MCP Server for AIMCP Server for AI

Live on the Odoo App Store

MCP Server for Odoo

Let an AI assistant query your Odoo, safely. Connecting an AI assistant to the database that runs your business is a reasonable thing to want and an unreasonable thing to do carelessly.

  • Odoo 16, 17, 18 and 19. Community or Enterprise, on Odoo.sh or self-hosted.
  • Free and open source (LGPL-3), a free download on the Odoo App Store.
MCP Server for Odoo by Tripster Developers

Features

Nothing is readable until you allow it

This connects Claude, ChatGPT, Copilot or any Model Context Protocol client to an Odoo database, and is built to be approved rather than merely installed.

The default posture is that nothing is available. You open up exactly what you intend to, one model at a time, and everything the assistant asks is written down.

No model is readable by default

You add each one deliberately. An allowlist rather than a blocklist, so a new model in a future Odoo version is never exposed by accident.

Read only

The assistant can list the allowed models, describe their fields, search records and count them. There is no tool that creates or changes a record, and the writing switch on each model and key is off by default.

Named fields can be redacted

So salaries and bank details never leave the database. Passwords, tokens, keys and signatures are always stripped, whatever a model's configuration says.

Every question the assistant asks is written to an audit log

With the key that asked it, the user it acted as, the rows returned and the time taken, in its own transaction so a refused call is still recorded.

Odoo's own access rules still apply

Every call runs as the Odoo user the key acts for, so record rules and access rights are enforced underneath. The allowlist can only narrow what that user could already reach.

Limits you set per model

Restrict a model to an Odoo domain the assistant can never see past, such as this year's records or one company, and cap the rows returned per call.

How it works

How it works

  1. 01

    Install it

    Add the module to Odoo.sh or your own server and install it from the Apps menu. It needs nothing but Odoo itself, and nothing is exposed yet.

  2. 02

    Allow models and create a key

    Under MCP Server, add the models you want readable, one at a time, with any redacted fields and limits. Then create a key that acts as a specific Odoo user. It is shown once and stored only as a hash.

  3. 03

    Point your assistant at /mcp

    Give your MCP client the address and the key, ask your question in plain language, and watch the Audit Log as it works.

Technical Edge

Why an allowlist rather than a permission model

Odoo's own access rules are written for people, who ask for one record at a time and stop when they have it. An assistant will happily read everything it is permitted to read. An allowlist is the only posture where the blast radius of a mistake is something you chose in advance.

Technical Stack

Checked in the module code and the live Odoo App Store listing, September 2026

Odoo versions
16.0, 17.0, 18.0, 19.0A separate build for each series, each certified against a real Odoo image of that series before it is listed.
Editions
Community and EnterpriseOn Odoo.sh or self-hosted. Not Odoo Online, which cannot run third-party modules that contain Python.
Depends on
Base onlyNo other Odoo app is required.
Protocol
Model Context Protocol, JSON-RPC 2.0Over HTTP POST at /mcp on your own Odoo, authenticated with a key sent as a bearer token.
Tools
Four, all read onlyList models, describe a model's fields, search records and count records.
Adds
An MCP Server menuAllowed Models, Keys and Audit Log, plus a "Manage the MCP server" permission kept separate from general administration.
Keys
Hashed, shown onceEach key acts as one Odoo user, can carry an expiry date, and records when it was last used.
Scheduled actions
NoneIt only answers when an assistant asks.
Reads and writes
Reads only the models you allowWrites nothing to your business records. Its own writes are its keys, its allowlist and the audit log.

Pricing

Free, and open source.

Published on the Odoo App Store under LGPL-3, so your own developer can read every line before it goes near your data.

