OdooSAFE
Odoo MCP for AI agents — gated writes, multi-instance. Hosted product: https://erpipe.com
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
ERPipe is the managed Odoo MCP gateway from the maintainer of `erpipe-org/mcp-odoo`, formerly `tuanle96/mcp-odoo`; the Python project remains the self-hosted server.
The free AI layer for Odoo — any edition, any version. Odoo's built-in AI is Enterprise-only. Odoo MCP gives Community and Enterprise 16+ the same power for $0 with the LLM you already use (Claude, GPT, Gemini, DeepSeek, Ollama). Five-minute install. Zero Odoo-side setup. Safe writes, real diagnostics, JSON-2 ready years before the Odoo 22 XML-RPC removal.
🚀 ERPipe hosted — free v1 · live at erpipe.com ·
b91dff6a1f00OBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add odoo-mcp --env ODOO_PASSWORD=${ODOO_PASSWORD} -- None odoo-mcp==1.3.2Exposed tools (23)
18 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
accounting_health_summary | read | Quick accounting posture: open AR/AP item counts plus draft invoices. |
aggregate_across_instances | read | Group/aggregate per instance plus additive grand totals across them. |
build_domain | read | Build safe domain arrays for search_records and Odoo ORM calls. |
cancel_async_task | write | Cancel a task: pending tasks never start; running ones are discarded. |
fit_gap_report | read | Normalize requirements into standard/config/Studio/custom/avoid/unknown buckets. |
generate_json2_payload | read | Generate a JSON-2 endpoint, headers, and named JSON body. |
get_async_task | read | Return task status; includes the result once status is succeeded. |
get_model_fields | read | |
health_check | read | Return local process health and hardening flags without opening Odoo. |
index_knowledge | read | Index records for free-text relevance search without further RPC calls. |
inspect_model_relationships | read | Summarize relationship fields using provided metadata or bounded fields_get. |
knowledge_stats | read | List per-model index sizes, total documents, and the configured cap. |
list_async_tasks | read | List live and recently finished tasks (results omitted; poll by id). |
list_instances | read | List configured Odoo instances (name, url, db, transport) — never credentials. |
list_models | read | |
preview_write | write | Build a canonical approval token for a later approved write. |
read_record | read | |
scan_addons_source | read | Summarize manifests, custom models, risky methods, views, and ACL files. |
search_across_instances | write | Run one search across many instances; rows are tagged with `_instance`. |
search_employee | read | |
search_knowledge | read | Rank indexed records against a free-text query (accent-insensitive). |
submit_async_task | write | Submit a background task; poll with get_async_task. |
validate_write | write | Validate write shape and return an approval payload when safe. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
.importlinter
tool_helpers.validate_model_name("../../../etc/passwd")ODOO_URL=http://127.0.0.1:18169 \
ODOO_URL=http://127.0.0.1:18169 ODOO_DB=mcp_bench_db \
ODOO_URL=http://127.0.0.1:18169 ODOO_DB=mcp_bench_db \
The server listens on `http://127.0.0.1:8000/mcp`. The reverse proxy handles
proxy_pass http://127.0.0.1:8000;
assert base64.b64decode(report["data_base64"]) == b"hello pdf!"
crewai, crewai-tools
langchain, langchain-mcp-adapters, langchain-openai, langgraph
openai-agents
<div class="a">Envelope-encrypted at rest. Decrypted only on the request path — never in logs or the platform admin UI. Prefer read-only API keys; writes stay off until you enable them and complete th
<div class="flow-step" data-n="1"><div><h4>15-minute intro call</h4><p>Scope the models (audit) or addons + target version (pre-flight). You create a <b>read-only user + API key</b> — we send instruct
<li><b>Read-only credentials</b> recommended and verified at kickoff</li>
Gates applied: no_behavioural_pass.
b91dff6a1f00full audit observations/trust-audit/mcp-server/tuanle96__odoo.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | b91dff6a1f00 | SAFE | B | 89 | first audit |
Questions
What is the Odoo MCP server?
Odoo MCP for AI agents — gated writes, multi-instance. Hosted product: https://erpipe.com
What tools does Odoo expose?
23 in total: 18 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Odoo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Odoo need?
It reads ODOO_API_KEY, ODOO_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Odoo run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as odoo-mcp.
How current is this page?
The grade is for one exact copy of the source (b91dff6a1f00), read on 2026-10-02. The repository is watched and re-audited when it changes.