{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "odoo",
    "name": "Odoo External API",
    "vendor": "Odoo SA",
    "vendorUrl": "https://www.odoo.com",
    "kind": "http-api",
    "category": "accounting",
    "summary": "Odoo is a business suite from Odoo SA in Belgium with accounting, invoicing, sales, stock and HR apps on one database. Outside software reaches it through the JSON-2 HTTP API with API keys and, from Odoo 20, an MCP server.",
    "url": "https://www.anchorterminal.com/tools/odoo",
    "markdownUrl": "https://www.anchorterminal.com/tools/odoo.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/odoo.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/odoo.json",
    "repo": "https://github.com/odoo/odoo",
    "license": "Community edition LGPL-3.0. The Enterprise edition (the full Accounting app and the AI app with the MCP server) is proprietary under the Odoo Enterprise Subscription Agreement",
    "transports": [
      "http"
    ],
    "packages": [],
    "auth": "api-key",
    "authNotes": "An API key created by a user under Preferences, Account Security, New API Key, sent as `Authorization: bearer \u003ckey\u003e`. The key acts with that user's access rights and record rules, is shown once and expires within three months at most. Self-serve once the database is on a plan that includes the external API (Custom on Odoo Online), with no app review. The MCP server takes a key created with the MCP scope. The deprecated XML-RPC and JSON-RPC services take the database name, user id and password or key in the call.",
    "pricing": "paid",
    "pricingNotes": "Odoo Online needs the Custom plan for the external API. On 8 October 2026 the pricing page, read from a UK address, showed Custom at £41 a user a month billed yearly or £52 billed monthly (£32 and £41 for the first 12 months), Standard at £22 or £28 without the external API, and One App Free at £0 for one app without it. A free trial needs no card. The Community edition is free to self-host under LGPLv3 and includes the JSON-2 API. We did not read US dollar prices, so the price table is empty.",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the external API docs, the MCP server docs or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 54912,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://www.odoo.com/documentation/20.0/developer/reference/external_api.html",
    "capabilities": [
      "accounting.ledger",
      "accounting.invoices",
      "accounting.bills"
    ],
    "tags": [
      "hosted",
      "self-hosted",
      "open-source",
      "enterprise",
      "mcp",
      "status-page"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 55.9,
      "grade": "C",
      "agentReady": false,
      "rank": 499,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 7,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 67,
        "maintenance": 73,
        "payments": 22,
        "reliability": 44,
        "schema": 51,
        "security": 61,
        "transparency": 93
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 44,
          "points": 8.8,
          "reason": "Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 51,
          "points": 8.29,
          "reason": "No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at `/doc-bearer/index.json` and `/doc-bearer/\u003cmodel\u003e.json`, which needs a key, and the docs section on it reads \"Under construction\" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 67,
          "points": 10.89,
          "reason": "`fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, `offset`, `limit`, `order` and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a \"Readonly Tool\" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 61,
          "points": 10.68,
          "reason": "Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through `get_audit_logs`, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 22,
          "points": 2.75,
          "reason": "No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 73,
          "points": 6.39,
          "reason": "Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 93,
          "points": 8.14,
          "note": "editorial 87, provenance 98",
          "reason": "The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, `offset`, `limit`, `order` and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a \"Readonly Tool\" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7).",
          "maintenance": "Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8).",
          "payments": "No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0).",
          "reliability": "Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10).",
          "schema": "No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at `/doc-bearer/index.json` and `/doc-bearer/\u003cmodel\u003e.json`, which needs a key, and the docs section on it reads \"Under construction\" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11).",
          "security": "Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through `get_audit_logs`, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11).",
          "transparency": "The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18)."
