SETUP GUIDE · OFFICIAL SOURCES

Odoo behind Cloudflare Access

Connect ERPipe to an Odoo hostname protected by Cloudflare Access using a service token, a Service Auth policy and your separate Odoo credential.

Published: September 18, 2026 · Last updated: September 29, 2026 · Review by: December 18, 2026

By Lê Anh Tuấn · Founder of ERPipe

Answer first

Use a Cloudflare Access service token to let ERPipe reach a protected Odoo hostname. Keep the Odoo credential separate: the service token admits the request through Access, then Odoo authenticates its own user. A browser login working does not prove that an API client can connect.

This walkthrough applies to ERPipe builds that show Cloudflare Access on a connection's Configure page. If the card is absent, check the release available to your workspace before proceeding. Do not remove protection to compensate for a missing setting. For field definitions and automation contracts, use the Cloudflare Access reference.

Before you start

Have an ERPipe workspace owner available, a dedicated Odoo service user and the Odoo database name. Use an API key for Odoo 19 JSON-2. Odoo's official JSON-2 reference describes bearer authentication and the per-model HTTP endpoint; ERPipe handles those requests after configuration.

You also need authority to configure the Cloudflare Access application protecting your Odoo hostname. Use a test instance for the first check. Hosted ERPipe requires a publicly resolvable HTTPS hostname; a localhost address or a private-network-only name is insufficient, even when a service token exists. Review the Odoo compatibility matrix for your deployment.

1. Check the protected Odoo hostname

Use the base URL, such as https://odoo.example.com, without a login path or credentials in the URL. Configure an Access application for that exact hostname. Cloudflare's public application instructions describe adding a public hostname under a self-hosted application.

Cloudflare Tunnel is optional. When used, it connects Cloudflare to your origin; Access supplies the authentication policy. Configure Access before publishing a new origin route. In the Tunnel setup, the route's service address must be reachable from the connector. For Docker deployments, an Odoo service name works only when the connector can reach that Docker network. A tunnel token belongs to the connector, never to ERPipe's Client Secret field.

Check policies for all paths ERPipe uses: /json/2/, /web/webclient/version_info and, for XML-RPC, /xmlrpc/2/. A rule covering only /web is insufficient. Cloudflare applies more-specific application paths independently; review application-path precedence when one probe works and another redirects.

2. Create the service token

In Cloudflare Zero Trust, open Access controls → Service credentials → Service Tokens. Create a token named for the integration, choose its duration and save the full Client ID and Client Secret in your secret manager. The secret is displayed at creation; do not send it in email or chat. Follow the current service-token instructions if dashboard labels differ.

3. Add the Service Auth policy

On the Access application protecting Odoo, add a policy with action Service Auth. Use an Include rule whose selector is Service Token, and select the token you just created. Save the policy on the correct application. Keep any required human sign-in policy separately.

Cloudflare distinguishes Service Auth from an identity-provider-based Allow policy and from Bypass. Bypass removes Access enforcement for matching traffic; it is unnecessary for this integration. See the official policy actions. Test the effective policy rather than assuming that creating a token alone authorizes it.

4. Configure the ERPipe connection

For a new connection, open Connections, start a new connection, and enter the Odoo URL, database and service-user credential. At the Odoo access step, expand Odoo is behind Cloudflare Access. Paste the complete Client ID and Client Secret. Finish the existing five-step wizard; the review displays only that a token was supplied.

For an existing connection, open its Configure page and locate Cloudflare Access below Connection identity. Enter both values and select Set service token or Replace service token. ERPipe checks the pair with the Odoo credential already saved on that connection. A failed check leaves the previous token unchanged; successful saving clears the input fields.

The Cloudflare fields do not replace the Odoo password/API key field. ERPipe keeps saved values out of connection responses and sends the two dedicated Access headers on Odoo requests. Configuring Access does not resume a paused connection or enable Odoo writes.

5. Verify an actual Odoo read

After saving, connect your MCP client using the connector guide and choose the explicit instance key returned by list_instances. Keep Odoo writes off while validating. Ask the agent for a small, known record set and compare it with Odoo.

This example is a read request with no credentials:

{
  "name": "search_records",
  "arguments": {
    "instance": "your-instance-key",
    "model": "res.partner",
    "domain": [["id", ">", 0]],
    "fields": ["id"],
    "limit": 1
  }
}

A returned record verifies that this request traversed the connection and reached Odoo. An empty result needs comparison with the test user's permissions and records. Merely listing tools or running health_check does not establish that Odoo data was read. Do not broaden permissions just to make a test return a record; select a known record the service user is allowed to read.

Troubleshoot 302 redirects and 403 errors

SymptomWhat to check next
Redirect to Cloudflare Access loginCorrect hostname, both token fields, selected service token and the Service Auth action. ERPipe does not follow browser-login redirects.
HTTP 403Token expiry/revocation, effective Access rules and other proxy controls, then Odoo permissions. A 403 alone does not identify which layer denied the request.
One API call works but version verification failsThe policy also needs to cover /web/webclient/version_info; check more-specific path rules.
Odoo authentication fails after Access admits the requestOdoo API key/password, username, database, transport and user permissions. Changing the Access secret will not repair an invalid Odoo credential.
URL validation or DNS failureUse the actual public HTTPS hostname, not localhost or the Docker service name. Check DNS and origin/Tunnel connectivity.
Access settings return a workspace permission errorAsk the ERPipe workspace owner to configure the pair. MCP configuration also needs write scope.

Use the reference error table for ERPipe's response codes. Share only the error category and safe connection details when asking for help. Exclude token values, request headers, cookies and raw network captures.

Replace or remove the token

For a planned rotation, prepare a replacement token and policy authorization, save its pair in ERPipe, and verify a bounded read before revoking the previous token. Use Replace service token, not Clear, while Odoo remains protected. The connection uses the replacement on subsequent runtime resolution.

If the Odoo password/API key also changed or expired, expand Odoo credential also changed? in the Cloudflare Access card. Enter the new Odoo credential along with the new Client ID and Client Secret, then replace the token. ERPipe verifies both together and saves them on the same connection. Leave the optional Odoo field blank when its stored credential still works. If verification fails, both previous credentials stay saved.

Clear service token verifies that the saved Odoo connection can authenticate without Access headers. If Access still requires them, ERPipe rejects the clear and keeps the token. Remove a token only when you intend the connection to operate without it and have deliberately configured the surrounding access policy. See replacement and removal behavior.

Sources and next steps

Cloudflare and Odoo sources above were reviewed on September 18, 2026. The setup instructions describe the documented configuration and ERPipe's implemented behavior; they do not imply that your hostname or policy has already been tested. Verify your own protected path before relying on it.

Continue with the operator and API reference, MCP tool catalog, connector setup and ERPipe security boundaries. Cloudflare Access admission and the connected Odoo user's permissions remain separate controls.