Skip to Content
Odoo Menu
  • Sign in
  • Try it free
  • Apps
    Finance
    • Accounting
    • Invoicing
    • Expenses
    • Spreadsheet (BI)
    • Documents
    • Sign
    Sales
    • CRM
    • Sales
    • POS Shop
    • POS Restaurant
    • Subscriptions
    • Rental
    Websites
    • Website Builder
    • eCommerce
    • Blog
    • Forum
    • Live Chat
    • eLearning
    Supply Chain
    • Inventory
    • Manufacturing
    • PLM
    • Purchase
    • Maintenance
    • Quality
    Human Resources
    • Employees
    • Recruitment
    • Time Off
    • Appraisals
    • Referrals
    • Fleet
    Marketing
    • Social Marketing
    • Email Marketing
    • SMS Marketing
    • Events
    • Marketing Automation
    • Surveys
    Services
    • Project
    • Timesheets
    • Field Service
    • Helpdesk
    • Planning
    • Appointments
    Productivity
    • Discuss
    • Approvals
    • IoT
    • VoIP
    • Knowledge
    • WhatsApp
    Third party apps Odoo Studio Odoo Cloud Platform
  • Industries
    Retail
    • Book Store
    • Clothing Store
    • Furniture Store
    • Grocery Store
    • Hardware Store
    • Toy Store
    Food & Hospitality
    • Bar and Pub
    • Restaurant
    • Fast Food
    • Guest House
    • Beverage Distributor
    • Hotel
    Real Estate
    • Real Estate Agency
    • Architecture Firm
    • Construction
    • Property Management
    • Gardening
    • Property Owner Association
    Consulting
    • Accounting Firm
    • Odoo Partner
    • Marketing Agency
    • Law firm
    • Talent Acquisition
    • Audit & Certification
    Manufacturing
    • Textile
    • Metal
    • Furnitures
    • Food
    • Brewery
    • Corporate Gifts
    Health & Fitness
    • Sports Club
    • Eyewear Store
    • Fitness Center
    • Wellness Practitioners
    • Pharmacy
    • Hair Salon
    Trades
    • Handyman
    • IT Hardware & Support
    • Solar Energy Systems
    • Shoe Maker
    • Cleaning Services
    • HVAC Services
    Others
    • Nonprofit Organization
    • Environmental Agency
    • Billboard Rental
    • Photography
    • Bike Leasing
    • Software Reseller
    Browse all Industries
  • Community
    Learn
    • Tutorials
    • Documentation
    • Certifications
    • Training
    • Blog
    • Podcast
    Empower Education
    • Education Program
    • Scale Up! Business Game
    • Visit Odoo
    Get the Software
    • Download
    • Compare Editions
    • Releases
    Collaborate
    • Github
    • Forum
    • Events
    • Translations
    • Become a Partner
    • Services for Partners
    • Register your Accounting Firm
    Get Services
    • Find a Partner
    • Find an Accountant
      • Get a Tailored Demo
    • Implementation Services
    • Customer References
    • Support
    • Upgrades
    Github Youtube Twitter Linkedin Instagram Facebook Spotify
    +32 2 290 34 90
    • Get a Tailored Demo
  • Pricing
  • Help
  1. APPS
  2. Productivity
  3. MCP Server v 19.0
  4. Sales Conditions FAQ

MCP Server

by much. Consulting https://muchconsulting.com/
Odoo
v 19.0 Third Party 213 3739
Download for v 19.0 Deploy on Odoo.sh
Apps purchases are linked to your Odoo account, please sign in or sign up first.
Versions 16.0 17.0 18.0 19.0
You bought this module and need support? Click here!
Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies Discuss (mail)
Lines of code 6546
Technical Name mcp_server
LicenseOPL-1
Websitehttps://muchconsulting.com/
Versions 16.0 17.0 18.0 19.0
  • Description
  • Manifest
  • Documentation
  • License

Connect AI Assistants to Your Odoo Data with MCP Server

Enable natural language to search, create, update, and manage your Odoo records.

Built-in MCP endpoint with OAuth login — works with Claude, ChatGPT, Microsoft Copilot, Cursor, VS Code, and more.

MCP Server for Odoo seamlessly connects any AI assistant that supports the Model Context Protocol to your Odoo instance, giving you the power to search, create, update, and manage records using natural language — all through a secure, standards-based integration. Odoo itself speaks MCP: assistants like Claude, ChatGPT, Microsoft Copilot, Perplexity, Cursor, VS Code, etc. connect directly to your Odoo URL — users simply log in with their Odoo account, and every call runs under their real permissions, fully audited.

AI Query Demo

What is Model Context Protocol (MCP)?

Model Context Protocol (MCP) is an open standard developed by Anthropic that enables seamless integration between AI assistants and data sources. It provides a universal way for AI systems to securely access and interact with local and remote resources while maintaining user control and privacy. One integration, every MCP-compatible AI tool.

🔌

Universal Compatibility

One integration works with ALL AI assistants that support MCP - no need for multiple custom integrations or proprietary connectors.

