Odoo External API

by Odoo SA HTTP API in Accounting & invoicing

Odoo SA · odoo.com since 2001 · status page · who's behind it

Odoo is a business suite from Odoo SA in Belgium with accounting, invoicing, sales, stock and HR apps on one database. Outside software reaches it through the JSON-2 HTTP API with API keys and, from Odoo 20, an MCP server.

Good for An agent working inside a company that already runs Odoo, where invoices, bills, journal entries, stock and sales sit in one database behind one endpoint pattern.

Is this your product? Claim this listing or verify it

Assessment. One endpoint pattern reaches every model, with field selection, filters and paging, and keys that expire within three months. On Odoo Online the external API needs the Custom plan, there is no OpenAPI file, and the acceptable use policy asks for about one call a second with no parallel calls.

Facts

Transport
HTTP
Auth
API key
Pricing
Paid · Paid
x402
No
Licence
Community edition LGPL-3.0. The Enterprise edition (the full Accounting app and the AI app with the MCP server) is proprietary under the Odoo Enterprise Subscription Agreement
llms.txt
not found
Last release
GitHub stars
55k
Surfaces
JSON-2 API at /json/2/<model>/<method> (new in Odoo 19.0, POST only, JSON body with ids, context and named arguments). MCP server at <database_url>/mcp (Odoo 20, AI app). XML-RPC and JSON-RPC at /xmlrpc/2 and /jsonrpc are deprecated
Plan needed
Custom plan only on Odoo Online. One App Free and Standard exclude the external API. A self-hosted Community server needs no plan
Credentials
API key per user from Preferences, Account Security, sent as a bearer token. Shown once, 160-bit, mandatory expiry of at most three months, scopes rpc and MCP, programmatic res.users.apikeys/generate and revoke
Rate limits
The acceptable use policy gives about 1 call a second, no parallel calls, for unsustained use. Odoo Online audit logs allow one request every 5 minutes. No 429 behaviour documented
Accounting objects
account.move (customer invoices, vendor bills, credit notes, receipts and journal entries by move_type), account.move.line, account.account, account.journal, account.payment, with action_post and action_register_payment
MCP tools
Exposed by default are Get Models, Get Fields, Search, Read group and MCP Retrieve initial context. Update Records, Create Records and about 20 navigation, website and media tools are off until an administrator ticks "Available in MCP"
Errors
4xx or 5xx with a JSON object of name (the Python exception), message, arguments, context and debug (a traceback). 401 for a bad key, 404 for an unknown model or method, 422 for bad arguments
Sandbox
Free trial database without a card, or a self-hosted Community server. Whether a trial database accepts external API calls was not established
Versions
Odoo 20.0 released September 2026 with standard support to September 2029. Odoo Online also runs SaaS versions released every two to three months

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • /json/2/<model>/<method> reaches every model the user can see, including account.move for invoices, bills and journal entries
  • API keys are per user, shown once, expire within three months at most and can be generated and revoked through the API
  • Odoo 20 adds an MCP server at <database_url>/mcp that exposes five read-only tools by default, with write tools switched on one by one
  • The Community edition is LGPLv3 and carries the same JSON-2 controller, so a self-hosted server answers the same calls at no charge
  • The privacy policy of 24 September 2026 names subprocessors, hosting regions and retention periods

Weaknesses

  • On Odoo Online the external API is limited to the Custom plan. One App Free and Standard exclude it
  • No OpenAPI file and no llms.txt. The per-database reference at /doc needs a login or a key, and its docs section reads "Under construction"
  • The acceptable use policy puts API traffic at about one call a second with no parallel calls. No 429 or Retry-After handling was found in the docs
  • No idempotency keys, and the JSON-2 docs say several calls cannot share one transaction
  • status.odoo.com has no history page, and its only dated entry is a planned upgrade on 4 August 2026
  • The full Accounting app and the MCP server are in the proprietary Enterprise edition. Community has Invoicing

Before you call it notes for agents

  1. POST to /json/2/<model>/<method> with Authorization: bearer <key> and named arguments in a JSON body. Add X-Odoo-Database when one host serves several databases
  2. Pass fields and limit on search_read. The default limit is every matching record
  3. Create invoices and bills on account.move with move_type set to out_invoice or in_invoice, then call action_post. A new move is a draft
  4. Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one create call
  5. Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date

Who's behind it provenance 98/100

  • Legal entity namedOdoo SA20/20
  • Domain ageodoo.com, registered 2001-01-25 (25 years)15/15
  • Endpoint on the vendor's domainodoo.com15/15
  • Terms of serviceread, states 5 of the 7 things a reader expects8.3/10
  • Privacy policyread, states 7 of the 8 things a reader expects9.3/10
  • Status pagestatus.odoo.com10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service gives no date, states 5 of 7

TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find how changes are announced. The rules found no clause to flag.

