openapi: 3.1.0
info:
title: Odoo External Common Object API
description: 'Odoo''s external API exposes business data and methods via XML-RPC (and
JSON-RPC) endpoints. The common endpoint accepts unauthenticated calls
used for version information and authentication; the object endpoint
accepts authenticated `execute_kw` calls that operate on Odoo models
(search, search_count, read, search_read, fields_get, create, write,
unlink). Authentication is performed by calling `authenticate` on the
common endpoint with database, username, and password or API key
(Odoo 14+). This OpenAPI describes the HTTP transport surface; the
XML-RPC request bodies follow the standard XML-RPC envelope.
'
version: '17.0'
contact:
name: Odoo
url: https://www.odoo.com/documentation/17.0/developer/reference/external_api.html
servers:
- url: https://{instance}.odoo.com
description: Odoo Online or self-hosted instance
variables:
instance:
default: mycompany
description: Odoo instance / database hostname prefix
security: []
tags:
- name: Object
description: Authenticated XML-RPC endpoint for model operations
paths:
/xmlrpc/2/object:
post:
tags:
- Object
summary: XML-RPC object endpoint (execute_kw on Odoo models)
description: 'Accepts authenticated XML-RPC `execute_kw` calls with positional
arguments (db, uid, password/api-key, model, method, args, kwargs).
Supported model methods include `search`, `search_count`, `read`,
`search_read`, `fields_get`, `create`, `write`, and `unlink`.
'
requestBody:
required: true
content:
application/xml:
schema:
type: string
description: XML-RPC methodCall envelope wrapping execute_kw
responses:
'200':
description: XML-RPC methodResponse (record IDs, data, or fault)
content:
application/xml:
schema:
type: string
components:
securitySchemes:
OdooApiKey:
type: apiKey
in: header
name: X-API-Key
description: 'Odoo 14+ supports per-user API keys generated under user preferences
Account Security. These can be substituted for the password parameter
in `authenticate` and `execute_kw` calls.
'