🔒

Secure by Design

Built-in security with OAuth 2.1 or API-key authentication, granular per-model permissions, rate limiting, and a complete audit trail.

🚀

Future-Proof

As new AI tools emerge, they'll support MCP - your Odoo integration automatically works with them. No vendor lock-in, ever.

Key Features & Benefits

🚀

Instant AI Integration

Connect any MCP-compatible AI assistant to your Odoo data without complex API development. Odoo itself speaks MCP at /mcp — no middleware or separate server process to run.

💬

Natural Language Operations

Not just queries - create, update, and delete records naturally. Ask "Create a new customer for Acme Corp" or "Update John Doe's phone number" and watch it happen instantly.

👥

Empower Your Team

Let employees use their preferred AI tools to access Odoo data naturally and efficiently - no retraining required.

🔑

Log in with Odoo (OAuth 2.1)

Users connect Claude.ai, ChatGPT or Le Chat by signing in with their own Odoo account and approving a consent screen. Tokens are short-lived and revocable; admins see and manage every client and session.

📖

Read-Only Consent

One checkbox at the consent screen grants an assistant read-only access: write tools are not even listed for that session, and any write attempt is refused. Ideal for connecting AI to production safely.

🛡️

Secure & Controlled Access

Granular per-model, per-operation permissions on top of Odoo's own access rights. "MCP only" API keys confine a key to the MCP endpoint. Every call, denial and login attempt lands in the audit log.

🧩

Custom Tools

Expose curated verbs like confirm_sale_order backed by Odoo server actions — instead of enabling generic write access. Each tool has its own schema, access groups, and read-only flag.

⚙️

Easy Configuration

Set up in minutes through Odoo's standard settings interface. No technical expertise required - just point, click, and configure.

</>

No Vendor Lock-in

Switch between AI providers anytime - your MCP integration continues to work seamlessly with any future MCP-compatible tool.

Full CRUD Capabilities

Go beyond simple queries. Create, Read, Update, and Delete operations for any enabled model - all through natural language.

➕ Create

"Create a new customer for Acme Corp"
"Add a product called Premium Widget"
"Schedule a meeting for tomorrow"

🔍 Read

"Show me all customers from Spain"
"Find unpaid invoices from last month"
"List products below reorder point"

✏️ Update

"Update John's phone number"
"Change order status to confirmed"
"Set product price to $99.99"

🗑️ Delete

"Remove the test contact"
"Delete cancelled orders"
"Clean up duplicate records"

Three Ways to Connect

🔑

1. Log in with Odoo Recommended

The module is a complete OAuth 2.1 authorization server. Paste your Odoo URL into the AI client, sign in with your normal Odoo login, approve the consent screen — done. No keys created, copied, or stored.

🗝️

2. API Key (Bearer)

For headless setups, service accounts and CI: mint a key once and set an Authorization: Bearer header. Choose the "MCP only" scope so a leaked key cannot be used for general RPC access.

🖥️

3. Local Bridge

For stdio-only MCP clients: the companion open-source mcp-server-odoo client (uvx) runs locally and bridges to the same module APIs — same permissions, same audit log.

Works with ANY MCP-Compatible AI Assistant

The beauty of open standards - one integration, endless possibilities. Cloud assistants (Claude.ai, ChatGPT, Perplexity, Mistral Le Chat, Microsoft Copilot, etc.) connect with an OAuth login; local tools (Claude Code, Cursor, VS Code, Gemini CLI, etc.) can use OAuth or an API key. View the growing list of compatible clients at modelcontextprotocol.io/clients.

Popular MCP Clients Include:

Claude
Claude

Web, Desktop, Mobile & Claude Code

ChatGPT
ChatGPT

Custom apps with OAuth login

Microsoft Copilot
Microsoft Copilot

M365 Copilot & Copilot Studio

Cursor
Cursor

AI-first code editor

And Many More...

💬 Chat assistants: ChatGPT (custom apps, OAuth login), Claude.ai web & mobile, Perplexity, Mistral Le Chat, LibreChat, Cherry Studio, etc.
🏢 Enterprise platforms: Microsoft 365 Copilot & Copilot Studio, Gemini Enterprise, etc.
🤖 Coding agents & CLIs: Claude Code, Codex CLI, Gemini CLI, Goose, Cline, etc.
💻 IDEs & editors: VS Code (Copilot agent mode), Windsurf, Zed, Continue.dev, Roo Code, Kilo Code, etc.
🧩 Frameworks & custom solutions: Chainlit, LangChain, any tool built with the MCP SDK

The MCP ecosystem now spans 500+ clients and is growing rapidly - new clients are added every week.

Feature Details

Dive deeper into the technical capabilities that make MCP Server for Odoo so powerful and flexible.

MCP Models Configuration in Odoo Settings
MCP Server Configuration in Odoo Settings
  • CRUD
  • Security
  • Permissions
  • Custom Tools
  • Connectivity
  • LLM-Ready

Full CRUD Through Natural Language

Complete data management through conversation, with the same ease as asking questions. 12 built-in tools cover the full lifecycle.

