odoo-mcp-gateway
Adds team-gateway mode and Microsoft SSO to Odoo MCP, allowing business users to authenticate via OAuth 2.1 and execute tool calls with their own Odoo permissions, ACLs, and audit trails.
README
odoo_mcp_sso — Team-gateway / Microsoft-SSO add-on for odoo-mcp-guard
This folder is a self-contained, extractable package (odoo_mcp_sso) that adds
team-gateway mode (ADR-017) and Microsoft SSO login (ADR-018) on top of the
odoo-mcp-guard core. Business users authenticate in their browser with their
usual Odoo login through an OAuth 2.1 authorization-code + PKCE flow (the
MCP-standard client flow); every tool call then executes against Odoo as that
user — Odoo ACLs, record rules, and multi-company all apply per user, the
policy file restricts on top, and audit lines are nominative.
Design: it consumes the MIT core, UNMODIFIED
The dependency is strictly one-directional: odoo_mcp_sso imports the core; the
core never imports odoo_mcp_sso (enforced by an import-linter contract in the
root pyproject.toml: "Core never imports the SSO package"). The core stays
gateway-unaware — build_server resolves each request through a
RequestContextResolver, and this package supplies a GatewayResolver for
gateway mode while the core's default SingleUserResolver is untouched.
What this package consumes from the core (all public, unmodified):
odoo_mcp_guard.server.context.RequestContextResolver— the per-request seam.GatewayResolver(inodoo_mcp_sso.users) implements it structurally.odoo_mcp_guard.server.identity— the identity contract (UserIdentity,UserSession,CredentialVault). These live in the core, not here, so the core can speak the contract without importing this package.odoo_mcp_ssore-exports them for its own consumers.odoo_mcp_guard.server.unconnected.UnconnectedClient— the fail-closed base-profile placeholder. Lives in the core (depends only onerrors+odoo.api, no gateway logic).odoo_mcp_guard.odoo.session_client.SessionClient— stays in the core by design. It is a genericOdooClientover an Odoo web-session cookie with no gateway import; the core wires it viaodoo.detect.make_session_client, and the SSO package consumes it through that core function (Microsoft SSOodoo_sessionauth method). It is NOT moved into this package.odoo_mcp_guard.config(ProfileConfig,load_profile),odoo_mcp_guard.errors,odoo_mcp_guard.audit, and theodooclient/transport layer.
Package contents
| Module | Role |
|---|---|
odoo_mcp_sso/auth.py |
OAuth 2.1 AS + PKCE, /authorize browser login, /token, RFC 8414/9728 metadata, Microsoft-SSO relay (ADR-018), make_odoo_validator, make_ms_sso, mount_gateway, bearer/vault middleware |
odoo_mcp_sso/users.py |
UserClientPool (per-user client cache), GatewayResolver (the RequestContextResolver impl), GatewaySessionMissingError |
odoo_mcp_sso/vault.py |
InMemoryVault (TTL, never persisted — Rule 1 #7) |
odoo_mcp_sso/types.py |
GatewayConfig (gateway-mode wiring; identity types live in the core) |
How it is wired today (in-tree)
This package is a uv workspace member of the core repo ([tool.uv.workspace] members = ["SSO_MICROSOFT"] in the root pyproject.toml). One
uv sync --all-packages installs both the core and this add-on editable, so a
single uv run python -m pytest from the repo root collects both core and SSO
tests (SSO_MICROSOFT/tests is in testpaths).
The gateway is activated entirely from the core's serve.py on the --gateway
path via function-local imports of odoo_mcp_sso (the only allowed
core→sso edge, whitelisted in the import-linter contract):
# odoo_mcp_guard/server/serve.py (gateway path only)
from odoo_mcp_sso.users import GatewayResolver, UserClientPool
from odoo_mcp_sso.vault import InMemoryVault
from odoo_mcp_sso.auth import GatewayAuthApp, make_ms_sso, make_odoo_validator, mount_gateway
from odoo_mcp_sso.types import GatewayConfig
Extracting this into its own repository later
Because the dependency is one-directional and the core is consumed unmodified, lifting this out is mechanical:
- Move the folder out of the core repo into a new repository
(
SSO_MICROSOFT/→ the new repo root;odoo_mcp_sso/is the package,tests/are its tests). - Replace the workspace dependency with a pinned core release. In the new
repo's
pyproject.toml, drop[tool.uv.sources] odoo-mcp-guard = { workspace = true }and pin a publishedodoo-mcp-guardversion (PyPI release or git tag). Thenpip install odoo-mcp-guard(oruv add). - Wire
servein the new repo. The core'sserve.pykeeps only its two self-host transports (stdio + single-credential bearer HTTP). Move the--gatewayflag and the_build_gateway_app/mount_gatewaywiring into the new repo's own entrypoint, which callsodoo_mcp_guard.server.app.build_server( runtime, resolver=GatewayResolver(...)). SessionClientstays in the core — do not copy it. The new repo reaches it throughodoo_mcp_guard.odoo.detect.make_session_client, exactly as it does in-tree.
Nothing in the core has to change to support the move: the seam, the identity
types, and SessionClient are already in their permanent homes.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。