{
  "fixes": {
    "slug": "odoo",
    "name": "Odoo External API",
    "listing": "https://www.anchorterminal.com/tools/odoo",
    "markdown": "# Fix list: Odoo External API\n\nFrom Anchor Terminal's listing at https://www.anchorterminal.com/tools/odoo, the October 2026 research run, assessed 8 October 2026. Grade C, 55.9 out of 100.\n\nThis is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.\n\nFor a coding agent working on Odoo External API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.\n\n## 1. Reliability, 44 out of 100, up to 11.2 more on the total\n\nWhy it scored 44: Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):\n\nHosted APIs, MCP servers, models and platforms.\n\n- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.\n\nLocal packages, SDKs, frameworks and stdio MCP servers.\n\n- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.\n\nProtocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.\n\n## 2. Payments \u0026 pricing, 22 out of 100, up to 9.8 more on the total\n\nWhy it scored 22: No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):\n\nThe published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).\n\n- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).\n\nPayment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.\n\nOpen-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.\n\n## 3. Schema \u0026 documentation, 51 out of 100, up to 8 more on the total\n\nWhy it scored 51: No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at `/doc-bearer/index.json` and `/doc-bearer/\u003cmodel\u003e.json`, which needs a key, and the docs section on it reads \"Under construction\" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):\n\nAPIs and MCP servers.\n\n- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.\n\nModels are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.\n\n## 4. Security \u0026 auth, 61 out of 100, up to 6.8 more on the total\n\nWhy it scored 61: Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through `get_audit_logs`, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-security):\n\n- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.\n\nModels are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.\n\n## 5. Agent ergonomics, 67 out of 100, up to 5.4 more on the total\n\nWhy it scored 67: `fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, `offset`, `limit`, `order` and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a \"Readonly Tool\" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):\n\n- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.\n\nModels are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.\n\n## 6. Maintenance \u0026 community, 73 out of 100, up to 2.4 more on the total\n\nWhy it scored 73: Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):\n\n- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.\n\nModels are read for deprecation notice periods and model churn rather than release counts.\n\n## 7. Transparency \u0026 trust, 93 out of 100, up to 0.6 more on the total\n\nMade of editorial 87, provenance 98.\n\nWhy it scored 93: The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18).\n\nThe checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):\n\n- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).\n\nThe other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.\n\nProvenance checks not met in full (half of this category, computed from checked facts):\n\n- Terms of service: read, states 5 of the 7 things a reader expects (8.3 of 10)\n- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)\n\n## What we couldn't check\n\nWhat we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.\n\n- unchecked: US dollar prices. The pricing page served GBP to our UK address, so `unitPrices` is empty\n- unchecked: whether a free trial database accepts external API calls before a Custom subscription starts\n- unchecked: the MCP tool input schemas and annotations. The AI app is Enterprise code and is not in the public repository, so only the documentation was read\n- unchecked: whether a profit and loss report can be read through JSON-2. The reporting engine is Enterprise code, so `accounting.reports` is left out\n- unchecked: issue and pull request reply times on GitHub, and the pass rate on runbot.odoo.com\n- unchecked: the MCP registry was not searched for an Odoo entry\n- status.odoo.com carries placeholder text and sample data in parts of its markup that are hidden or commented out. We scored only what a reader sees\n- The lead pointed at the 19.0 docs. Odoo 20.0 was released in September 2026 and is the version read here\n- No SOC 2 or ISO 27001 report for Odoo itself was found on the security page. Data centre certifications are listed in the privacy policy\n\n## Weaknesses\n\n- On Odoo Online the external API is limited to the Custom plan. One App Free and Standard exclude it\n- No OpenAPI file and no llms.txt. The per-database reference at `/doc` needs a login or a key, and its docs section reads \"Under construction\"\n- The acceptable use policy puts API traffic at about one call a second with no parallel calls. No 429 or Retry-After handling was found in the docs\n- No idempotency keys, and the JSON-2 docs say several calls cannot share one transaction\n- status.odoo.com has no history page, and its only dated entry is a planned upgrade on 4 August 2026\n- The full Accounting app and the MCP server are in the proprietary Enterprise edition. Community has Invoicing\n\n## What costs an agent a turn today\n\nThe notes we give agents before they call it. Each one is a workaround an agent shouldn't need.\n\n- POST to `/json/2/\u003cmodel\u003e/\u003cmethod\u003e` with `Authorization: bearer \u003ckey\u003e` and named arguments in a JSON body. Add `X-Odoo-Database` when one host serves several databases\n- Pass `fields` and `limit` on `search_read`. The default limit is every matching record\n- Create invoices and bills on `account.move` with `move_type` set to `out_invoice` or `in_invoice`, then call `action_post`. A new move is a draft\n- Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one `create` call\n- Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date\n\n## When it's done\n\nSend what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `\"kind\": \"dispute\"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.\n",
    "grade": "C",
    "score": 55.9,
    "assessed": "2026-10-08",
    "run": "October 2026 research run",
    "categories": [
      {
        "key": "reliability",
        "name": "Reliability",
        "score": 44,
        "maxGain": 11.2,
        "reason": "Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10).",
        "checklist": [
          "Hosted APIs, MCP servers, models and platforms.",
          "- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).\n- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.\n- 15, rate limits documented with numbers.\n- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.\n- 10, an SLA published for any paid tier.\n- 10, the surface agents use is generally available, not beta or preview.",
          "Local packages, SDKs, frameworks and stdio MCP servers.",
          "- 20, installs from an official package with supported runtimes stated.\n- 25, a public CI and test suite, passing on the default branch.\n- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).\n- 15, semver discipline and breaking changes called out in a changelog.\n- 15, version 1.0 or later, or declared stable.",
