by erpipe-org
Odoo MCP for AI agents — 41 tools, gated writes, multi-instance. Free hosted: ERPipe → mcp.erpipe.com
# Add to your Claude Code skills
git clone https://github.com/erpipe-org/mcp-odooLast scanned: 7/23/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-07-23T06:29:30.440Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}mcp-odoo is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by erpipe-org. Odoo MCP for AI agents — 41 tools, gated writes, multi-instance. Free hosted: ERPipe → mcp.erpipe.com. It has 370 GitHub stars.
Yes. mcp-odoo passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/erpipe-org/mcp-odoo" and add it to your Claude Code skills directory (see the Installation section above).
mcp-odoo is primarily written in Python. It is open-source under erpipe-org on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh mcp-odoo against similar tools.
No comments yet. Be the first to share your thoughts!
Want ChatGPT / Claude on a stable remote URL without running a process?
ERPipe is the hosted product from the same author — free v1 public beta, live in production.
Sign up → add HTTPS Odoo instance(s) → connect once tohttps://mcp.erpipe.com/mcp(workspace OAuth, multi-instance, gated writes, audit dashboard).
This repo stays the local / self-host Python server (full 41-tool surface, stdio, Docker). TypeScript building blocks:erpipe.
This repo (odoo-mcp) |
ERPipe hosted | |
|---|---|---|
| Run where | Your laptop / Docker / CI | Cloudflare (managed) |
| Install | uvx odoo-mcp --setup |
Sign up at mcp.erpipe.com |
| MCP URL | stdio or local HTTP | https://mcp.erpipe.com/mcp |
| Clients | Claude Code, Cursor, local agents | ChatGPT (primary), Claude, Cursor, any remote MCP client |
| Tool surface | 41 tools + 11 prompts (full local pack) | 37 tools + 7 prompts (workspace multi-instance + governance) |
| Multi-instance | Config file / env on your machine | Dashboard + explicit instance key per tool |
| Writes | Env gate + approval tokens (+ optional MCP elicitation) | Default OFF · HITL inbox · journal · field policy |
| Audit | Optional JSONL file | Dashboard + D1 audit trail |
| Cost | Free forever (MIT) | Free v1 beta (fair-use caps) |
Odoo MCP turns any Odoo 16+ database into a Model Context Protocol server — using only your existing credentials. No App Store module, no permission setup, no admin access required. Built for local agents, IDEs, and automation tools that need real Odoo context without hand-rolled scripts or unsafe direct write access.
It speaks XML-RPC for Odoo 16-18 and External JSON-2 for Odoo 19+. It exposes a compact MCP surface with read tools, diagnostics, schema discovery, migration helpers, local addon scanning, and a gated write workflow. One server can serve multiple named Odoo instances at once.
Once configured (see Setup), ask your agent things like:
"Show me all customers from Spain with unpaid invoices."
"Find products with stock below 10 units in the main warehouse."
"Audit the
custom_billingaddon for upgrade risks before we move to Odoo 19."
