MCP gateway for Odoo

Let your AI assistant work in Odoo — on your terms.

Cravit Gateway connects Claude, ChatGPT, Microsoft Copilot and AWS assistants to your Odoo ERP through the Model Context Protocol. Every request is authenticated per person, checked against a role you define, and written to an audit trail.

AI assistantClaude · ChatGPT · Microsoft Copilot · AWS Bedrock / Amazon Q
Cravit GatewayIdentity · role check · limits · confirmation · injection scan · audit
Your OdooOdoo 14 and later · Enterprise or Community · runs as the user's own Odoo account
What it does

One controlled doorway between AI and your ERP

Instead of handing an assistant a master API key, each colleague gets a personal gateway key. The gateway decides what that person's assistant may see and change, then talks to Odoo on their behalf.

Search and read

Ask in plain language about customers, orders, invoices, stock, projects or any other Odoo model — including your custom ones. Large result sets are paginated with a per-tenant page size.

Create and update

Let the assistant draft quotations, log leads or update tasks — only for people granted write access, within the per-request limits you set, and with confirmation for bulk changes.

Works with any model

Four generic tools — search, read, create, update — cover standard apps, Studio fields and custom modules alike. No per-app connector to wait for.

Admin panel per customer

Your own subdomain, e.g. yourcompany.cravitgateway.com. Add users, choose Read or Read + Write, assign roles, revoke or reactivate access, and review activity.

Roles you define

Allow-list roles state exactly which models a group of users can reach, and how many records one request may create or update. Anything not listed is denied.

Managed by Cravit

Hosted on Google Cloud and operated by an Odoo Gold Partner. We onboard your tenant, connect your Odoo and help roll out your assistant of choice.

How it works

From question to Odoo record in four steps

Sign in

Each person connects their assistant with a personal gateway key, or via OAuth for the Claude web connector.

Link Odoo

They enrol their own Odoo API key once. It is stored encrypted and used only for their requests.

Checked

Each tool call passes the control plane: scope, role, record limits, confirmation and rate limit — before Odoo is touched.

Logged

The call runs under that user's Odoo access rights and the outcome is written to the audit trail.

Security

Built so that the gateway is the safest way in

An assistant should never have more power than the person using it. These controls apply to every request, on every supported Odoo version and edition.

Per-person identity

No shared service account. Every colleague has an individual gateway key, stored only as a salted hash, with a Read or Read + Write scope.

Your Odoo rights still apply

Requests run with the user's own Odoo API key, so Odoo's access rights and record rules are enforced as usual. The gateway can only narrow access, never widen it.

Default-deny roles

Access profiles are allow-lists. A model that is not listed is refused, and a user without a valid profile gets nothing — the gateway fails closed.

Write limits and confirmation

Caps on records created or updated per request, and an explicit confirmation step before bulk writes go through.

Prompt-injection guardrails

Data coming back from Odoo is scanned and tagged as external content, so text inside a record is not mistaken for an instruction.

Append-only audit trail

Who, which assistant, which model, which action and the result — recorded for every call and viewable per tenant.

Encrypted credential vault

Odoo credentials are kept in Google Secret Manager, one secret per user, with optional customer-managed encryption keys. They are never shown again after enrolment.

Network and rate controls

Admin panel sign-in can be restricted to your office IP ranges. Rate limiting and a maximum session age contain runaway or abandoned sessions.

Instant off-switch

Revoke a single user or deactivate a whole tenant in one click. Deactivated accounts are refused at both key and OAuth sign-in immediately.

Versions and editions

Works with the Odoo you run today

Cravit Gateway supports Odoo from version 14 onwards, on both Enterprise and Community, wherever your database is hosted.

Odoo 14Odoo 15Odoo 16Odoo 17Odoo 18Odoo 19 EnterpriseOdoo Online* · Odoo.sh · on-premise Communityself-hosted

Every supported version

The gateway speaks Odoo's standard external API, so the same roles, limits and audit trail apply whichever version you are on. Nothing has to be installed inside your Odoo database — only an API key per user.

Community edition

Standard Community models work out of the box, including OCA and custom modules. Self-hosted instances can allow-list our outbound address in their firewall.

* Odoo Online requires a plan that includes external API access.

FAQ

Common questions

What is MCP?

The Model Context Protocol is an open standard that lets AI assistants call external tools in a structured way. Cravit Gateway is an MCP server: the assistant asks it to search or update Odoo, and the gateway decides whether that is allowed.

Does the AI get my Odoo password or API key?

No. The assistant only holds a gateway key. Your Odoo API key stays in the encrypted vault and is used by the gateway for your requests only.

Can the assistant see more than I can in Odoo?

No. Calls run under your own Odoo user, so access rights and record rules apply. Your gateway role can restrict this further.

Which Odoo versions and editions are supported?

Odoo 14 and later, on both Enterprise and Community — on Odoo Online, Odoo.sh or your own servers.

Do we have to install a module in Odoo?

No. The gateway uses Odoo's standard external API. Each user only creates an API key in their Odoo preferences.

Which assistants are supported?

Claude, ChatGPT, Microsoft Copilot (Microsoft 365) and AWS assistants such as Amazon Bedrock and Amazon Q. Any MCP-compatible client can connect. Step-by-step instructions are in the documentation.

How do we get started?

Cravit onboards each customer: we create your tenant and subdomain, connect your Odoo and set up your first admins. Contact us through cravit.nl.