# Odoo JSON-2 tool boundary — operations agent

Mark **Allow** or **Deny** before you register a Gateway target. The adapter you own calls `POST /json/2/{model}/{method}` with a bearer key for a dedicated integration user. The model supplies field values you already listed. It does not supply the method name.

JSON-2 shipped in Odoo 19.0. XML-RPC and JSON-RPC (`/xmlrpc`, `/xmlrpc/2`, `/jsonrpc`) are scheduled for removal in Odoo 22 (fall 2028) and Odoo Online 21.1 (winter 2027). New work uses JSON-2.

API keys last at most 3 months. The key is shown once. Odoo Online exposes the external API on Custom plans. One App Free and Standard do not. Self-hosted Odoo uses the same route with its own users.

Official MCP at `{database}/mcp` starts on saas-19.4 (release notes, July 2026). Databases below 19.4 return 404 on that path. Default exposed tools are five server actions: Get Fields, Get Models, MCP Retrieve initial context, Search, and Read group. The Readonly Tool checkbox advises the client. It does not deny the call.

| Tool you expose | JSON-2 call | User | Week one | Check |
| --- | --- | --- | --- | --- |
| `search_sale_orders` | `POST /json/2/sale.order/search_read` | Integration user, sales read | Allow | Fixed `fields` list in the adapter: name, state, partner, amount, commitment date. `limit` set by the adapter, not the model. |
| `read_product` | `POST /json/2/product.product/search_read` | Same user, product read | Allow | Search by default code or name you already parsed. Return qty fields you listed. |
| `search_stock_quants` | `POST /json/2/stock.quant/search_read` | Same user, stock read | Allow | Filter to the warehouse you named. Include a quantity and a location. |
| `get_models` / `get_fields` | Official MCP defaults, or JSON-2 `fields_get` if you wrap it | Integration user | Deny on the operations agent | Useful in a developer session. A shop-floor agent does not need the whole schema. |
| `confirm_sale_order` | `sale.order` `action_confirm` | Would need sales manager rights | Deny | Confirming a quotation creates a sales order. A person does that in Odoo. |
| `create_invoice` | `account.move` create, or the sale invoice wizard | Accounting rights | Deny | Money movement. A person posts the invoice. |
| `validate_picking` | `stock.picking` `button_validate` | Stock rights | Deny | Validates a transfer. A person does that on the warehouse screen. |
| `execute` | Any `POST /json/2/{model}/{method}` the prompt names | Whatever the key's user can do | Deny | Delete this tool. The trace will show methods you never listed. |
| `generate_api_key` | `res.users.apikeys` generate | Settings admin by default | Deny | Keys are shown once and last at most 3 months. Rotation is a deploy task. |
| Official `/mcp` server | `{database}/mcp`, MCP-scoped key | The user who minted the key | Deny until write server actions are unticked | Five read-shaped defaults still sit next to any server action you marked Available in MCP. Readonly is advice, not a deny. |

## Credential split

| Secret | Who | Where it lives |
| --- | --- | --- |
| JSON-2 bearer key, scope for RPC | Integration user | AgentCore Identity or Secrets Manager. Rotate before the 3 month cap. |
| MCP-scoped bearer key | A user you would let drive server actions | A different secret, if you use `/mcp` at all. Not the JSON-2 key. |
| Database name header | Adapter, only when one host serves multiple databases | `X-Odoo-Database`. Not a model argument. |

## What the adapter must do on every call

- Send `Authorization: bearer` and `Content-Type: application/json`. Add `X-Odoo-Database` only on multi-database hosts.
- Put `model` and `method` in the URL from the allow-list. Ignore any model or method string in the tool arguments.
- Send `fields` and `limit` from the adapter. A domain may include values the user asked for (order name, product code), bound to the fields you already chose.
- On HTTP 401, stop. The key is invalid or expired. Do not ask the model to generate a new one.
- On success, speak only from the JSON body. An empty list means no rows, not a guess.

## Explicitly not in this worksheet

Odoo Studio customization, website checkout, a measured ticket deflection rate, and a runnable database.
