Administration

API keys

Generate and manage the API keys used to authenticate MCP-compatible IDEs (Cursor, Windsurf) against Aidoo.

6 min readUpdated October 1, 2026

Overview

Aidoo API keys authenticate the MCP requests that reach your Odoo. Each key is tied to a member and a workspace, with granular permissions over allowed operations.

All keys follow the format:

aid_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

The aid_live_ prefix is common to every key. The next 8 characters serve as a visual identifier in the dashboard.

When is it needed? For Claude.ai, ChatGPT, Claude Desktop and Claude Code, you don't handle any key: authentication happens through OAuth (see Connecting with Claude and Connecting with ChatGPT). Aidoo then creates the key for you, with the permissions ticked on the consent screen; it shows up on the API keys page marked "(OAuth)". Generating a key by hand is only needed for IDEs that don't support OAuth (Cursor, Windsurf, etc.).

One active key per member

By default, each member has a single active key per workspace:

  • generating a key for a member who already has one is refused: revoke the old one first;
  • a new OAuth connection (Claude, ChatGPT) replaces the member's active key, including a key pasted into an IDE, which then stops working.

To use an OAuth-connected assistant and a key-based IDE side by side, contact support.

Keys managed automatically by Aidoo (those of agents and of the chat embedded in Odoo) are not affected by an OAuth connection and don't appear in the list.

Create an API key

Generating keys is reserved for workspace owners and admins.

  1. Sign in to the Aidoo dashboard
  2. Go to Team from the side menu
  3. Check that the member has their Odoo token configured: without it, the key icon is greyed out and opens the "Odoo token" window first
  4. Click the key icon (Generate a key) next to the member
  5. Assign a descriptive name (e.g. "Cursor - Accounting")
  6. Select the desired permissions
  7. Click Generate key

Important: the full key is only shown once. Copy it immediately and store it in a secure place. It cannot be retrieved later.

If your workspace has a staging environment configured, tick "Use different permissions in staging" to give it a separate set, for instance writes allowed in staging only. Without that box, staging reuses the production permissions.

Permissions

Every API key has permissions that define which operations are allowed on Odoo. You can configure them precisely depending on the use case.

PermissionLabelDescription
querySearchSearch records (filters, domains)
readReadRead fields of existing records
schemaSchemaInspect model structure (fields, types, relations)
reportReportCompute aggregations and statistics (totals, averages, counts)
printPDF printingGenerate Odoo PDFs (quotations, invoices, delivery slips)
createCreateCreate new records
writeEditUpdate existing records
deleteDeletePermanently delete records, with no way back
executeExecuteTrigger Odoo business buttons (confirm, validate) and call server methods
workflowWorkflowRun the Aidoo workflows saved in the dashboard
attachFilesGenerate single-use upload links to drop files into Odoo
feedbackFeedbackUpdate a model's instructions (hints) when you correct the assistant
documentDocument readingRead PDFs and images attached in Odoo (transcription, signatures, amounts)

Two permissions also depend on another setting:

  • feedback additionally requires the right to update hints on the member's profile, granted by default to owners and admins;
  • document only takes effect if the "Allow AI to read attachments" setting is on in the workspace Settings (on by default). Each read consumes AI credits: 1 credit per batch of 20 pages, charged once per document.

Default permissions: when created from the Team page, query, read, schema and report are pre-ticked. The OAuth consent screen also pre-ticks print. These read-only permissions suit most exploratory use cases. The full tool-to-permission mapping is in the MCP tools reference.

Recommendations by profile

  • Consultation / Reporting: query, read, schema, report, print
  • Day-to-day management: the above, plus create and write
  • End-to-end processing: the above, plus execute
  • Bulk corrections: delete, temporarily, then removed

Limiting members to read access

By default, everyone chooses the permissions of their own connector; Odoo applies the rights of their own account anyway. To go further, turn on Settings → Connector and AI → Read-only members (owners and admins).

Once the option is on, a member can only grant query, read, schema, report, print and document to their connector: write checkboxes are greyed out on the authorization screen and on the Team page, and a write request is refused. When you turn it on, keys already issued to members lose their write permissions. Owners and admins, agents and the chat inside Odoo are not affected. To give write access to one specific member, make them an admin.

Key management

List keys

From the API keys page in the dashboard:

  • Owners and admins see all the company's keys
  • Members only see their own keys

Each key shows: name, member, identification prefix, active permissions, last used date and creation date.

Edit permissions

Owners and admins can change a key's name and permissions without regenerating it: Edit button next to the key, then "Edit permissions". The key stays the same, nothing to reconfigure in the client. Start a new conversation so the assistant picks up the new rights.

Revoke a key

Revocation is immediate and final. A revoked key cannot be reactivated.

  • Owners and admins can revoke any of the company's keys
  • Members can only revoke their own keys
  • Removing a member from the workspace revokes all their keys

To revoke:

  1. Go to API keys
  2. Click Revoke next to the relevant key
  3. Confirm the action in the confirmation modal

Remember to update your IDE's MCP configuration if you replace a revoked key.

Use in an IDE

Once the key is created, configure it in your MCP-compatible IDE (Cursor, Windsurf, etc.) following the full guide: Local clients (IDEs).

Example for Cursor (~/.cursor/mcp.json):

{
  "mcpServers": {
    "aidoo": {
      "url": "https://mcp.aidoo.ai/sse",
      "headers": {
        "Authorization": "Bearer aid_live_your_key_here"
      }
    }
  }
}

Best practices

  • One key per user: don't share a key between several people
  • Minimum permissions: only grant the strictly necessary permissions
  • Regular rotation: revoke and recreate your keys periodically
  • Explicit naming: use descriptive names to quickly identify each key (e.g. "Cursor - Marie - Accounting")
  • Never version a key in a Git repository or a shared file