Gives the date it was last updated

Not found in the text.

Without a date nobody can tell which version they agreed to.

Names the governing law or courts
In case any one or more of the provisions of this Agreement or any application thereof shall be

Says where a dispute would be heard and under whose law.

States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
In no event will either party or its affiliates be liable for any indirect, special, exemplary,

Says the most the vendor would owe if the service causes a loss.

Says how the agreement or account can be ended
breach, this Agreement may be terminated immediately by the non-breaching Party.

Says when the vendor can cut off access and what notice it gives.

Says how changes to the terms are announced

Not found in the text.

Says whether a customer hears about a change before it binds them.

Lists what users may not do
activities, and strictly observe the rules outlined in the Acceptable Use Policy

The acceptable-use rules an agent acting for a user has to stay inside.

Refers to a service level or uptime commitment Names 99.9% availability
Hosting in Tier-III data centers or equivalent, with 99.9% network uptime

Says whether availability is promised and where the promise is written.

The agreement renews automatically for an equal term, and on renewal charges below the current list price rise by up to 7 per cent a year.
applicable list price, these charges will increase by up to 7% per year of the previous Term.

Noted by a second reader on 2026-10-08.

Each party's total liability is capped at 50 per cent of what the customer paid in the preceding 12 months.
affiliates arising out of or related to this Agreement will not exceed 50% of the total amount

Noted by a second reader on 2026-10-08.

A customer that breaches the section on software access and usage verification agrees to pay an extra fee of 300 per cent of list price for its users.
fee equal to 300% of the applicable list price for the actual number of Users and Light Users.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 6,823 words

Privacy policy dated 2026-09-24, states 7 of 8

TL;DR Dated 2026-09-24. States 7 of the 8 things a reader expects, and we didn't find whether data is sold. The rules found no clause to flag.

Gives the date it was last updated Last updated 2026-09-24
Effective date: September 24, 2026

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
As part of running those services we collect data about you and your business.

The basic statement a privacy policy exists to make.

Says how long data is kept Names a period of 2 days
The OAuth token is not stored and is deleted as soon as you close your Odoo.SH session, or after 2 days.

Says when data sent to the service is deleted.

Says who else receives the data
See also Google Privacy Policy and Terms of Use in the Third Party Service Providers section below.

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
Account & Contact Data: You have the right to access and update personal data you have previously provided to us.

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact privacy@odoo.com
If you have are any question regarding this Privacy Policy, or any enquiry about your personal data,please reach out to the Odoo Helpdesk or contact us via email at privacy@odoo.com or by post:

An address or officer to send a request to.

Says where data is transferred or stored Relies on standard contractual clauses
Odoo uses EU Standard Contractual Clauses to bind subsidiaries in a way that offers sufficient safeguards on data protection for the limited and temporary data transfers that occur for such access.

The countries data goes to and the safeguard used.

A cloud database is kept deactivated for three weeks after cancellation and then destroyed.
For databases hosted on the Odoo Cloud, if you cancel the service your database is kept deactivated for 3 weeks (the grace period during which you can change your mind), and then destroyed.

Noted by a second reader on 2026-10-08.

Deleted personal data can remain in backups for up to 12 months.
The personal data could remain stored for up to 12 months in those backups, until they are automatically destroyed.

Noted by a second reader on 2026-10-08.

Some optional In-App Purchase services may be active by default and send transaction data to third-party services.
When you use Odoo on the Odoo Cloud or on your own self-hosted deployments, some optional "In-App Purchase" services may be active by default.

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 5,218 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The Odoo Enterprise Subscription Agreement (version 13, 24 September 2026) is between the customer and Odoo SA and its affiliates, under Belgian law, and covers the cloud platforms and self-hosting. The Acceptable Use Policy of 7 May 2025 is incorporated into it.

The privacy policy (effective 24 September 2026) gives the postal contact as Odoo SA, Chaussée de Namur 40, Belgium, and privacy@odoo.com.

www.odoo.com/.well-known/security.txt is PGP-signed and gives security@odoo.com, the disclosure policy and a hall of fame. It has no Expires field, which RFC 9116 requires.

