I run autonomous AI agents against live Odoo databases daily: data reconciliation, scheduled reporting, migration verification. This is the pattern that keeps it safe.

The connection

Odoo 19 speaks XML-RPC and JSON-RPC. Generate an API key per user (Preferences → API Keys), then authenticate with username plus key instead of password. The agent stores the key, not the password, and revocation is one click.

import xmlrpc.client

url = "https://odoo.example.com"
db = "production"
username = "agent@company.com"
key = "API_KEY"

common = xmlrpc.client.ServerProxy(f"{url}/xmlrpc/2/common")
uid = common.authenticate(db, username, key, {})
models = xmlrpc.client.ServerProxy(f"{url}/xmlrpc/2/object")

models.execute_kw(db, uid, key, "res.partner", "search_count",
                  [[["customer_rank", ">", 0]]])

JSON-RPC works the same way with the /json/1 endpoint and the API key in the password field. I use XML-RPC for scripts (stdlib only, no dependencies) and JSON-RPC when the agent already speaks HTTP.

Write discipline

Agents get read access by default and write access per task. The rules that keep live databases alive:

  • Verify with a read after every write. A write that “succeeded” and a write that worked are different events.
  • Never write stock quantities through stock.quant.inventory_quantity; it’s not RPC-writable. Stock goes through moves and move lines.
  • stock.move isn’t directly writable either. Create stock.move.line records with the quantity field (Odoo 19 renamed qty_done).
  • One operation at a time, verified, then the next. Agents that batch fifty writes before checking the first are how you spend an afternoon restoring.

What agents are genuinely good at here

  • Reconciliation: reading 700k legacy stock records and flagging the ~25% that are duplicates.
  • Verification: after a migration step, re-reading every count and comparing against source.
  • Scheduled reports: reading the same five models each morning and posting a summary where the team actually looks.
  • Drafting: filling in vendor bills from PO data for a human to confirm. 3-way match checks happen at validation.

What they should not touch

Confirmed documents, anything with legal standing (invoices, payments), and deletions. Agents draft; humans validate. That single rule has kept every database I manage intact.