  • Create: Add new records to any enabled model - customers, products, orders, tasks, and more
  • Read: Search, filter, aggregate, and retrieve records with complex criteria expressed in plain English
  • Update: Modify individual fields or update records based on conditions
  • Delete: Remove records with full respect for Odoo's referential integrity rules
  • Beyond CRUD: post chatter messages, inspect model fields, call whitelisted business methods (admin opt-in), and fetch binaries/attachments on demand
  • Per-model toggles: Enable each operation independently for each exposed model

Enterprise-Grade Security

Security-first design with controls at every layer of the integration. Every call runs as a real Odoo user - never elevated.

  • Log in with Odoo (OAuth 2.1): Built-in authorization server with dynamic client registration, PKCE, per-request consent, and one-click revocation of any client or session
  • Read-only consent: Users can grant an assistant read-only access with one checkbox - enforced server-side per tool call (mcp:read / mcp:write scopes)
  • Hardened tokens: Opaque access tokens stored hashed, short-lived, with rotating refresh tokens and reuse detection
  • "MCP only" API keys: Keys confined to the MCP endpoint - a leaked key cannot be used for general RPC access
  • Model whitelist: Explicitly enable each model - default-deny posture protects unconfigured data
  • Audit logging: Every call, permission denial, and authentication attempt recorded for monitoring and compliance
  • Sanitized errors: Clients never see tracebacks, SQL, or internal details

Granular Permission System

Control exactly what each AI assistant can do, down to the model and operation level - always on top of Odoo's own access rights and record rules.

  • Model-level permissions: Choose which Odoo models AI can access - res.partner, sale.order, account.move, or any custom model
  • Operation-level permissions: Independently enable Create, Read, Update, and Delete per model
  • Method calls (opt-in): Optionally allow whitelisted public business methods per model - off by default
  • Read-only sessions: OAuth consent can pin a whole session to read-only, regardless of model settings
  • User-level enforcement: Every call runs as the authenticated user - Odoo ACLs and record rules always apply
  • Familiar interface: All managed through standard Odoo settings - no separate admin tools

Custom Tools from Server Actions

Curated verbs beat generic CRUD: expose exactly the business operations you want AI to perform, wrapped as first-class MCP tools.

  • Server-action backed: Wrap an Odoo Python server action as a tool like confirm_sale_order - no module development needed
  • Own contract: Each tool has a name, an LLM-facing description, and a JSON input schema advertised to clients
  • Runs as the caller: The action executes under the calling user's real permissions - a custom tool never grants elevated rights
  • Access-gated: Who may call a tool is controlled by the action's Allowed Groups; unauthorized users don't even see it listed
  • Independent of model flags: A custom tool is bounded by its action's logic and the caller's permissions, not by a model's Allow Read/Create/Write/Delete toggles - scope each action narrowly
  • Read-only flag: Mark a tool read-only to make it callable in read-only OAuth sessions
  • Safe by default: Failures roll back the whole call, errors are sanitized, and every execution is audited

Connectivity & Protocols

Flexible connectivity options to fit any deployment scenario.

  • Native MCP endpoint: Streamable HTTP (JSON-RPC 2.0) at /mcp - protocol revisions 2025-11-25 and 2025-06-18, negotiated at handshake
  • OAuth 2.1 discovery: Standard /.well-known metadata (RFC 9728 / RFC 8414) plus dynamic client registration (RFC 7591) - clients configure themselves
  • MCP resources: Binaries and attachments served on demand via odoo:// URIs instead of inline base64
  • REST API endpoints: Health check, model listing, and key validation for custom integrations
  • XML-RPC endpoints: MCP-gated XML-RPC used by the companion stdio bridge (uvx mcp-server-odoo) for stdio-only clients

Built for Real LLM Workflows

Responses are shaped for language models - compact, relevant, and predictable.

  • Smart field selection: Automatically picks the most relevant fields per model when the client doesn't specify any - compact output, fewer tokens
  • User context on connect: The handshake hands the assistant the connected user, timezone, and company scope - fewer wrong guesses, fewer wrong writes
  • Pagination & limits: Configurable default and maximum record limits keep responses inside context windows
  • On-demand binaries: Images and attachments are fetched via resources only when needed - no base64 bloat in every response
  • Rate limiting: Built-in per-user protection prevents runaway AI agents from overwhelming the server

Simple Setup Process

From installation to your first AI-powered Odoo query in minutes - no keys to copy with the OAuth flow.

1

Install Module

Install MCP Server in your Odoo instance like any other module.

2

Enable Models

Turn on the MCP switch and choose which models to expose, with per-operation permissions.

3

Add URL to Your AI Client

Paste https://your-odoo.com/mcp as a connector in Claude, ChatGPT, Cursor, VS Code...

4

Log in & Approve

Sign in with your Odoo login and approve the consent screen - optionally read-only. Done.

Prefer static credentials? Mint an "MCP only" API key from your Odoo profile and use it as a Bearer header instead.