Odoo Online databases answer at <name>.odoo.com. A self-hosted server answers on the owner's own domain.

status.odoo.com is a single page with component states and no history page. Its only dated entry on 8 October 2026 was the planned odoo.com upgrade of 4 August 2026.

RDAP for odoo.com gives a registration date of 2001-01-25.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 19:38 UTC

  • Vendor status page unknown, no machine-readable status found · 1 hour ago

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/odoo.json

Notable

  • The JSON-2 docs state that access to data through the external API is only available on Custom plans and not on One App Free or Standard source
  • API keys cannot last more than three months, and res.users.apikeys/generate and revoke allow rotation by API, with 10 programmatic keys a user by default source
  • Odoo 20, released September 2026, adds an MCP server at <database_url>/mcp with an API key in the MCP scope. The documented client set-up runs npx -y mcp-remote source
  • The XML-RPC and JSON-RPC db service was removed in Odoo 20, and the common and object services are scheduled for removal in Odoo 22 (autumn 2028) and Online 21.1 (winter 2027) source
  • The acceptable use policy names unthrottled RPC or API calls as abuse and gives 1 call a second with no parallel calls as typically acceptable source
  • The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding guarantees source
  • The Community account module is named Invoicing in its manifest. The pricing page lists Accounting among the apps of the paid plans source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 8.8
Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 8.3
No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at /doc-bearer/index.json and /doc-bearer/<model>.json, which needs a key, and the docs section on it reads "Under construction" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11).
Agent ergonomics 13%16.2 10.9
fields on read and search_read and limit size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, offset, limit, order and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a "Readonly Tool" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7).
Security & auth 14%17.5 10.7
Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, rpc and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through get_audit_logs, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11).
Payments & pricing 10%12.5 2.8
No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 6.4
Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8).
Transparency & trusteditorial 87, provenance 98 7%8.8 8.1
The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18).
Negative events≤15None recorded0
Total55.9 · C

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 18 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Odoo External API, or have the agent fetch /fixes/odoo.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: Odoo External API

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/odoo, the October 2026 research run, assessed 8 October 2026. Grade C, 55.9 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on Odoo External API: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Reliability, 44 out of 100, up to 11.2 more on the total

Why it scored 44: Graded as the hosted service, Odoo Online, on the hosted lines. status.odoo.com lists components for Odoo Online and Odoo.sh with their current state, but has no history page and no visible API component (10). Its only dated entry is the planned odoo.com upgrade of 4 August 2026, so the last 90 days could not be read as an incident record (5). The acceptable use policy gives about 1 call a second with no parallel calls as typically acceptable, a guide and not an enforced figure, and audit logs are limited to one request every 5 minutes (10). No 429 or Retry-After handling and no idempotency keys were found. The docs do say each call is one transaction that rolls back on error (4). The cloud SLA page sets a 99.9 per cent monthly uptime target and says its objectives are not legally binding (5). JSON-2 has been generally available since Odoo 19.0 (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 2. Payments & pricing, 22 out of 100, up to 9.8 more on the total

Why it scored 22: No x402, MPP or L402 (0). Plan prices per user per month are public without a login (10). The free trial needs no card and the Community edition is free to self-host with the same API, but the free hosted plan excludes the external API and we could not confirm a trial database accepts API calls (12). A person signs up in a browser and creates the first key. The key API needs an existing key (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 3. Schema & documentation, 51 out of 100, up to 8 more on the total

Why it scored 51: No OpenAPI file. Each database serves a JSON description of its models, fields and method signatures at `/doc-bearer/index.json` and `/doc-bearer/<model>.json`, which needs a key, and the docs section on it reads "Under construction" (12). No llms.txt on www.odoo.com or under the documentation (0). The JSON-2 page explains bot users, transactions and when one method should replace two calls, and the ORM reference documents each generic method. The MCP tools have one-line descriptions (12). Method signatures are typed in the ORM reference, but arguments travel as a free JSON body and search domains are nested lists with no schema (6). Examples in Python, JavaScript and Bash, and one documented error object with 401, 403, 404 and 422 named (10). Docs are versioned by release (19.0, 20.0) with release notes and a dated removal plan for XML-RPC, but there is no API changelog of its own (11).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 4. Security & auth, 61 out of 100, up to 6.8 more on the total

