openapi: 3.1.0
info:
title: Odoo External Common API
description: 'Odoo''s external API exposes business data and methods via XML-RPC (and
JSON-RPC) endpoints. The common endpoint accepts unauthenticated calls
used for version information and authentication; the object endpoint
accepts authenticated `execute_kw` calls that operate on Odoo models
(search, search_count, read, search_read, fields_get, create, write,
unlink). Authentication is performed by calling `authenticate` on the
common endpoint with database, username, and password or API key
(Odoo 14+). This OpenAPI describes the HTTP transport surface; the
XML-RPC request bodies follow the standard XML-RPC envelope.
'
version: '17.0'
contact:
name: Odoo
url: https://www.odoo.com/documentation/17.0/developer/reference/external_api.html
servers:
- url: https://{instance}.odoo.com
description: Odoo Online or self-hosted instance
variables:
instance:
default: mycompany
description: Odoo instance / database hostname prefix
security: []
tags:
- name: Common
description: Unauthenticated XML-RPC endpoint for version + authentication
paths:
/xmlrpc/2/common:
post:
tags:
- Common
summary: XML-RPC common endpoint (version, authenticate)
description: 'Accepts unauthenticated XML-RPC method calls. Used to retrieve
server metadata via `version()` and to authenticate via
`authenticate(db, login, password, {})` which returns the user
identifier (uid) needed for subsequent calls.
'
requestBody:
required: true
content:
application/xml:
schema:
type: string
description: XML-RPC methodCall envelope (e.g. version or authenticate)
responses:
'200':
description: XML-RPC methodResponse
content:
application/xml:
schema:
type: string
components:
securitySchemes:
OdooApiKey:
type: apiKey
in: header
name: X-API-Key
description: 'Odoo 14+ supports per-user API keys generated under user preferences
Account Security. These can be substituted for the password parameter
in `authenticate` and `execute_kw` calls.
'