# Odoo External API (slim) > Odoo is a business suite from Odoo SA in Belgium with accounting, invoicing, sales, stock and HR apps on one database. Outside software reaches it through the JSON-2 HTTP API with API keys and, from Odoo 20, an MCP server. - Full: https://www.anchorterminal.com/tools/odoo.md (~7,200 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/odoo.json · canonical https://www.anchorterminal.com/tools/odoo - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 55.9/100 · rank #499 of 722 · #7 in Accounting & invoicing · not agent-ready · confidence medium** Assessment: One endpoint pattern reaches every model, with field selection, filters and paging, and keys that expire within three months. On Odoo Online the external API needs the Custom plan, there is no OpenAPI file, and the acceptable use policy asks for about one call a second with no parallel calls. ## Facts - Kind: HTTP API · vendor: Odoo SA · category: Accounting & invoicing · legal entity: Odoo SA · provenance 98/100 - Local only (HTTP) - Auth: API key · pricing: Paid · x402: no · licence: Community edition LGPL-3.0. The Enterprise edition (the full Accounting app and the AI app with the MCP server) is proprietary under the Odoo Enterprise Subscription Agreement - Probe metrics: not measured yet (probes haven't run) - Surfaces: JSON-2 API at `/json/2//` (new in Odoo 19.0, POST only, JSON body with `ids`, `context` and named arguments). MCP server at `/mcp` (Odoo 20, AI app). XML-RPC and JSON-RPC at `/xmlrpc/2` and `/jsonrpc` are deprecated - Plan needed: Custom plan only on Odoo Online. One App Free and Standard exclude the external API. A self-hosted Community server needs no plan - Credentials: API key per user from Preferences, Account Security, sent as a bearer token. Shown once, 160-bit, mandatory expiry of at most three months, scopes `rpc` and MCP, programmatic `res.users.apikeys/generate` and `revoke` - Rate limits: The acceptable use policy gives about 1 call a second, no parallel calls, for unsustained use. Odoo Online audit logs allow one request every 5 minutes. No 429 behaviour documented - Accounting objects: `account.move` (customer invoices, vendor bills, credit notes, receipts and journal entries by `move_type`), `account.move.line`, `account.account`, `account.journal`, `account.payment`, with `action_post` and `action_register_payment` - MCP tools: Exposed by default are Get Models, Get Fields, Search, Read group and MCP Retrieve initial context. Update Records, Create Records and about 20 navigation, website and media tools are off until an administrator ticks "Available in MCP" - Errors: 4xx or 5xx with a JSON object of `name` (the Python exception), `message`, `arguments`, `context` and `debug` (a traceback). 401 for a bad key, 404 for an unknown model or method, 422 for bad arguments - Sandbox: Free trial database without a card, or a self-hosted Community server. Whether a trial database accepts external API calls was not established - Versions: Odoo 20.0 released September 2026 with standard support to September 2029. Odoo Online also runs SaaS versions released every two to three months - Scores: Reliability 44, Performance pending, Schema & documentation 51, Agent ergonomics 67, Security & auth 61, Payments & pricing 22, Task success pending, Maintenance & community 73, Transparency & trust 93 · total over the 7 assessed categories - Why: Reliability, Graded as the hosted service, Odoo Online, on the hosted lines. · Schema & documentation, No OpenAPI file. · Agent ergonomics, `fields` on `read` and `search_read` and `limit` size a response, and the MCP server exposes five tools by default out of about 30 (22). · Security & auth, Per-user API keys in a header, shown once, revocable, with a mandatory expiry of at most three months, `rpc` and MCP scopes and rotation by… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Nightly 20.0 build dated 8 October 2026, and Odoo 20.0 released September 2026 (30). · Transparency & trust, The Community edition, including the JSON-2 controller, is LGPLv3. The full Accounting app and the MCP server are proprietary Enterprise cod… - Sources: 18, open questions: 9, both in the full twin - Capabilities: accounting.ledger, accounting.invoices, accounting.bills - JSON: https://www.anchorterminal.com/api/v1/tools/odoo.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/odoo.svg` or a link to https://www.anchorterminal.com/tools/odoo from a page on odoo.com or one of its subdomains, or the README of github.com/odoo/odoo, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. POST to `/json/2//` with `Authorization: bearer ` and named arguments in a JSON body. Add `X-Odoo-Database` when one host serves several databases 2. Pass `fields` and `limit` on `search_read`. The default limit is every matching record 3. Create invoices and bills on `account.move` with `move_type` set to `out_invoice` or `in_invoice`, then call `action_post`. A new move is a draft 4. Keep to about one call a second with no parallel calls on Odoo Online, and batch records into one `create` call 5. Ask the owner for a key on a dedicated bot user with the minimum access rights, and rotate it before its expiry date ## Connect ```bash curl https://$DATABASE.odoo.com/json/2/res.partner/search_read \ -X POST \ --oauth2-bearer $API_KEY \ -H "X-Odoo-Database: $DATABASE" \ -H "Content-Type: application/json" \ -d '{"domain": [["is_company", "=", true]], "fields": ["name"]}' ``` ```bash claude mcp add --transport stdio -- npx -y mcp-remote /mcp --header "Authorization: Bearer " ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/odoo ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Apideck Accounting API + MCP | BB | 72.9 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/apideck-accounting.min.md | | Merge Accounting API | BB | 70 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/merge-accounting.min.md | | Xero API + MCP | B | 67.2 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/xero.min.md | | Codat | B | 64.3 | accounting.bills, accounting.ledger, accounting.invoices | https://www.anchorterminal.com/tools/codat.min.md | | Zoho Books | C | 61.1 | accounting.ledger, accounting.invoices, accounting.bills | https://www.anchorterminal.com/tools/zoho-books.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)