ERPipe is built by Lê Anh Tuấn (tuanle96): a hosted, governance-first Odoo MCP gateway so AI agents can work on live ERP without a fragile self-hosted bridge.
About ERPipe
- Related open-source work: odoo-mcp on PyPI and the erpipe-org GitHub organization
- Contact: hello@erpipe.com
Who builds ERPipe
ERPipe is built by Lê Anh Tuấn (tuanle96). The work sits at the overlap of Odoo operations and AI agents: live ERP is useful to a model only when identity, policy, and write gates stay visible to a human owner.
The hosted product is published under the erpipe-org GitHub organization. Support and security reports go to hello@erpipe.com.
Why ERPipe exists
Self-hosting an Odoo MCP server is a reasonable weekend project and a poor production default. The hard parts are not listing models. They are OAuth for every client, workspace isolation, encrypted secrets, SSRF boundaries, writes that start off, an approval inbox, and an audit trail that does not dump raw payloads.
ERPipe is the hosted control plane for that gap. ChatGPT, Claude Code, Codex, Gemini, Grok, and other MCP clients get one workspace endpoint. Odoo stays the system of record. Owners keep Pause, revoke, and least-privilege service users.
Relationship to open-source odoo-mcp
The open-source odoo-mcp package on PyPI and its mcp-odoo source are the Python self-hosted lineage many operators tried first. ERPipe is the hosted Odoo MCP gateway from the maintainer of odoo-mcp. The erpipe repository is the TypeScript self-host core. The erpipe-mcp repository contains optional companion Odoo addons; it is not a server inside Odoo.
The hosted product is the multi-tenant evolution of that work: same job (governed live Odoo for agents), plus tenancy, OAuth S256 PKCE, human approval, and a public HTTPS MCP URL at https://mcp.erpipe.com/mcp.
ERPipe is not affiliated with Odoo S.A.
Governance-first
- Writes are off by default.
- Odoo ACLs and record rules remain authoritative.
- Field policy and method allowlists can narrow the surface further.
- Uncertain writes are marked unknown and are not retried blindly.
- Credentials are encrypted and never returned to the agent.
That stance is the product, not a slogan. If you need a firehose from ERP into a chat window, this is the wrong tool.
Evidence you can inspect
- Python self-host source and TypeScript self-host core.
- Dated hosted tool catalog with the named runtime surface.
- Compatibility matrix and smoke-test method.
- Security and write-approval documentation and the public changelog.
Contact
Last updated: 2026-08-26