Odoo Mcp Gateway
About
Security-first MCP gateway for Odoo 17/18/19 — 27 tools, YAML-driven security
Explore
- Rate limiting — per-session token bucket with separate global and write budgets
- RBAC — tool-level access control by user group, field-level response filtering
- Input validation — model names, method names, field names, domain filters, ORDER BY clauses, write values (size/depth/type)
- IDOR protection — plugin tools scope data access to the authenticated user
- Audit logging — structured JSON logs for all allowed and denied operations
- Error sanitization — strips internal URLs, SQL fragments, file paths, stack traces from error messages
- XXE protection — XML-RPC responses parsed with defusedxml
- Domain validation — Odoo domain filters validated for operators, field names, value types, nesting depth, and list sizes
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Odoo Mcp GatewayCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
pip install odoo-mcp-gateway
cp config/restrictions.yaml.example config/restrictions.yaml
cp config/model_access.yaml.example config/model_access.yaml
cp config/rbac.yaml.example config/rbac.yaml
export ODOO_URL=http://localhost:8069
export ODOO_DB=mydb
Add to claude_desktop_config.json:
json{
"mcpServers": {
"odoo": {
"command": "python",
"args": ["-m", "odoo_mcp_gateway"],
"env": {
"ODOO_URL": "http://localhost:8069",
"ODOO_DB": "mydb"
}
}
}
}
bash
| Variable | Default | Description |
|----------|---------|-------------|
| ODOO_URL | http://localhost:8069 | Odoo server URL |
| ODOO_DB | (required) | Odoo database name |
| MCP_TRANSPORT | stdio | Transport mode (stdio or streamable-http) |
| MCP_HOST | 127.0.0.1 | HTTP host (streamable-http mode) |
| MCP_PORT | 8080 | HTTP port (streamable-http mode) |
| MCP_LOG_LEVEL | INFO | Logging level |
Three stock Odoo auth methods — no custom addon needed:
| Method | Protocol | Use Case |
|--------|----------|----------|
| api_key | XML-RPC | Server-to-server, CI/CD pipelines |
| password | JSON-RPC | Interactive users, Claude Desktop |
| session | JSON-RPC | Reuse existing browser session (development) |
| File | Purpose |
|------|---------|
| config/restrictions.yaml | Model/method/field block lists (3 tiers) |
| config/model_access.yaml | Per-model access policies, allowed methods, sensitive fields |
| config/rbac.yaml | Role-based tool access and field filtering by group |
| config/gateway.yaml | Server, connection, auth settings |
All files have .example templates with extensive inline documentation. Copy and customize:
bashcp config/restrictions.yaml.example config/restrictions.yaml
cp config/model_access.yaml.example config/model_access.yaml
cp config/rbac.yaml.example config/rbac.yaml
odoo-mcp-tools validate-config --config-dir config
odoo-mcp-tools list-models --config-dir config
login
Authenticate with Odoo (api_key / password / session)
list_models
List accessible models with metadata and keyword filter
get_model_fields
Get field definitions for a model with optional filter
search_read
Search records with domain filters, field selection, ordering
get_record
Get a single record by ID
search_count
Count matching records
create_record
Create a new record (validates field names and values)
update_record
Update existing record (validates field names and values)
delete_record
Delete a single record by ID
read_group
Aggregated grouped reads with aggregate functions
execute_method
Call allowed model methods (validates method name)
> login(method="password", username="admin", credential="admin", database="mydb")
``
| Tool | Description |
|------|-------------|
| login | Authenticate with Odoo (api_key / password / session) |list_models
| | List accessible models with metadata and keyword filter |get_model_fields
| | Get field definitions for a model with optional filter |search_read
| | Search records with domain filters, field selection, ordering |get_record
| | Get a single record by ID |search_count
| | Count matching records |create_record
| | Create a new record (validates field names and values) |update_record
| | Update existing record (validates field names and values) |delete_record
| | Delete a single record by ID |read_group
| | Aggregated grouped reads with aggregate functions |execute_method` | Call allowed model methods (validates method name) |
|
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"odoo mcp gateway": {
"odoo-mcp-gateway": {
"command": "python",
"args": [
"-m",
"odoo_mcp_gateway"
]
}
}
}
}
McpServers
{
"odoo-mcp-gateway": {
"command": "python",
"args": [
"-m",
"odoo_mcp_gateway"
]
}
}
Security-first, version-agnostic MCP gateway for Odoo 17/18/19. Works with stock and custom modules via YAML configuration. Zero Odoo-side code required.
<!-- mcp-name: io.github.parth-unjiya/odoo-mcp-gateway -->
Why This Exists
Existing Odoo MCP servers share common problems: hardcoded model lists that miss custom modules, security as an afterthought, mandatory custom Odoo addons, and single-version targets. This gateway solves all of them:
- Two-layer security — MCP restrictions (YAML) + Odoo's built-in ACLs (ir.model.access + ir.rule)
- YAML-driven configuration — model restrictions, RBAC, field-level access, rate limiting, audit logging
- Custom module support — auto-discovers models via ir.model, add YAML config and it works
- Version-agnostic — Odoo 17, 18, 19 with version-specific adapters
- Zero Odoo-side code — pip install + YAML config = done. No custom addon required
- Full MCP primitives — 27 Tools + 5 Resources + 7 Prompts (most servers only implement Tools)
- Plugin architecture — extend with pip-installable domain packs via entry_points
Architecture
MCP Client (Claude Desktop / Claude Code / HTTP)
| User calls login tool with Odoo credentials
v
MCP Server (FastMCP)
|
|-- security_gate() --> Rate limit + RBAC tool access + audit logging
|-- restrictions --> Model/method/field block lists (YAML + hardcoded)
|-- rbac --> Field-level filtering + write sanitization
|
|-- tools/ --> 27 MCP tools (auth + schema + CRUD + plugins)
|-- resources/ --> 5 MCP resources (odoo:// URIs)
|-- prompts/ --> 7 reusable prompt templates
|-- plugins/ --> Entry-point plugin system (HR, Sales, Project, Helpdesk)
|
| JSON-RPC / XML-RPC as authenticated user
v
Odoo 17/18/19 (security enforced per user via ir.model.access + ir.rule)
Security Pipeline
Every tool and resource call passes through this pipeline:
Request --> Rate Limit --> Authentication Check --> RBAC Tool Access
--> Model Restriction --> Method Restriction --> Field Validation
--> Handler Execution --> RBAC Field Filtering --> Audit Log --> Response
Hardcoded safety guardrails that cannot be overridden by YAML:
- 18 always-blocked models (ir.config_parameter, ir.cron, ir.module.module, ir.rule, ir.mail_server, etc.)
- 18 always-blocked methods (sudo, with_user, with_env, _sql, _write, _create, etc.)
- 28 ORM methods blocked in execute_method (prevents bypassing field-level checks)
Quick Start
```bash
pip install odoo-mcp-gateway
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