Use Cases & Examples

🎧

Customer Service Acceleration

Scenario: Support agents need instant access to customer data while on calls
With MCP Server, support teams can ask their AI assistant to:

  • "Look up all orders for customer X in the last 6 months"
  • "Create a new support ticket for this complaint"
  • "Update the customer's preferred contact method to email"
  • "Show me unresolved tickets assigned to my team"
  • "Add a note about the resolution to this customer's record"

Business Impact: Agents handle calls without switching screens, reducing call times and improving customer satisfaction scores.

📈

Sales Intelligence on Demand

Scenario: Sales reps need to manage their CRM during prospect research and outreach
Sales teams can interact with their pipeline conversationally:

  • "Create a lead for Acme Corp with priority high"
  • "Update opportunity 'Q3 Enterprise Deal' status to won"
  • "Show me all opportunities closing this month"
  • "Which deals haven't had activity in 14+ days?"
  • "Add a follow-up activity for tomorrow on this lead"

Business Impact: Sales reps spend less time on data entry and more time selling, with cleaner pipeline data as a side effect.

📦

Inventory Management Made Conversational

Scenario: Warehouse managers need quick stock insights and updates
Operations teams can manage inventory through natural language:

  • "List products below reorder point"
  • "Create a new product variant for Widget Pro in red"
  • "Update stock levels for SKU-1234 to 500 units"
  • "Show me incoming shipments expected this week"
  • "Find products with no movement in the last 90 days"

Business Impact: Faster stock decisions, fewer stockouts, and reduced time spent navigating inventory screens.

💰

Financial Operations Through Chat

Scenario: Finance teams need rapid invoice processing and customer payment insights
Accountants can handle daily finance operations conversationally:

  • "Find unpaid invoices from last month over €5,000"
  • "Create an invoice for customer X with these line items"
  • "Update payment terms on this order to Net 60"
  • "Show overdue receivables grouped by customer"
  • "List all credit notes issued this quarter"

Business Impact: Month-end close runs faster, dunning workflows become proactive, and AR teams spot issues earlier.

👥

HR Records at Your Fingertips

Scenario: HR teams handle frequent record updates and lookups
HR professionals can manage employee data through conversation:

  • "Add new employee John Doe to the Engineering department"
  • "Update Sarah Chen's department to Marketing"
  • "List employees with upcoming work anniversaries"
  • "Show me all open positions in the company"
  • "Find employees who haven't completed onboarding"

Business Impact: Reduces administrative overhead for HR staff and surfaces actionable insights from people data.

📋

Project Management Without the Clicks

Scenario: Project managers juggle tasks, milestones, and resource allocation across multiple projects
PMs can drive their projects through natural language:

  • "Create a task 'Website redesign kickoff' due next Friday"
  • "Update milestone deadline for the Q4 launch to December 15"
  • "Show overdue tasks for the Marketing team"
  • "List all tasks blocked waiting on the design team"
  • "Assign this task to the next available developer"

Business Impact: PMs spend more time managing people and outcomes, less time wrangling tools.

Technical Specifications

Requirements

  • Odoo 19.0
  • Python packages: authlib (≥1.6.12, <1.7.0), defusedxml, packaging
  • Any AI assistant with MCP support

Protocols Supported

  • Native MCP at /mcp - Streamable HTTP, JSON-RPC 2.0
  • MCP protocol revisions 2025-11-25 & 2025-06-18
  • OAuth 2.1 (RFC 9728 / 8414 / 7591, PKCE S256)
  • REST API endpoints
  • XML-RPC (used by the stdio bridge client)

Security Features

  • OAuth 2.1 browser login with per-request consent
  • Read-only consent (mcp:read / mcp:write scopes)
  • "MCP only" API keys (endpoint-confined)
  • Hashed opaque tokens, rotating refresh + reuse detection
  • Per-model whitelist & per-operation permissions
  • Complete audit logging, sanitized errors

LLM-Ready by Design

  • User/timezone/company context on connect
  • Smart field selection & pagination limits
  • On-demand binaries via odoo:// resources
  • Per-user rate limiting

Ready to connect AI to your Odoo data?

Install the module, paste your Odoo URL into your AI assistant, and log in. Experience the future of business data interaction today.

For support or questions, contact much. Consulting.

Availability
Odoo Online
Odoo.sh
On Premise
Odoo Apps Dependencies Discuss (mail)
Lines of code 6546
Technical Name mcp_server
LicenseOPL-1
Websitehttps://muchconsulting.com/

MCP Server for Odoo

Overview

The MCP Server module enables AI assistants to securely access and interact with your Odoo data through the Model Context Protocol (MCP). The module speaks MCP natively: it exposes a built-in MCP endpoint at /mcp (Streamable HTTP, JSON-RPC 2.0, protocol revisions 2025-11-25 and 2025-06-18), so any MCP client (Claude.ai, Claude Desktop, Claude Code, Cursor, VS Code, MCP Inspector) connects directly to your Odoo URL with no separate process to install. Supports full CRUD operations - create, read, update, and delete records through natural language.

There are three ways to connect a client, from simplest to most involved:

  1. Log in with Odoo (OAuth 2.1) — paste the Odoo MCP URL into the client and sign in with a normal Odoo login. No keys to create or copy. Recommended.
  2. API key (Bearer token) — mint a key once and configure it as an Authorization: Bearer header.
  3. Standalone local client (uvx mcp-server-odoo) — a bridge process for stdio-only MCP clients, using the same module APIs.