Why it scored 61: Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by API. Scopes are coarse, and what a key can touch follows the user's access rights (25). The docs recommend a dedicated bot user with minimum rights, and the MCP server hides write tools until an administrator exposes them. The API itself has no confirmation step (14). Records hold text written by customers and suppliers, and no prompt-injection guidance was found (3). Odoo Online admin activity logs through `get_audit_logs`, and records keep the creating and writing user. No per-call log for the operator was found (8). Signed security.txt, a disclosure policy with CVE ids and advisories, a hall of fame with no cash bounty, and CSA STAR Level 1. No SOC 2 or ISO 27001 report for Odoo itself was found (11).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 5. Agent ergonomics, 67 out of 100, up to 5.4 more on the total

Why it scored 67: `fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). Search domains, `offset`, `limit`, `order` and grouped aggregates. The default limit is every matching record (18). Errors are JSON with the Python exception name, message and arguments and a matching HTTP status, with a traceback in place of stable error codes (12). No idempotency keys. A call commits or rolls back as a whole, calls cannot share a transaction, and MCP tools carry a "Readonly Tool" flag (8). Few required parameters and plain HTTP examples in three languages, with no official SDK (7).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 6. Maintenance & community, 73 out of 100, up to 2.4 more on the total

Why it scored 73: Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). The 20.0 release plus daily nightly builds in the last 90 days (20). Commits on the 18.0, 20.0, saas-19.4 and master branches on 8 October 2026. GitHub shows about 3,800 open issues and we could not read reply times (12). No official SDK. The MCP server is built in, and we did not find it in the MCP registry (3). Public CI on runbot.odoo.com across community, enterprise, upgrade and security checks. We did not read a pass rate (8).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 7. Transparency & trust, 93 out of 100, up to 0.6 more on the total

Made of editorial 87, provenance 98.

Why it scored 93: The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise code under a published agreement (24). Privacy policy effective 24 September 2026 with retention periods (logs 12 months, a cancelled database destroyed after 3 weeks, backups at least 3 months) and data protection terms inside the subscription agreement. No stand-alone DPA was read (27). XML-RPC and JSON-RPC removal is dated to Odoo 22 in autumn 2028, and a support table gives each version's end date (18). Subprocessors (OVH, Google Cloud, Amazon and others) and production and backup locations for five hosting regions are listed (18).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: read, states 5 of the 7 things a reader expects (8.3 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: US dollar prices. The pricing page served GBP to our UK address, so `unitPrices` is empty
- unchecked: whether a free trial database accepts external API calls before a Custom subscription starts
- unchecked: the MCP tool input schemas and annotations. The AI app is Enterprise code and is not in the public repository, so only the documentation was read
- unchecked: whether a profit and loss report can be read through JSON-2. The reporting engine is Enterprise code, so `accounting.reports` is left out
- unchecked: issue and pull request reply times on GitHub, and the pass rate on runbot.odoo.com
- unchecked: the MCP registry was not searched for an Odoo entry
- status.odoo.com carries placeholder text and sample data in parts of its markup that are hidden or commented out. We scored only what a reader sees
- The lead pointed at the 19.0 docs. Odoo 20.0 was released in September 2026 and is the version read here
- No SOC 2 or ISO 27001 report for Odoo itself was found on the security page. Data centre certifications are listed in the privacy policy

## Weaknesses

- On Odoo Online the external API is limited to the Custom plan. One App Free and Standard exclude it
- No OpenAPI file and no llms.txt. The per-database reference at `/doc` needs a login or a key, and its docs section reads "Under construction"
- The acceptable use policy puts API traffic at about one call a second with no parallel calls. No 429 or Retry-After handling was found in the docs
- No idempotency keys, and the JSON-2 docs say several calls cannot share one transaction
- status.odoo.com has no history page, and its only dated entry is a planned upgrade on 4 August 2026
- The full Accounting app and the MCP server are in the proprietary Enterprise edition. Community has Invoicing

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- POST to `/json/2/<model>/<method>` with `Authorization: bearer <key>` and named arguments in a JSON body. Add `X-Odoo-Database` when one host serves several databases
- Pass `fields` and `limit` on `search_read`. The default limit is every matching record
- Create invoices and bills on `account.move` with `move_type` set to `out_invoice` or `in_invoice`, then call `action_post`. A new move is a draft
- Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one `create` call
- Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: US dollar prices. The pricing page served GBP to our UK address, so unitPrices is empty
  • unchecked: whether a free trial database accepts external API calls before a Custom subscription starts
  • unchecked: the MCP tool input schemas and annotations. The AI app is Enterprise code and is not in the public repository, so only the documentation was read
  • unchecked: whether a profit and loss report can be read through JSON-2. The reporting engine is Enterprise code, so accounting.reports is left out
  • unchecked: issue and pull request reply times on GitHub, and the pass rate on runbot.odoo.com
  • unchecked: the MCP registry was not searched for an Odoo entry
  • status.odoo.com carries placeholder text and sample data in parts of its markup that are hidden or commented out. We scored only what a reader sees
  • The lead pointed at the 19.0 docs. Odoo 20.0 was released in September 2026 and is the version read here
  • No SOC 2 or ISO 27001 report for Odoo itself was found on the security page. Data centre certifications are listed in the privacy policy