MCP Server for AI

Free

LGPL-3 · Odoo 16.0 to 19.0

  • Allowlist of readable models, nothing by default
  • Field redaction and per-model limits
  • Hashed keys that act as one Odoo user
  • Audit log of every question asked
  • Email support from the people who wrote it
View on the Odoo App Store ↗

Custom work

On quote

Scoped with you before any work starts

  • Changes to fit how your AI access is run
  • Built by the team that wrote the module
  • Separate from module support
Talk to us

Built For

Who this is for

Teams who want to ask their own database questions in plain language: what did this customer order, which quotations are stale, what is the exposure on that supplier. The value is in the asking being cheap, which is exactly why the boundary has to be set deliberately rather than inherited.

  • The people who have said no. It is also for anyone whose answer to "can we connect AI to Odoo" has so far been no, on the entirely reasonable grounds that nobody could say what it would be able to read.
  • Whoever signs it off. The allowlist, the redacted fields and the audit log are the answers an approver asks for, written down in Odoo rather than promised.

FAQ

Questions

What can the assistant see by default?

Nothing. No model is readable until you add it, and even then only what the Odoo user behind the key could already see. The server is read only: its four tools list, describe, search and count records, and none of them creates or changes one.

Can I stop it reading sensitive fields?

Yes. Named fields can be redacted, so salaries and bank details never leave the database even on a model you have allowed. Passwords, tokens, keys and signatures are always stripped, whatever the configuration says.

Is there a record of what was asked?

Yes. Every question is written to an audit log along with the key that asked it, the user it acted as, how many rows came back and how long it took. The entry is written in its own transaction, so a refused call is still recorded.

Which Odoo versions are supported?

Odoo 16, 17, 18 and 19. Every listed Odoo version is certified on each release by installing the module into a real Odoo image of that series and running the full test suite. A version is only listed once it passes.

Does it work on Odoo Online?

Odoo Online cannot run third-party modules that contain Python, which is Odoo's rule rather than ours. Odoo.sh and self-hosted installs are both fine.

How do I get help?

Email hello@tripsterdevelopers.com with your Odoo version, the module version and what you did. If a call failed, its entry in the audit log holds exactly what was asked and the error, which answers most questions immediately.

Does it work on Community as well as Enterprise?

Yes. Odoo 16, 17, 18 or 19, Community or Enterprise. The same build installs on either edition.

How do I install it?

Download the module from its Odoo Apps Store page, place the folder in your addons path, restart Odoo, then update the apps list and install it from the Apps menu. Odoo.sh users add it to the repository branch instead.

Will it survive an Odoo upgrade?

Each listed Odoo version has its own build. When you move to a new major version, install the build for that version; the configuration you have already entered is read by the new build.

Where is my data processed?

Inside your own Odoo instance. The module runs on your server and answers the assistant you point at it. We do not host your records and we do not receive a copy of them. What the assistant does with an answer is governed by that assistant's provider, which is exactly why the allowlist and redaction exist.

Can I read and adapt the source?

Yes. Odoo modules are distributed as readable Python and XML, so your own developer can review exactly what runs and extend it under the license the module ships with (LGPL-3).

What should I send when something is wrong?

Your Odoo version, the module version from the Apps screen, and the matching entry from the audit log. Those three together are usually enough to answer in one reply rather than four.

Do you take feature requests?

Yes, at the same support address. Say what you are trying to achieve rather than the field you want added; it is often already possible, and when it is not, the underlying goal is what shapes the change.

Is there a public changelog?

Not as a separate page. The current version for each Odoo series is shown on the module's Odoo Apps Store page and on the Apps screen in your own database; ask the support address what changed between two versions and you will get a straight answer.

Who builds and maintains these modules?

Tripster Developers, a Shopify Partner and Odoo module publisher based in Auckland, New Zealand. The same team writes the code and answers the support mail.

Miko Apps

Let AI read your Odoo, on your terms.

Free and open source (LGPL-3), published by Tripster Developers

Miko for Odoo

Other Miko apps for Odoo

Published and maintained by Tripster Developers on the Odoo App Store. See all Odoo apps.

Not on Shopify yet?

Start a free Shopify trial, then add Miko apps when you are ready.

Set up your store in minutes and try it with your own products. Loyalty, wholesale pricing, AI descriptions and the rest of the Miko apps install in one click once your store is live.