21risk MCP server for AI agents and assistants

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with 21risk MCP or direct API to create audits, update checklists, assign actions, and monitor compliance tasks through natural language.

 21risk logo 21risk
Api Key

21RISK is a web app built for easy checklist, audit, and compliance management. It streamlines risk processes so teams can focus on what matters.

8 Tools

Try 21risk now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
21risk
Try asking
TOOLS

Supported Tools

Every 21risk action and event your agent gets out of the box.

Get Compliance

Tool to retrieve compliance data for sites, categories, or questions.

Get Items (BETA)

Tool to retrieve items (BETA) from the 21RISK OData API.

Get Items Per Month

Tool to retrieve fact table data for ItemsPerMonth, one row per question per site per month.

Get Organizations

Tool to retrieve organizations from the 21RISK OData API.

Get Properties

Tool to fetch a list of properties related to sites, including COPE information and other relevant data.

Get Reports

Tool to retrieve audit reports, including draft, published, and scheduled reports.

Get RiskModel Categories

Tool to retrieve risk model categories for grouping questions and compliance checks.

Get Risk Models

Tool to retrieve risk models used for audits and compliance.

SETUP GUIDE

Connect 21risk MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/openai @ai-sdk/mcp
Install the Composio SDK and Claude Agent SDK
2

Create Tool Router Session

typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: 'your-api-key' });

console.log("Creating Tool Router session...");
const { mcp } = await composio.create('your-user-id');
console.log(`Tool Router session created: ${mcp.url}`);
Initialize the Composio client and create a Tool Router session
3

Connect to AI Agent

typescript
import { openai } from '@ai-sdk/openai';
import { experimental_createMCPClient as createMCPClient } from '@ai-sdk/mcp';
import { generateText, stepCountIs } from 'ai';

const client = await createMCPClient({
  transport: {
    type: 'http',
    url: mcp.url,
    headers: { 'x-api-key': 'your-composio-api-key' }
  }
});

const tools = await client.tools();

const { text } = await generateText({
  model: openai('gpt-4o'),
  tools,
  messages: [{ role: 'user', content: 'Get audit reports from last month' }],
  stopWhen: stepCountIs( 5 )
});

console.log(`Agent: ${text}`);
Use the MCP server with your AI agent
SETUP GUIDE

Connect 21risk API Tool with your Agent

1

Install Composio

typescript
npm install @composio/openai
Install the Composio SDK
2

Initialize Composio and Create Tool Router Session

typescript
import OpenAI from 'openai';
import { Composio } from '@composio/core';
import { OpenAIResponsesProvider } from '@composio/openai';

const composio = new Composio({
  provider: new OpenAIResponsesProvider(),
});
const openai = new OpenAI({});
const session = await composio.create('your-user-id');
Import and initialize Composio client, then create a Tool Router session
3

Execute 21risk Tools via Tool Router with Your Agent

typescript
const tools = session.tools;
const response = await openai.responses.create({
  model: 'gpt-4.1',
  tools: tools,
  input: [{
    role: 'user',
    content: 'List all open audit reports for Q2 2024'
  }],
});
const result = await composio.provider.handleToolCalls(
  'your-user-id',
  response.output
);
console.log(result);
Get tools from Tool Router session and execute 21risk actions with your Agent

Why Use Composio?

AI Native 21risk Integration

  • Supports both 21risk MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for reading, writing, and querying your 21risk data

Managed Auth

  • Built-in API key handling and secure credential storage
  • Central place to manage, scope, and revoke 21risk access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access 21risk
  • Scoped, least privilege access to 21risk resources
  • Full audit trail of agent actions to support review and compliance
FAQ

Frequently asked questions

Yes, 21risk requires you to configure your own API key credentials. Once set up, Composio handles secure credential storage and API request handling for you.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Yes. Composio is SOC 2 Type II compliant and is built to keep your 21risk connection and credentials secure. OAuth tokens and API keys are encrypted, and sensitive customer data is protected at rest and in transit.

Composio also undergoes independent security testing and continuously monitors its systems for security threats. You can review the latest reports and policies in the Composio Trust Center.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Create the key in your 21risk account settings, then paste it once on Composio's connection page. Composio stores it encrypted and uses it only for the 21risk actions your agent runs. Nobody else in your workspace can read it, and you can revoke it inside 21risk at any time.

When you connect a 21risk account through Composio, every action runs under that account, so anything the agent creates, sends, or changes shows up in 21risk as done by you. Keep an approval step in your prompt for actions with side effects, such as sending or deleting, and have the agent draft first.

Whatever the credentials you connect allow inside 21risk. If 21risk lets you scope a key to specific permissions, create a scoped one so the agent can only do what you intend. You can revoke the key inside 21risk at any time.

Yes. Composio supports multiple connected accounts for the same app, and that works in Claude, ChatGPT, or any other assistant you connect through Composio. Give each 21risk connection a name such as work or personal, and the assistant uses the one you mention in the request. Each account keeps its own credentials and nothing is merged.

The connection stops working the moment 21risk rejects the old key. Create a new key in 21risk and reconnect the account from the Composio dashboard or by asking your agent to reconnect 21risk. Nothing else changes.

Composio's free plan includes 100,000 tool calls per month with no credit card, which covers most personal 21risk use. Paid plans add higher limits and team features. Your 21risk plan and its API limits still apply as usual.

Built-in connectors usually give one AI access to a limited set of apps. Many people use Composio because it lets their AI connect to more apps than it normally supports, or connect to multiple accounts for the same app (e.g. connect Claude to multiple 21risk accounts).

With Composio, you connect 21risk once and then use it across different AI assistants without setting it up separately in each one. Connect your apps to Composio once, then connect Composio to whichever AI you use, whether that's Claude, ChatGPT, Hermes, or your own custom assistant.

Start with 21risk.It takes 30 seconds.

Managed auth, hosted MCP servers, and every 21risk tool your agent needs.Free to start.

Start building