          "Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-reliability"
      },
      {
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "score": 22,
        "maxGain": 9.8,
        "reason": "No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0).",
        "checklist": [
          "The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).",
          "- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.\n- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for \"contact sales\" or prices behind a login.\n- 20, a free tier or trial that doesn't need a card.\n- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).",
          "Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.",
          "Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-payments"
      },
      {
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "score": 51,
        "maxGain": 8,
        "reason": "No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at `/doc-bearer/index.json` and `/doc-bearer/\u003cmodel\u003e.json`, which needs a key, and the docs section on it reads \"Under construction\" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11).",
        "checklist": [
          "APIs and MCP servers.",
          "- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).\n- 10, llms.txt or Markdown docs served for agents.\n- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.\n- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.\n- 0 to 15, examples and documented error responses.\n- 15, versioning and a public changelog.",
          "Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-schema"
      },
      {
        "key": "security",
        "name": "Security \u0026 auth",
        "score": 61,
        "maxGain": 6.8,
        "reason": "Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through `get_audit_logs`, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11).",
        "checklist": [
          "- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.\n- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.\n- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.\n- 0 to 15, audit logs or per-call visibility for the operator.\n- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.",
          "Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-security"
      },
      {
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "score": 67,
        "maxGain": 5.4,
        "reason": "`fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, `offset`, `limit`, `order` and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a \"Readonly Tool\" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7).",
        "checklist": [
          "- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).\n- 20, pagination, filtering and output-size controls.\n- 20, actionable, documented error responses, codes and messages an agent can recover from.\n- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.\n- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.",
          "Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-ergonomics"
      },
      {
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "score": 73,
        "maxGain": 2.4,
        "reason": "Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8).",
        "checklist": [
          "- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.\n- 20, at least three releases or dated changelog entries in the last 90 days.\n- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.\n- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).\n- 10, package health, current dependencies and CI.",
          "Models are read for deprecation notice periods and model churn rather than release counts."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-maintenance"
      },
      {
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "score": 93,
        "maxGain": 0.6,
        "reason": "The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18).",
        "blend": "editorial 87, provenance 98",
        "checklist": [
          "- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.\n- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).\n- 0 to 20, a deprecation policy or notices with dates.\n- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).",
          "The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two."
        ],
        "checklistUrl": "https://www.anchorterminal.com/benchmark/#checklist-transparency"
      }
    ],
    "provenance": [
      {
        "label": "Terms of service",
        "value": "read, states 5 of the 7 things a reader expects",
        "points": 8.3,
        "max": 10
      },
      {
        "label": "Privacy policy",
        "value": "read, states 7 of the 8 things a reader expects",
        "points": 9.3,
        "max": 10
      }
    ],
    "unchecked": [
      "unchecked: US dollar prices. The pricing page served GBP to our UK address, so `unitPrices` is empty",
      "unchecked: whether a free trial database accepts external API calls before a Custom subscription starts",
      "unchecked: the MCP tool input schemas and annotations. The AI app is Enterprise code and is not in the public repository, so only the documentation was read",
      "unchecked: whether a profit and loss report can be read through JSON-2. The reporting engine is Enterprise code, so `accounting.reports` is left out",
      "unchecked: issue and pull request reply times on GitHub, and the pass rate on runbot.odoo.com",
      "unchecked: the MCP registry was not searched for an Odoo entry",
      "status.odoo.com carries placeholder text and sample data in parts of its markup that are hidden or commented out. We scored only what a reader sees",
      "The lead pointed at the 19.0 docs. Odoo 20.0 was released in September 2026 and is the version read here",
      "No SOC 2 or ISO 27001 report for Odoo itself was found on the security page. Data centre certifications are listed in the privacy policy"
    ],
    "weaknesses": [
      "On Odoo Online the external API is limited to the Custom plan. One App Free and Standard exclude it",
      "No OpenAPI file and no llms.txt. The per-database reference at `/doc` needs a login or a key, and its docs section reads \"Under construction\"",
      "The acceptable use policy puts API traffic at about one call a second with no parallel calls. No 429 or Retry-After handling was found in the docs",
      "No idempotency keys, and the JSON-2 docs say several calls cannot share one transaction",
      "status.odoo.com has no history page, and its only dated entry is a planned upgrade on 4 August 2026",
      "The full Accounting app and the MCP server are in the proprietary Enterprise edition. Community has Invoicing"
    ],
    "agentNotes": [
      "POST to `/json/2/\u003cmodel\u003e/\u003cmethod\u003e` with `Authorization: bearer \u003ckey\u003e` and named arguments in a JSON body. Add `X-Odoo-Database` when one host serves several databases",
      "Pass `fields` and `limit` on `search_read`. The default limit is every matching record",
      "Create invoices and bills on `account.move` with `move_type` set to `out_invoice` or `in_invoice`, then call `action_post`. A new move is a draft",
      "Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one `create` call",
      "Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date"
    ],
    "recheck": "https://www.anchorterminal.com/builders/#disputes"
  },
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  }
}
