I run autonomous AI agents against live Odoo databases daily: data reconciliation, scheduled reporting, migration verification. This is the pattern that keeps it safe.
The connection
Odoo 19 speaks XML-RPC and JSON-RPC. Generate an API key per user (Preferences → API Keys), then authenticate with username plus key instead of password. The agent stores the key, not the password, and revocation is one click.
import xmlrpc.client
url = "https://odoo.example.com"
db = "production"
username = "agent@company.com"
key = "API_KEY"
common = xmlrpc.client.ServerProxy(f"{url}/xmlrpc/2/common")
uid = common.authenticate(db, username, key, {})
models = xmlrpc.client.ServerProxy(f"{url}/xmlrpc/2/object")
models.execute_kw(db, uid, key, "res.partner", "search_count",
[[["customer_rank", ">", 0]]])
JSON-RPC works the same way with the /json/1 endpoint and the API key in the password field. I use XML-RPC for scripts (stdlib only, no dependencies) and JSON-RPC when the agent already speaks HTTP.
Write discipline
Agents get read access by default and write access per task. The rules that keep live databases alive:
- Verify with a read after every write. A write that “succeeded” and a write that worked are different events.
- Never write stock quantities through
stock.quant.inventory_quantity; it’s not RPC-writable. Stock goes through moves and move lines. stock.moveisn’t directly writable either. Createstock.move.linerecords with thequantityfield (Odoo 19 renamedqty_done).- One operation at a time, verified, then the next. Agents that batch fifty writes before checking the first are how you spend an afternoon restoring.
What agents are genuinely good at here
- Reconciliation: reading 700k legacy stock records and flagging the ~25% that are duplicates.
- Verification: after a migration step, re-reading every count and comparing against source.
- Scheduled reports: reading the same five models each morning and posting a summary where the team actually looks.
- Drafting: filling in vendor bills from PO data for a human to confirm. 3-way match checks happen at validation.
What they should not touch
Confirmed documents, anything with legal standing (invoices, payments), and deletions. Agents draft; humans validate. That single rule has kept every database I manage intact.