvals enabled.
- The screen, command, file, run, or destination named in this guide reflects the expected state.