Whichever way a client connects, every call runs as a real Odoo user and shares the same per-model permissions (mcp.enabled.model), audit log and rate limiting.

Installation

  1. Download and install the module in your Odoo instance (requires the authlib (>=1.6.12,<1.7.0), defusedxml and packaging Python packages — shipped as requirements.txt inside the module; on Odoo.sh reference it with -r from your repository-root requirements.txt, the only file installed automatically)
  2. Navigate to Settings > MCP Server and turn on the master switch
  3. Enable the models you want to expose and set their per-operation permissions
  4. Connect your MCP client to the /mcp endpoint (see below)

Configuration

Model Access

  1. Go to Settings > Technical > MCP > MCP Available Models
  2. Add models you want to expose (e.g., res.partner, product.product)
  3. Configure permissions for each model:
    • Read access
    • Write access
    • Create access
    • Delete access
    • Allow Method Calls (opt-in for the call_model_method tool, default off)

Server Settings

Settings > MCP Server holds the master switch plus: Allow OAuth 2.1 login (on by default; system parameter mcp_server.enable_oauth), rate limiting and its request limit, audit logging and its retention, the default/maximum record limits for tool responses, and an optional Allowed Browser Origins allowlist (system parameter mcp_server.allowed_origins; empty by default = any Origin accepted, when set a browser request from another Origin is refused with HTTP 403 — native clients send no Origin header and are never affected).

Security Groups

The module creates two security groups:

  • MCP Administrator: Can configure MCP settings and manage enabled models, custom tools, OAuth clients/tokens and the audit log
  • MCP User: Can access MCP-enabled models based on configured permissions

Multi-database deployment

On an Odoo instance that serves more than one database, every /mcp route returns 404 "No database is selected" until Odoo can tell which database a request targets — the Bearer token or OAuth session cannot select one on its own. Give each database its own hostname and let Odoo map host → database (proxy_mode = True, dbfilter = ^%d$ in odoo.conf); this is the only option that works for browser OAuth clients. Bearer / API-key clients that can set headers may instead send X-Odoo-Database: <db>. Single-database instances need none of this.

Connecting AI Assistants

Option 1: Log in with Odoo (OAuth 2.1) — recommended

The simplest way to connect: give the client your Odoo MCP URL and sign in with your normal Odoo login — no API key is created, copied or stored. The module is itself a complete OAuth 2.1 authorization server; any MCP client that supports OAuth for remote servers works out of the box.

  • Claude.ai (web) / Claude Desktop: Settings > Connectors > Add custom connector, paste https://your-company.odoo.com/mcp, complete the Odoo login and consent.

  • Claude Code (CLI):

    claude mcp add --transport http much-odoo https://your-company.odoo.com/mcp
    

    then run /mcp inside Claude Code and choose Authenticate — the browser opens your Odoo login.

  • ChatGPT: enable Developer Mode, then Settings > Apps & Connectors > Advanced settings > Create app with the same URL — the Odoo login opens when you connect (web, paid plans; see Client compatibility below).

  • Perplexity / Mistral Le Chat: add the URL as a custom connector in their Connectors settings — the OAuth login starts automatically.

  • Cursor / VS Code: add the server URL without an Authorization header; recent versions detect the OAuth challenge and open the login flow automatically.

Under the hood, an unauthenticated POST /mcp returns 401 with an RFC 9728 resource_metadata pointer; the client registers itself (RFC 7591 dynamic client registration, public PKCE client), the user signs in and approves a per-request consent screen, and the client exchanges the authorization code (PKCE S256) for an opaque access token bound to that user and to the /mcp resource (RFC 8707 resource indicator) — a token not bound to this resource is refused. Access tokens are short-lived (1 hour) and renewed by rotating refresh tokens; replaying an already-rotated refresh token is treated as a compromise and revokes the whole token family, so the client must sign in again.

The consent screen includes an "Allow creating and modifying data" checkbox. Unchecking it grants the session the read-only mcp:read scope: write tools are not even listed and any write attempt is refused with a clear read-only error. Leaving it checked grants mcp:write (read + write). The granted scope is computed server-side and can only ever be narrower than what the client registered for.

Administrators manage registered clients and issued tokens under Settings > Technical > MCP (OAuth Clients / OAuth Tokens); a token can be revoked from its form or via the bulk list action, and deactivating a client cuts off every token it issued. A daily scheduled action garbage-collects spent credentials. To accept API keys only, turn off Allow OAuth 2.1 login in Settings > MCP Server.