        },
        "sources": [
          {
            "what": "External JSON-2 API reference, Odoo 20.0 (plan limit, keys, errors, transactions, RPC removal dates)",
            "url": "https://www.odoo.com/documentation/20.0/developer/reference/external_api.html",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server documentation, read from the 20.0 branch of odoo/documentation",
            "url": "https://www.odoo.com/documentation/20.0/applications/productivity/ai/mcp_server.html",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP tool list",
            "url": "https://www.odoo.com/documentation/20.0/applications/productivity/ai/mcp_server/mcp_tools.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Pricing page (GBP shown)",
            "url": "https://www.odoo.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "Acceptable use policy (API throttling)",
            "url": "https://www.odoo.com/acceptable-use",
            "seen": "2026-10-08"
          },
          {
            "what": "Cloud SLA page",
            "url": "https://www.odoo.com/cloud-sla",
            "seen": "2026-10-08"
          },
          {
            "what": "Status page",
            "url": "https://status.odoo.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Odoo Enterprise Subscription Agreement, version 13",
            "url": "https://www.odoo.com/documentation/20.0/legal/terms/enterprise.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy policy",
            "url": "https://www.odoo.com/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "Security page and responsible disclosure policy",
            "url": "https://www.odoo.com/security",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.odoo.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Supported versions table",
            "url": "https://www.odoo.com/documentation/20.0/administration/standard_extended_support.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Odoo 20 release notes",
            "url": "https://www.odoo.com/odoo-20-release-notes",
            "seen": "2026-10-08"
          },
          {
            "what": "JSON-2 controller, API key model, `account` module and `/doc-bearer` routes on the 20.0 branch (shallow clone)",
            "url": "https://github.com/odoo/odoo/tree/20.0",
            "seen": "2026-10-08"
          },
          {
            "what": "Odoo Online administration (database list and audit logs through JSON-2)",
            "url": "https://www.odoo.com/documentation/20.0/administration/odoo_online.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Nightly builds for 20.0",
            "url": "https://nightly.odoo.com/20.0/nightly/src/",
            "seen": "2026-10-08"
          },
          {
            "what": "Public CI",
            "url": "https://runbot.odoo.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "NVD keyword search for Odoo, 8 October 2025 to 8 October 2026",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?keywordSearch=odoo",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: US dollar prices. The pricing page served GBP to our UK address, so `unitPrices` is empty",
          "unchecked: whether a free trial database accepts external API calls before a Custom subscription starts",
          "unchecked: the MCP tool input schemas and annotations. The AI app is Enterprise code and is not in the public repository, so only the documentation was read",
          "unchecked: whether a profit and loss report can be read through JSON-2. The reporting engine is Enterprise code, so `accounting.reports` is left out",
          "unchecked: issue and pull request reply times on GitHub, and the pass rate on runbot.odoo.com",
          "unchecked: the MCP registry was not searched for an Odoo entry",
          "status.odoo.com carries placeholder text and sample data in parts of its markup that are hidden or commented out. We scored only what a reader sees",
          "The lead pointed at the 19.0 docs. Odoo 20.0 was released in September 2026 and is the version read here",
          "No SOC 2 or ISO 27001 report for Odoo itself was found on the security page. Data centre certifications are listed in the privacy policy"
        ]
      },
      "negative": 0,
      "verdict": "One endpoint pattern reaches every model, with field selection, filters and paging, and keys that expire within three months. On Odoo Online the external API needs the Custom plan, there is no OpenAPI file, and the acceptable use policy asks for about one call a second with no parallel calls.",
      "bestFor": "An agent working inside a company that already runs Odoo, where invoices, bills, journal entries, stock and sales sit in one database behind one endpoint pattern.",
      "strengths": [
        "`/json/2/\u003cmodel\u003e/\u003cmethod\u003e` reaches every model the user can see, including `account.move` for invoices, bills and journal entries",
        "API keys are per user, shown once, expire within three months at most and can be generated and revoked through the API",
        "Odoo 20 adds an MCP server at `\u003cdatabase_url\u003e/mcp` that exposes five read-only tools by default, with write tools switched on one by one",
        "The Community edition is LGPLv3 and carries the same JSON-2 controller, so a self-hosted server answers the same calls at no charge",
        "The privacy policy of 24 September 2026 names subprocessors, hosting regions and retention periods"
      ],
      "weaknesses": [
        "On Odoo Online the external API is limited to the Custom plan. One App Free and Standard exclude it",
        "No OpenAPI file and no llms.txt. The per-database reference at `/doc` needs a login or a key, and its docs section reads \"Under construction\"",
        "The acceptable use policy puts API traffic at about one call a second with no parallel calls. No 429 or Retry-After handling was found in the docs",
        "No idempotency keys, and the JSON-2 docs say several calls cannot share one transaction",
        "status.odoo.com has no history page, and its only dated entry is a planned upgrade on 4 August 2026",
        "The full Accounting app and the MCP server are in the proprietary Enterprise edition. Community has Invoicing"
      ],
      "agentNotes": [
        "POST to `/json/2/\u003cmodel\u003e/\u003cmethod\u003e` with `Authorization: bearer \u003ckey\u003e` and named arguments in a JSON body. Add `X-Odoo-Database` when one host serves several databases",
        "Pass `fields` and `limit` on `search_read`. The default limit is every matching record",
        "Create invoices and bills on `account.move` with `move_type` set to `out_invoice` or `in_invoice`, then call `action_post`. A new move is a draft",
