Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Estate Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
      • Get a Tailored Demo
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +32 2 290 34 90
    • Get a Tailored Demo
  • Pricing
  • Help
  1. APPS
  2. Authentication
  3. JWT Authentication v 17.0
  4. Sales Conditions FAQ

JWT Authentication

by samiakram@live.com
Odoo
v 17.0 Third Party 193
Download for v 17.0 Deploy on Odoo.sh
Apps purchases are linked to your Odoo account, please sign in or sign up first.
Availability
Odoo Online
Odoo.sh
On Premise
Lines of code 911
Technical Name odoo_jwt
LicenseAGPL-3
You bought this module and need support? Click here!
Availability
Odoo Online
Odoo.sh
On Premise
Lines of code 911
Technical Name odoo_jwt
LicenseAGPL-3

JWT Authentication for Odoo Controllers

This module adds JWT authentication to Odoo APIs, providing a stateless authentication mechanism suitable for mobile and server-based applications. After installation just go to https://localhost:8069/api/login and you can use and understand all the functionality

Features

  • Authentication Routes: /api/authenticate for login, /api/update/access-token and /api/update/refresh-token for token management, and /api/revoke/token for logout.
  • Protected Resources: Access endpoints like /api/protected/json with valid JWT tokens.

Why JWT?

JWTs offer a stateless authentication method that doesn't rely on server-stored sessions, making them ideal for mobile and server-based applications. They reduce server overhead and improve scalability by embedding authentication data within the token itself.

Installation

  1. Install PyJWT: pip install PyJWT
  2. This module is compatible with Odoo 11 and later versions, including Odoo 17.

For detailed installation guides:

  • Video Tutorial
  • Text Guide

Module Documentation

irHttp (models.AbstractModel) (models/ir_http.py)

Overrides _authenticate to handle JWT authentication by checking the Authorization header and validating the token.

JwtToken (setup/jwt_token.py)

  • get_jwt_secret(cls): Retrieves the secret key for token signing.
  • generate_token(cls, user_id, duration=0): Generates a JWT token for a user.
  • create_refresh_token(cls, uid): Creates and stores a refresh token; sets it as a secure cookie for web clients.
  • verify_refresh_token(cls, req, uid, r_token): Validates the refresh token.

ApiAuth (http.Controller) (controllers/api_auth.py)

Endpoints:

  • /api/authenticate: Authenticates a user and issues tokens.
    • Input: { "db": "o17e", "login": "admin", "password": "xxx" }
    • Output: { 'rotation_period': n, 'token': xxx, 'user_id': xx, ... }
  • /api/update/access-token: Refreshes an access token.
    • Input: { 'user_id': xx }
    • Headers (mobile): {'refreshToken': xx, ...default_headers}
    • Output: { 'access_token': xxx }
  • /api/update/refresh-token: Rotates the refresh token.
    • Input: { 'user_id': xx }
    • Headers (mobile): {'refreshToken': xxxx, ...default_headers}
    • Output: { 'status': 'done' }
  • /api/revoke/token: Revokes a refresh token.
    • Input: {}
    • Headers (mobile): {'refreshToken': xxxx, ...default_headers}
    • Output: { 'status': 'done' }
  • /api/protected/json: Access protected resources with a valid JWT.
    • Input: {}
    • Headers (mobile): {'refreshToken': xxxx, ...default_headers}
    • Output: { 'status': user_list }

Utility Methods

  • get_refresh_token(cls, req_obj): Retrieves the refresh token from cookies or headers.
  • get_json_params(cls): Extracts JSON parameters from the request body.

Testing

Use the /api/login page to test API routes by entering host details, API URL, headers, and input data.

Notes

default_headers = {
    'Accept': 'application/json',
    'Content-Type': 'application/json',
    'access_token': xxx (null in case of /api/authenticate and /api/update/access-token)
}
    

Secret key auto created on module install. Its added it gitignore, you can however update the key manually after install

For best performance, on token revoke (logout) the long term token (refreshToken is marked as is_revoked and no more usable) but the access token which has no direct relation to the refreshToken will be valid until its expiry time reaches (60 seconds total), so it has been left upon client to discard the access_token on logout, so server has not to make any extra checks for token validation

This module is designed for seamless JWT integration with Odoo APIs, enhancing security and scalability for your applications.

Please log in to comment on this module

  • The author can leave a single reply to each comment.
  • This section is meant to ask simple questions or leave a rating. Every report of a problem experienced while using the module should be addressed to the author directly (refer to the following point).
  • If you want to start a discussion with the author, please use the developer contact information. They can usually be found in the description.
Please choose a rating from 1 to 5 for this module.
Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with