Option 2: API key (Bearer token)

For headless setups, service accounts, CI, or MCP clients without OAuth support:

  1. Go to My Profile > Account Security > New API Key
  2. Set Access to MCP only (recommended) or keep All APIs (default). An MCP only key authenticates only on /mcp — a leaked key cannot be used for general XML-RPC/JSON-RPC access
  3. Enter a description and copy the key (shown only once)
  4. Use the key as a Bearer token in your MCP client configuration

Claude Code (CLI)

claude mcp add --transport http much-odoo \
  https://your-company.odoo.com/mcp \
  --header "Authorization: Bearer YOUR_API_KEY"

Cursor (~/.cursor/mcp.json or a project .cursor/mcp.json):

{
  "mcpServers": {
    "much-odoo": {
      "url": "https://your-company.odoo.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

VS Code (.vscode/mcp.json — note the top-level servers key):

{
  "servers": {
    "much-odoo": {
      "type": "http",
      "url": "https://your-company.odoo.com/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_API_KEY"
      }
    }
  }
}

MCP Inspector (protocol testing)

npx @modelcontextprotocol/inspector

Point it at https://your-company.odoo.com/mcp and add the header Authorization: Bearer YOUR_API_KEY (or leave it out and use its OAuth flow).

Option 3: Standalone local client (uvx mcp-server-odoo)

The companion open-source client mcp-server-odoo runs as a small local process on the client machine and bridges stdio MCP to this module's XML-RPC/REST API. Use it when your MCP client only speaks stdio (no remote HTTP servers) or when you want a local, pinnable process. Requires Python 3.10+ and uv.

{
  "mcpServers": {
    "odoo": {
      "command": "uvx",
      "args": ["mcp-server-odoo"],
      "env": {
        "ODOO_URL": "https://your-company.odoo.com",
        "ODOO_API_KEY": "your-api-key-here",
        "ODOO_DB": "your-database-name"
      }
    }
  }
}

The bridge goes through the same per-model permissions, audit log and rate limits, but talks to this module's legacy /mcp/xmlrpc/* and /mcp/* REST endpoints rather than to /mcp. Those delegate authentication to Odoo core (scope rpc), so it needs a global (all-APIs) or rpc-scope API key — an "MCP only" key works on /mcp only and is rejected here. Besides stdio it can also serve Streamable HTTP itself (--transport streamable-http; note it adds no authentication of its own). See the mcp-server-odoo repository for full instructions (transports, username/password auth, multi-language output).

Client compatibility

Verified against this module's endpoint (Streamable HTTP, MCP protocol 2025-11-25 / 2025-06-18, OAuth 2.1 with dynamic client registration + PKCE, or Bearer API keys):

  • Claude.ai (web) / Claude Desktop — OAuth via the Connectors UI (all plans; Free: one connector). Connectors call your server from Anthropic's cloud (egress range 160.79.104.0/21 — allowlist it if a WAF/firewall fronts Odoo), so it must be reachable on public HTTPS.
  • Claude mobile (iOS/Android) — add the connector once on claude.ai (web); it syncs to the mobile apps automatically.
  • Claude Code (CLI) — OAuth or API key; runs locally, so private/localhost instances also work.
  • ChatGPT — verified end-to-end against this module: OAuth login gives full read + write tool access in normal chat. Set up on ChatGPT web (paid plans): enable Developer Mode, then Settings > Apps & Connectors > Advanced settings > Create app with the /mcp URL (on Business/Enterprise/Edu a workspace admin enables the toggle). OAuth only — no header auth. Write actions prompt for confirmation by default. Feature limits: company knowledge only includes apps exposing search/fetch tools; deep research uses custom apps read-only; agent mode does not use custom apps.
  • Microsoft Copilot Studio / M365 Copilot — OAuth (dynamic discovery / DCR) or API key via the MCP onboarding wizard (transport mcp-streamable-1.0).
  • Perplexity (web & desktop) — custom remote connectors (paid tiers) with OAuth or API key.
  • Mistral Le Chat — Connectors > Custom MCP Connector; auth auto-detected (OAuth 2.1 with DCR, or Bearer token).
  • Gemini CLI — httpUrl server with automatic OAuth discovery, or an Authorization header. Gemini Enterprise (Google Cloud) — custom MCP data store with OAuth. The consumer Gemini app has no custom MCP connectors (as of July 2026) — use Gemini CLI or Gemini Enterprise instead.
  • Cursor / VS Code / Windsurf and other MCP IDEs — API-key header or OAuth.
  • Stdio-only clients (LM Studio, many desktop wrappers) — use the standalone uvx mcp-server-odoo bridge (Option 3).

Rule of thumb: cloud-hosted clients (Claude.ai, ChatGPT, Le Chat, Perplexity web, Copilot, Gemini Enterprise) need your Odoo on public HTTPS and usually offer only OAuth for custom connectors; locally-running clients (Claude Code, IDEs, Gemini CLI, the uvx bridge) can reach private instances and use either auth.

Features

Built-in Tools

The /mcp endpoint exposes 12 built-in tools — seven read tools (search_records, get_record, get_fields, list_models, aggregate_records, list_resource_templates, get_current_context) and five write tools (create_record, update_record, delete_record, post_message, call_model_method — the latter an admin opt-in per model). call_model_method is deliberately narrow: it runs only public business methods on models whose Allow Method Calls flag is set, and refuses private (_-prefixed) methods as well as data-access methods (read, search, name_search) — for those, use the dedicated CRUD tools. Binary data is served on demand via odoo:// resources (odoo://record/{model}/{id}/{field}, odoo://attachment/{id}) instead of inlined base64.