        "Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one `create` call",
        "Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 55.9
        }
      ],
      "editorialScores": {
        "ergonomics": 67,
        "maintenance": 73,
        "payments": 22,
        "reliability": 44,
        "schema": 51,
        "security": 61,
        "transparency": 87
      },
      "provenanceScore": 98
    },
    "connect": {
      "http": "curl https://$DATABASE.odoo.com/json/2/res.partner/search_read \\\n  -X POST \\\n  --oauth2-bearer $API_KEY \\\n  -H \"X-Odoo-Database: $DATABASE\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"domain\": [[\"is_company\", \"=\", true]], \"fields\": [\"name\"]}'",
      "claudeCode": "claude mcp add --transport stdio \u003cserver_name\u003e -- npx -y mcp-remote \u003cdatabase_url\u003e/mcp --header \"Authorization: Bearer \u003cAPI_KEY\u003e\"",
      "config": {
        "mcpServers": {
          "odoo": {
            "args": [
              "-y",
              "mcp-remote",
              "\u003cdatabase_url\u003e/mcp",
              "--header",
              "Authorization: Bearer \u003cAPI_KEY\u003e"
            ],
            "command": "npx"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/accounting.ledger",
      "tool": "https://letme.dev/odoo"
    },
    "notable": [
      "The JSON-2 docs state that access to data through the external API is only available on Custom plans and not on One App Free or Standard (https://www.odoo.com/documentation/20.0/developer/reference/external_api.html)",
      "API keys cannot last more than three months, and `res.users.apikeys/generate` and `revoke` allow rotation by API, with 10 programmatic keys a user by default (https://www.odoo.com/documentation/20.0/developer/reference/external_api.html)",
      "Odoo 20, released September 2026, adds an MCP server at `\u003cdatabase_url\u003e/mcp` with an API key in the MCP scope. The documented client set-up runs `npx -y mcp-remote` (https://www.odoo.com/documentation/20.0/applications/productivity/ai/mcp_server.html)",
      "The XML-RPC and JSON-RPC `db` service was removed in Odoo 20, and the `common` and `object` services are scheduled for removal in Odoo 22 (autumn 2028) and Online 21.1 (winter 2027) (https://www.odoo.com/documentation/20.0/developer/reference/external_api.html)",
      "The acceptable use policy names unthrottled RPC or API calls as abuse and gives 1 call a second with no parallel calls as typically acceptable (https://www.odoo.com/acceptable-use)",
      "The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding guarantees (https://www.odoo.com/cloud-sla)",
      "The Community `account` module is named Invoicing in its manifest. The pricing page lists Accounting among the apps of the paid plans (https://github.com/odoo/odoo/blob/20.0/addons/account/__manifest__.py)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surfaces",
        "value": "JSON-2 API at `/json/2/\u003cmodel\u003e/\u003cmethod\u003e` (new in Odoo 19.0, POST only, JSON body with `ids`, `context` and named arguments). MCP server at `\u003cdatabase_url\u003e/mcp` (Odoo 20, AI app). XML-RPC and JSON-RPC at `/xmlrpc/2` and `/jsonrpc` are deprecated"
      },
      {
        "label": "Plan needed",
        "value": "Custom plan only on Odoo Online. One App Free and Standard exclude the external API. A self-hosted Community server needs no plan"
      },
      {
        "label": "Credentials",
        "value": "API key per user from Preferences, Account Security, sent as a bearer token. Shown once, 160-bit, mandatory expiry of at most three months, scopes `rpc` and MCP, programmatic `res.users.apikeys/generate` and `revoke`"
      },
      {
        "label": "Rate limits",
        "value": "The acceptable use policy gives about 1 call a second, no parallel calls, for unsustained use. Odoo Online audit logs allow one request every 5 minutes. No 429 behaviour documented"
      },
      {
        "label": "Accounting objects",
        "value": "`account.move` (customer invoices, vendor bills, credit notes, receipts and journal entries by `move_type`), `account.move.line`, `account.account`, `account.journal`, `account.payment`, with `action_post` and `action_register_payment`"
      },
      {
        "label": "MCP tools",
        "value": "Exposed by default are Get Models, Get Fields, Search, Read group and MCP Retrieve initial context. Update Records, Create Records and about 20 navigation, website and media tools are off until an administrator ticks \"Available in MCP\""
      },
      {
        "label": "Errors",
        "value": "4xx or 5xx with a JSON object of `name` (the Python exception), `message`, `arguments`, `context` and `debug` (a traceback). 401 for a bad key, 404 for an unknown model or method, 422 for bad arguments"
      },
      {
        "label": "Sandbox",
        "value": "Free trial database without a card, or a self-hosted Community server. Whether a trial database accepts external API calls was not established"
      },
      {
        "label": "Versions",
        "value": "Odoo 20.0 released September 2026 with standard support to September 2029. Odoo Online also runs SaaS versions released every two to three months"
      }
    ],
    "provenance": {
      "legalEntity": "Odoo SA",
      "domain": "odoo.com",
      "domainRegistered": "2001-01-25",
      "endpointOnVendorDomain": true,
      "terms": "https://www.odoo.com/documentation/20.0/legal/terms/enterprise.html",
      "privacy": "https://www.odoo.com/privacy",
      "statusPage": "https://status.odoo.com",
      "changelog": "https://www.odoo.com/odoo-20-release-notes",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The Odoo Enterprise Subscription Agreement (version 13, 24 September 2026) is between the customer and Odoo SA and its affiliates, under Belgian law, and covers the cloud platforms and self-hosting. The Acceptable Use Policy of 7 May 2025 is incorporated into it.",
        "The privacy policy (effective 24 September 2026) gives the postal contact as Odoo SA, Chaussée de Namur 40, Belgium, and privacy@odoo.com.",
        "www.odoo.com/.well-known/security.txt is PGP-signed and gives security@odoo.com, the disclosure policy and a hall of fame. It has no Expires field, which RFC 9116 requires.",
        "Odoo Online databases answer at \u003cname\u003e.odoo.com. A self-hosted server answers on the owner's own domain.",
        "status.odoo.com is a single page with component states and no history page. Its only dated entry on 8 October 2026 was the planned odoo.com upgrade of 4 August 2026.",
        "RDAP for odoo.com gives a registration date of 2001-01-25."
