Odoo Mcp Gateway

by parth-unjiya

1.1k downloads Not rated yet
GitHub

About

Security-first MCP gateway for Odoo 17/18/19 — 27 tools, YAML-driven security

Explore

- Rate limiting — per-session token bucket with separate global and write budgets
- RBAC — tool-level access control by user group, field-level response filtering
- Input validation — model names, method names, field names, domain filters, ORDER BY clauses, write values (size/depth/type)
- IDOR protection — plugin tools scope data access to the authenticated user
- Audit logging — structured JSON logs for all allowed and denied operations
- Error sanitization — strips internal URLs, SQL fragments, file paths, stack traces from error messages
- XXE protection — XML-RPC responses parsed with defusedxml
- Domain validation — Odoo domain filters validated for operators, field names, value types, nesting depth, and list sizes

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Odoo Mcp Gateway
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

pip install odoo-mcp-gateway

cp config/restrictions.yaml.example config/restrictions.yaml
cp config/model_access.yaml.example config/model_access.yaml
cp config/rbac.yaml.example config/rbac.yaml

export ODOO_URL=http://localhost:8069
export ODOO_DB=mydb

Add to claude_desktop_config.json:

json
{
"mcpServers": {
"odoo": {
"command": "python",
"args": ["-m", "odoo_mcp_gateway"],
"env": {
"ODOO_URL": "http://localhost:8069",
"ODOO_DB": "mydb"
}
}
}
}

bash

| Variable | Default | Description |
|----------|---------|-------------|
| ODOO_URL | http://localhost:8069 | Odoo server URL |
| ODOO_DB | (required) | Odoo database name |
| MCP_TRANSPORT | stdio | Transport mode (stdio or streamable-http) |
| MCP_HOST | 127.0.0.1 | HTTP host (streamable-http mode) |
| MCP_PORT | 8080 | HTTP port (streamable-http mode) |
| MCP_LOG_LEVEL | INFO | Logging level |

Three stock Odoo auth methods — no custom addon needed:

| Method | Protocol | Use Case |
|--------|----------|----------|
| api_key | XML-RPC | Server-to-server, CI/CD pipelines |
| password | JSON-RPC | Interactive users, Claude Desktop |
| session | JSON-RPC | Reuse existing browser session (development) |


| File | Purpose |
|------|---------|
| config/restrictions.yaml | Model/method/field block lists (3 tiers) |
| config/model_access.yaml | Per-model access policies, allowed methods, sensitive fields |
| config/rbac.yaml | Role-based tool access and field filtering by group |
| config/gateway.yaml | Server, connection, auth settings |

All files have .example templates with extensive inline documentation. Copy and customize:

bash
cp config/restrictions.yaml.example config/restrictions.yaml
cp config/model_access.yaml.example config/model_access.yaml
cp config/rbac.yaml.example config/rbac.yaml

odoo-mcp-tools validate-config --config-dir config

odoo-mcp-tools list-models --config-dir config

login

Authenticate with Odoo (api_key / password / session)

list_models

List accessible models with metadata and keyword filter

get_model_fields

Get field definitions for a model with optional filter

search_read

Search records with domain filters, field selection, ordering

get_record

Get a single record by ID

search_count

Count matching records

create_record

Create a new record (validates field names and values)

update_record

Update existing record (validates field names and values)

delete_record

Delete a single record by ID

read_group

Aggregated grouped reads with aggregate functions

execute_method

Call allowed model methods (validates method name)

> login(method="password", username="admin", credential="admin", database="mydb")
``

| Tool | Description |
|------|-------------|
|
login | Authenticate with Odoo (api_key / password / session) |
|
list_models | List accessible models with metadata and keyword filter |
|
get_model_fields | Get field definitions for a model with optional filter |
|
search_read | Search records with domain filters, field selection, ordering |
|
get_record | Get a single record by ID |
|
search_count | Count matching records |
|
create_record | Create a new record (validates field names and values) |
|
update_record | Update existing record (validates field names and values) |
|
delete_record | Delete a single record by ID |
|
read_group | Aggregated grouped reads with aggregate functions |
|
execute_method` | Call allowed model methods (validates method name) |

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "odoo mcp gateway": {
            "odoo-mcp-gateway": {
                "command": "python",
                "args": [
                    "-m",
                    "odoo_mcp_gateway"
                ]
            }
        }
    }
}

McpServers

{
    "odoo-mcp-gateway": {
        "command": "python",
        "args": [
            "-m",
            "odoo_mcp_gateway"
        ]
    }
}

Security-first, version-agnostic MCP gateway for Odoo 17/18/19. Works with stock and custom modules via YAML configuration. Zero Odoo-side code required.

Python 3.10+
License: MIT
Odoo

<!-- mcp-name: io.github.parth-unjiya/odoo-mcp-gateway -->

Why This Exists

Existing Odoo MCP servers share common problems: hardcoded model lists that miss custom modules, security as an afterthought, mandatory custom Odoo addons, and single-version targets. This gateway solves all of them:

- Two-layer security — MCP restrictions (YAML) + Odoo's built-in ACLs (ir.model.access + ir.rule)
- YAML-driven configuration — model restrictions, RBAC, field-level access, rate limiting, audit logging
- Custom module support — auto-discovers models via ir.model, add YAML config and it works
- Version-agnostic — Odoo 17, 18, 19 with version-specific adapters
- Zero Odoo-side code — pip install + YAML config = done. No custom addon required
- Full MCP primitives — 27 Tools + 5 Resources + 7 Prompts (most servers only implement Tools)
- Plugin architecture — extend with pip-installable domain packs via entry_points

Architecture

MCP Client (Claude Desktop / Claude Code / HTTP)
    |  User calls login tool with Odoo credentials
    v
MCP Server (FastMCP)
    |
    |-- security_gate()    --> Rate limit + RBAC tool access + audit logging
    |-- restrictions       --> Model/method/field block lists (YAML + hardcoded)
    |-- rbac               --> Field-level filtering + write sanitization
    |
    |-- tools/             --> 27 MCP tools (auth + schema + CRUD + plugins)
    |-- resources/         --> 5 MCP resources (odoo:// URIs)
    |-- prompts/           --> 7 reusable prompt templates
    |-- plugins/           --> Entry-point plugin system (HR, Sales, Project, Helpdesk)
    |
    |  JSON-RPC / XML-RPC as authenticated user
    v
Odoo 17/18/19 (security enforced per user via ir.model.access + ir.rule)

Security Pipeline

Every tool and resource call passes through this pipeline:

Request --> Rate Limit --> Authentication Check --> RBAC Tool Access
    --> Model Restriction --> Method Restriction --> Field Validation
    --> Handler Execution --> RBAC Field Filtering --> Audit Log --> Response

Hardcoded safety guardrails that cannot be overridden by YAML:
- 18 always-blocked models (ir.config_parameter, ir.cron, ir.module.module, ir.rule, ir.mail_server, etc.)
- 18 always-blocked methods (sudo, with_user, with_env, _sql, _write, _create, etc.)
- 28 ORM methods blocked in execute_method (prevents bypassing field-level checks)

Quick Start

```bash
pip install odoo-mcp-gateway

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.