| Capability | What it gives you |
|---|---|
| 41 MCP tools | Read records and attachments, aggregate server-side, post chatter, inspect schema, build domains, scan addons, diagnose calls and upgrade logs, check data quality, access rules, resolve model renames, validate writes, and fan out across instances. |
| Field-level ACL | Opt-in per-instance, per-model field allow/deny enforced on every read path (records, aggregates, knowledge index, resources). First open-source Odoo MCP with it. See docs/field-acl.md. |
| Cross-instance queries | Read-only fan-out across many client DBs with merged, attributed, partial-failure-tolerant results — no warehouse, no sync. See docs/partner-playbook.md. |
| Workflow prompts | 11 prompts including 6 end-to-end business workflows (invoice approval, PO match, onboarding, expense review, month-end close, pre-migration data quality) that route writes through the gate. |
| Background tasks | submit_async_task runs long read operations (addon scans, knowledge indexing, AR/AP aging) on a bounded worker pool; poll with get_async_task while the agent keeps reasoning. |
| Local-first knowledge search | index_knowledge + search_knowledge give BM25 relevance ranking over a bounded record slice — accent-insensitive, in-process, no embeddings service, no data leaving the machine. |
| Accounting pack | receivable_payable_aging and accounting_health_summary answer the most common finance questions in one call instead of hand-built domains. |
| Agent Skills pack | 4 business-workflow skills (data-quality gate, migration copilot, month-end close, agency fleet review) — npx skills add erpipe-org/mcp-odoo. Developing on Odoo with shell access? Add the 21-skill companion dev suite odoo-ai-skills. See skills/. |
| Tool plugins | Ship your own tools as pip packages (odoo_mcp.tools entry points) — opt-in via ODOO_MCP_PLUGINS, fail-isolated, no fork needed. Trim the surface per deployment with ODOO_MCP_TOOLS_INCLUDE/EXCLUDE. See docs/plugins.md. |
| Rate limiting | Opt-in sliding-window budget per instance and tool (ODOO_MCP_RATE_LIMIT_MODE=warn|block), surfaced in health_check. |
| Multi-instance | One server, several named Odoo instances — optional instance parameter on every tool, list_instances discovery, instance-bound approval tokens, per-instance schema caches. |
| 5 agent prompts | Reusable workflows for failed calls, fit/gap workshops, JSON-2 migration, safe writes, and module audits. |
| Odoo 16-19 coverage | XML-RPC by default, JSON-2 opt-in for Odoo 19. |
| Streamable HTTP | Local HTTP/SSE support for clients that do not use stdio. |
| Smart field selection | search_records and read_record curate business-relevant fields when no fields argument is supplied — drops audit, message, binary, and unstored compute noise. Pass fields=["*"] to opt out. |
| Server-side aggregation | aggregate_records pushes groupby/sum/count/avg into Postgres via formatted_read_group (Odoo 19+) or read_group (16-18). |
| Chatter integration | chatter_post adds messages to any mail.thread record under the same approval-token gate as writes — or directly via MCP_CHATTER_DIRECT=1. |
| Locale plumbing | ODOO_LOCALE injects context.lang automatically on every Odoo call (caller can override). |
| Structured logging | JSON formatter and rotating file handler via ODOO_MCP_LOG_LEVEL, ODOO_MCP_LOG_JSON, ODOO_MCP_LOG_FILE. |
| Safe writes | Direct create, write, and unlink are blocked; approved writes require live metadata, a same-session token, explicit confirmation, and an env gate. |
| Human-in-the-loop approval | ODOO_MCP_ELICIT_WRITES=1 shows a native MCP confirmation form (with a diff summary) before any approved write executes — token flow stays as fallback. |
| Audit trail | ODOO_MCP_AUDIT_LOG appends one JSONL line per write-path event (preview, validate, execute, chatter) with instance and token digest. |
| Resilience | Read-only calls retry connection errors with exponential backoff; schema caches are TTL- and LRU-bounded; health_check flags N+1 read loops. |
| Real smoke tests | Docker Compose validation boots disposable Odoo 16.0, 17.0, 18.0, and 19.0 stacks, including restricted users, custom record rules, and packaged addon XML install/update. |
| Trait | Odoo MCP | Other MCP-Odoo bridges |
|---|---|---|
| Setup steps on Odoo side | 0 — works with any Odoo 16+ instance using credentials you already have. | Often require installing an App Store module, configuring enabled models, and granting per-tool permissions. |
| Safe write workflow | Approval token + live fields_get validation + explicit confirm + env gate. |
Often expose direct create/write/unlink or a "yolo" bypass. |
| Diagnostics | diagnose_odoo_call, diagnose_access, inspect_model_relationships, upgrade_risk_report, fit_gap_report, business_pack_report, scan_addons_source. |
Usually CRUD only. |
| Transport | XML-RPC (16+) and External JSON-2 (Odoo 19+). Ready for the Odoo 22 XML-RPC removal years early. | Usually XML-RPC only — deprecated since Odoo 19, removed in Odoo 22. |
| Migration helpers | generate_json2_payload previews the JSON-2 body for any XML-RPC call before you migrate. |
None. |
| Multi-instance | Named instances in one config file, per-tool routing, tokens and caches isolated per instance. | Usually one global connection per server process. |
| Agent prompts | 5 ready-made prompts for diagnose / fit-gap / |