      ],
      "score": 98,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Odoo SA",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "odoo.com, registered 2001-01-25 (25 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "odoo.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 5 of the 7 things a reader expects",
          "points": 8.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.odoo.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.odoo.com/documentation/20.0/legal/terms/enterprise.html",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 6823,
          "points": 8.3,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "In case any one or more of the provisions of this Agreement or any application thereof shall be"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In no event will either party or its affiliates be liable for any indirect, special, exemplary,",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "breach, this Agreement may be terminated immediately by the non-breaching Party."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "activities, and strictly observe the rules outlined in the Acceptable Use Policy"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Hosting in Tier-III data centers or equivalent, with 99.9% network uptime",
              "says": "Names 99.9% availability"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The agreement renews automatically for an equal term, and on renewal charges below the current list price rise by up to 7 per cent a year.",
              "quote": "applicable list price, these charges will increase by up to 7% per year of the previous Term."
            },
            {
              "date": "2026-10-08",
              "text": "Each party's total liability is capped at 50 per cent of what the customer paid in the preceding 12 months.",
              "quote": "affiliates arising out of or related to this Agreement will not exceed 50% of the total amount"
            },
            {
              "date": "2026-10-08",
              "text": "A customer that breaches the section on software access and usage verification agrees to pay an extra fee of 300 per cent of list price for its users.",
              "quote": "fee equal to 300% of the applicable list price for the actual number of Users and Light Users."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.odoo.com/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-24",
          "words": 5218,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: September 24, 2026",
              "says": "Last updated 2026-09-24"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "As part of running those services we collect data about you and your business."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "The OAuth token is not stored and is deleted as soon as you close your Odoo.SH session, or after 2 days.",
              "says": "Names a period of 2 days"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "See also Google Privacy Policy and Terms of Use in the Third Party Service Providers section below."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Account \u0026 Contact Data: You have the right to access and update personal data you have previously provided to us."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have are any question regarding this Privacy Policy, or any enquiry about your personal data,please reach out to the Odoo Helpdesk or contact us via email at privacy@odoo.com or by post:",
              "says": "privacy@odoo.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Odoo uses EU Standard Contractual Clauses to bind subsidiaries in a way that offers sufficient safeguards on data protection for the limited and temporary data transfers that occur for such access.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "A cloud database is kept deactivated for three weeks after cancellation and then destroyed.",
              "quote": "For databases hosted on the Odoo Cloud, if you cancel the service your database is kept deactivated for 3 weeks (the grace period during which you can change your mind), and then destroyed."
            },
            {
              "date": "2026-10-08",
              "text": "Deleted personal data can remain in backups for up to 12 months.",
              "quote": "The personal data could remain stored for up to 12 months in those backups, until they are automatically destroyed."
            },
            {
              "date": "2026-10-08",
              "text": "Some optional In-App Purchase services may be active by default and send transaction data to third-party services.",
              "quote": "When you use Odoo on the Odoo Cloud or on your own self-hosted deployments, some optional \"In-App Purchase\" services may be active by default."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/odoo.json",
    "live": {
      "slug": "odoo",
      "vendorStatus": {
        "page": "https://status.odoo.com",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:38:51.647101455Z"
      },
      "updatedAt": "2026-10-08T19:38:51.647101455Z"
    }
  }
}