Sources 18

  1. External JSON-2 API reference, Odoo 20.0 (plan limit, keys, errors, transactions, RPC removal dates) odoo.com · seen 2026-10-08
  2. MCP server documentation, read from the 20.0 branch of odoo/documentation odoo.com · seen 2026-10-08
  3. MCP tool list odoo.com · seen 2026-10-08
  4. Pricing page (GBP shown) odoo.com · seen 2026-10-08
  5. Acceptable use policy (API throttling) odoo.com · seen 2026-10-08
  6. Cloud SLA page odoo.com · seen 2026-10-08
  7. Status page status.odoo.com · seen 2026-10-08
  8. Odoo Enterprise Subscription Agreement, version 13 odoo.com · seen 2026-10-08
  9. Privacy policy odoo.com · seen 2026-10-08
  10. Security page and responsible disclosure policy odoo.com · seen 2026-10-08
  11. security.txt odoo.com · seen 2026-10-08
  12. Supported versions table odoo.com · seen 2026-10-08
  13. Odoo 20 release notes odoo.com · seen 2026-10-08
  14. JSON-2 controller, API key model, `account` module and `/doc-bearer` routes on the 20.0 branch (shallow clone) github.com · seen 2026-10-08
  15. Odoo Online administration (database list and audit logs through JSON-2) odoo.com · seen 2026-10-08
  16. Nightly builds for 20.0 nightly.odoo.com · seen 2026-10-08
  17. Public CI runbot.odoo.com · seen 2026-10-08
  18. NVD keyword search for Odoo, 8 October 2025 to 8 October 2026 services.nvd.nist.gov · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Paid Paid Odoo Online needs the Custom plan for the external API. On 8 October 2026 the pricing page, read from a UK address, showed Custom at £41 a user a month billed yearly or £52 billed monthly (£32 and £41 for the first 12 months), Standard at £22 or £28 without the external API, and One App Free at £0 for one app without it. A free trial needs no card. The Community edition is free to self-host under LGPLv3 and includes the JSON-2 API. We did not read US dollar prices, so the price table is empty.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/odoo.xml, or this listing's score history at history.json.

Connect

First request

curl https://$DATABASE.odoo.com/json/2/res.partner/search_read \
  -X POST \
  --oauth2-bearer $API_KEY \
  -H "X-Odoo-Database: $DATABASE" \
  -H "Content-Type: application/json" \
  -d '{"domain": [["is_company", "=", true]], "fields": ["name"]}'

Claude Code

claude mcp add --transport stdio <server_name> -- npx -y mcp-remote <database_url>/mcp --header "Authorization: Bearer <API_KEY>"

MCP client configuration

{
  "mcpServers": {
    "odoo": {
      "args": [
        "-y",
        "mcp-remote",
        "\u003cdatabase_url\u003e/mcp",
        "--header",
        "Authorization: Bearer \u003cAPI_KEY\u003e"
      ],
      "command": "npx"
    }
  }
}

Through letme picks today, calling later

GET https://letme.dev/odoo

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Apideck Accounting API + MCP ApideckBB72.9accounting.ledger accounting.invoices accounting.billsno
Merge Accounting API MergeBB70accounting.ledger accounting.invoices accounting.billsno
Xero API + MCP XeroB67.2accounting.ledger accounting.invoices accounting.billsno
Codat Codat LimitedB64.3accounting.bills accounting.ledger accounting.invoicesno
Zoho Books ZohoC61.1accounting.ledger accounting.invoices accounting.billsno
FreeAgent API FreeAgentC57.2accounting.ledger accounting.invoices accounting.billsno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    Odoo External API on Anchor Terminal, C, 55.9/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/odoo"><img src="https://www.anchorterminal.com/badges/odoo.svg" alt="Odoo External API on Anchor Terminal" height="20"></a>
    [![Odoo External API on Anchor Terminal](https://www.anchorterminal.com/badges/odoo.svg)](https://www.anchorterminal.com/tools/odoo)

    It counts on a page on odoo.com or one of its subdomains, or the README of github.com/odoo/odoo.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "odoo", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.