User Context on Connect

The initialize handshake returns a personalized instructions string — the connected user, their timezone, active and allowed companies, and the rule that all datetimes are UTC — which spec-compliant clients inject into the model's context automatically, so assistants stop guessing timezones or companies. The read-only get_current_context tool returns the same information on demand.

Custom Tools

Administrators can expose curated verbs (e.g. confirm_sale_order) instead of generic CRUD by wrapping a Python Code server action in a custom tool (Settings > Technical > MCP > Custom Tools): name, LLM-facing description, JSON input schema and a read-only flag. Arguments and results flow through a shared mcp dict in the action's code (mcp['args'] in, mcp['result'] = ... out). The action runs as the calling user (never elevated); who may call the tool is controlled by the action's Allowed Groups (fallback: write access to the action's model). Tools a user may not run are hidden from tools/list and refused when called; errors are rolled back and sanitized; every call is audited. The wrapped model need not appear in Available Models, and a model's per-operation Allow Read/Create/Write/Delete flags do not gate custom tools -- the tool-level access rule (plus the caller's ACLs) is the control, so a custom tool can perform an operation disabled there (e.g. create a contact while res.partner Allow Create is off). Scope each action narrowly.

Usage Examples

Once configured, you can query and manage your Odoo data using natural language:

Data Retrieval:

  • "Show me all customers from Spain"
  • "Find products with stock below 10 units"
  • "List today's sales orders over $1000"
  • "Search for unpaid invoices from last month"

Data Management:

  • "Create a new customer contact for Acme Corporation"
  • "Add a new product called 'Premium Widget' with price $99.99"
  • "Update the phone number for customer John Doe"
  • "Change the status of order SO/2024/001 to confirmed"
  • "Delete the test contact we created earlier"

API Endpoints

Native MCP

  • /mcp (POST) - native MCP server; auth via Authorization: Bearer <token>
  • /mcp/rpc (POST) - legacy alias of /mcp (same endpoint, same auth) (an mcp- or rpc-scope API key, or an OAuth 2.1 access token)

OAuth 2.1

  • /.well-known/oauth-protected-resource (GET) - RFC 9728 protected-resource metadata
  • /.well-known/oauth-authorization-server (GET) - RFC 8414 authorization-server metadata
  • /mcp/oauth/authorize (GET/POST) - Odoo-login + consent screen
  • /mcp/oauth/token (POST) - token endpoint (PKCE S256)
  • /mcp/oauth/register (POST) - dynamic client registration (IP rate-limited)

REST API

  • /mcp/health - Health check (no auth)
  • /mcp/system/info - System information
  • /mcp/auth/validate - API key validation
  • /mcp/models - List enabled models
  • /mcp/models/{model}/access - Check model permissions

XML-RPC API

Used by the standalone mcp-server-odoo client:

  • /mcp/xmlrpc/common - Authentication
  • /mcp/xmlrpc/db - Database operations
  • /mcp/xmlrpc/object - Model operations with MCP access control

Security Considerations

  • Prefer OAuth for interactive users: tokens are short-lived, revocable per client, and never need to be copied around; grant read-only consent where writes are not needed
  • Prefer MCP only API keys so a leaked key cannot reach general RPC
  • Use HTTPS in production environments
  • Configure model access carefully - only enable necessary models; leave Allow Method Calls off unless needed
  • Custom tools bypass a model's Allow Read/Create/Write/Delete flags (they are bounded by the wrapped action's logic, the caller's ACLs, and the read-only/OAuth-scope boundary) - scope each custom tool narrowly and set its action's Allowed Groups explicitly
  • Regularly review audit logs (Settings > Technical > MCP > MCP Logs)
  • Keep the module updated

Troubleshooting

Common Issues

Module Not Installing

  • Check that all dependencies are satisfied (authlib (>=1.6.12,<1.7.0), defusedxml, packaging). authlib is capped below 1.7.0 so it does not pull in a newer cryptography than the Odoo image ships. If the server still fails to start with module 'lib' has no attribute 'GEN_EMAIL', a newer cryptography was installed anyway (e.g. by another add-on) and the system pyOpenSSL cannot import against it — keep cryptography at the image's version, or upgrade pyOpenSSL to match
  • Ensure Odoo 19.0 is being used

OAuth Login Fails or Keeps Re-Prompting

  • Confirm MCP is enabled (Settings > MCP Server) and Allow OAuth 2.1 login is on
  • Check the token was not revoked / the client not deactivated (Settings > Technical > MCP)
  • Behind a reverse proxy, make sure the discovery documents point at the right origin (web.base.url)
  • A client forced to re-authenticate for no obvious reason may have replayed a stale refresh token — reuse detection revokes the whole token family by design; signing in again issues a fresh one

OAuth Token Accepted but Every Call Returns 401

  • The access token is not bound to this resource server. Compliant MCP clients send the RFC 8707 resource indicator (your /mcp URL) on the authorize and token requests; a token minted without it is refused on /mcp. Reconnect with a client that sends resource, or include it in manual token requests

API Key Not Working

  • Verify the key is active in user settings
  • Check user has appropriate MCP permissions
  • An MCP only key works only on /mcp (rejected on REST/XML-RPC by design)

Model Access Denied

  • Confirm model is in enabled models list
  • Check operation permissions for the model
  • Verify user's security group membership
  • On an OAuth session, a read-only consent (mcp:read) hides and refuses write tools

Connection Refused or 401 Unauthorized

  • Verify your Odoo URL is reachable from the client and ends in /mcp
  • Check the Authorization: Bearer <API_KEY> header is set and the key is active
  • Confirm MCP is enabled (Settings > MCP Server) and the model is exposed

Requests Return 429 (Too Many Requests)

  • The per-minute rate limit was exceeded; the response carries a Retry-After: 60 header. Wait for the window to reset, then retry — or raise Request Limit per Minute (or turn rate limiting off) in Settings > MCP Server

Support

For support, reach out to product@erp.muchconsulting.de

Odoo Proprietary License v1.0

This software and associated files (the "Software") may only be used (executed,
modified, executed after modifications) if you have purchased a valid license
from the authors, typically via Odoo Apps, or if you have received a written
agreement from the authors of the Software (see the COPYRIGHT file).

You may develop Odoo modules that use the Software as a library (typically
by depending on it, importing it and using its resources), but without copying
any source code or material from the Software. You may distribute those
modules under the license of your choice, provided that this license is
compatible with the terms of the Odoo Proprietary License (For example:
LGPL, MIT, or proprietary licenses similar to this one).

It is forbidden to publish, distribute, sublicense, or sell copies of the Software
or modified copies of the Software.

The above copyright notice and this permission notice must be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
DEALINGS IN THE SOFTWARE.

Please log in to comment on this module

  • The author can leave a single reply to each comment.
  • This section is meant to ask simple questions or leave a rating. Every report of a problem experienced while using the module should be addressed to the author directly (refer to the following point).
  • If you want to start a discussion with the author, please use the developer contact information. They can usually be found in the description.
  • Ratings
  • Discuss
Thanks for the cool project!
by
Sofia Etchegoin Suarez
on 7/3/26, 3:48 AM

For anyone on Odoo Online (SaaS) like me: you don't need odoo.sh or the mcp_server addon. Just run the MCP client locally with YOLO mode, which talks directly to the standard XML-RPC API:

{
"mcpServers": {     "odoo": {       "command": "uvx",       "args": ["mcp-server-odoo"],       "env": {         "ODOO_URL": "https://yourcompany.odoo.com",         "ODOO_DB": "yourcompany",         "ODOO_USER": "your-login@email.com",         "ODOO_API_KEY": "your-api-key",         "ODOO_YOLO": "read"       }     }   } }


A few gotchas that cost me some time:

  • In YOLO mode you need both ODOO_USER and ODOO_API_KEY (the key alone isn't enough — you'll get "YOLO mode requires either username/password or username/API key").
  • ODOO_USER is the email you log in with, and the API key must be generated by that same user (Profile → Account Security → API Keys).
  • ODOO_YOLO: "read" is read-only; use "true" for full CRUD. Keep in mind the key inherits all permissions of its user, so be careful with admin keys + write access.

Tested on saas-19.3 and working great.

 

Thanks for the cool project
by
Nikolaus Weingartmair
on 6/22/26, 9:36 AM
  1. Is there a github repo for this? 

Would be great to put in our Dev Flow.

B. 
I tried to integrate it to openclaw but it needs it the mcp in a stream format.
I (claude) created this script to convert it, is there a more professional way to do this?
https://github.com/weinni2000/odoo-mcp-adapter

Thanks for the cool project
by
much. Products
on 6/24/26, 11:42 AM Author

Hi Nikolaus, 

Thank you for reaching out. 

1. We are working on making the repo public. It should be available in a couple a weeks. 

2. You can find a streamable-http format example in the documentation tab of this page, as well as in the README.md instructions. 


Great module
by
Nuhash Kinzel
on 5/18/26, 2:46 AM

Exactly what I was looking for. Works even better than expected!


Greate module
by
Mohamed Khaled, Mohamed Khaled
on 5/22/26, 3:23 PM



Hello, does this module support Codex's MCP?
by
jon chow
on 1/5/26, 2:16 AM



Community
  • Tutorials
  • Documentation
  • Forum
Open Source
  • Download
  • Github
  • Runbot
  • Translations
Services
  • Odoo.sh Hosting
  • Support
  • Upgrade
  • Custom Developments
  • Education
  • Find an Accountant
  • Find a Partner
  • Become a Partner
About us
  • Our company
  • Brand Assets
  • Contact us
  • Jobs
  • Events
  • Podcast
  • Blog
  • Customers
  • Legal • Privacy
  • Security

Odoo is a suite of open source business apps that cover all your company needs: CRM, eCommerce, accounting, inventory, point of sale, project management, etc.

Odoo's unique value proposition is to be at the same time very easy to use and fully integrated.

Website made with