API keys
Generate and manage the API keys used to authenticate MCP-compatible IDEs (Cursor, Windsurf) against Aidoo.
6 min readUpdated October 1, 2026
Overview
Aidoo API keys authenticate the MCP requests that reach your Odoo. Each key is tied to a member and a workspace, with granular permissions over allowed operations.
All keys follow the format:
aid_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxThe aid_live_ prefix is common to every key. The next 8 characters serve as a visual identifier in the dashboard.
When is it needed? For Claude.ai, ChatGPT, Claude Desktop and Claude Code, you don't handle any key: authentication happens through OAuth (see Connecting with Claude and Connecting with ChatGPT). Aidoo then creates the key for you, with the permissions ticked on the consent screen; it shows up on the API keys page marked "(OAuth)". Generating a key by hand is only needed for IDEs that don't support OAuth (Cursor, Windsurf, etc.).
One active key per member
By default, each member has a single active key per workspace:
- generating a key for a member who already has one is refused: revoke the old one first;
- a new OAuth connection (Claude, ChatGPT) replaces the member's active key, including a key pasted into an IDE, which then stops working.
To use an OAuth-connected assistant and a key-based IDE side by side, contact support.
Keys managed automatically by Aidoo (those of agents and of the chat embedded in Odoo) are not affected by an OAuth connection and don't appear in the list.
Create an API key
Generating keys is reserved for workspace owners and admins.
- Sign in to the Aidoo dashboard
- Go to Team from the side menu
- Check that the member has their Odoo token configured: without it, the key icon is greyed out and opens the "Odoo token" window first
- Click the key icon (Generate a key) next to the member
- Assign a descriptive name (e.g. "Cursor - Accounting")
- Select the desired permissions
- Click Generate key
Important: the full key is only shown once. Copy it immediately and store it in a secure place. It cannot be retrieved later.
If your workspace has a staging environment configured, tick "Use different permissions in staging" to give it a separate set, for instance writes allowed in staging only. Without that box, staging reuses the production permissions.
Permissions
Every API key has permissions that define which operations are allowed on Odoo. You can configure them precisely depending on the use case.
| Permission | Label | Description |
|---|---|---|
query | Search | Search records (filters, domains) |
read | Read | Read fields of existing records |
schema | Schema | Inspect model structure (fields, types, relations) |
report | Report | Compute aggregations and statistics (totals, averages, counts) |
print | PDF printing | Generate Odoo PDFs (quotations, invoices, delivery slips) |
create | Create | Create new records |
write | Edit | Update existing records |
delete | Delete | Permanently delete records, with no way back |
execute | Execute | Trigger Odoo business buttons (confirm, validate) and call server methods |
workflow | Workflow | Run the Aidoo workflows saved in the dashboard |
attach | Files | Generate single-use upload links to drop files into Odoo |
feedback | Feedback | Update a model's instructions (hints) when you correct the assistant |
document | Document reading | Read PDFs and images attached in Odoo (transcription, signatures, amounts) |
Two permissions also depend on another setting:
feedbackadditionally requires the right to update hints on the member's profile, granted by default to owners and admins;documentonly takes effect if the "Allow AI to read attachments" setting is on in the workspace Settings (on by default). Each read consumes AI credits: 1 credit per batch of 20 pages, charged once per document.
Default permissions: when created from the Team page, query, read, schema and report are pre-ticked. The OAuth consent screen also pre-ticks print. These read-only permissions suit most exploratory use cases. The full tool-to-permission mapping is in the MCP tools reference.
Recommendations by profile
- Consultation / Reporting:
query,read,schema,report,print - Day-to-day management: the above, plus
createandwrite - End-to-end processing: the above, plus
execute - Bulk corrections:
delete, temporarily, then removed
Limiting members to read access
By default, everyone chooses the permissions of their own connector; Odoo applies the rights of their own account anyway. To go further, turn on Settings → Connector and AI → Read-only members (owners and admins).
Once the option is on, a member can only grant query, read, schema, report, print and document to their connector: write checkboxes are greyed out on the authorization screen and on the Team page, and a write request is refused. When you turn it on, keys already issued to members lose their write permissions. Owners and admins, agents and the chat inside Odoo are not affected. To give write access to one specific member, make them an admin.
Key management
List keys
From the API keys page in the dashboard:
- Owners and admins see all the company's keys
- Members only see their own keys
Each key shows: name, member, identification prefix, active permissions, last used date and creation date.
Edit permissions
Owners and admins can change a key's name and permissions without regenerating it: Edit button next to the key, then "Edit permissions". The key stays the same, nothing to reconfigure in the client. Start a new conversation so the assistant picks up the new rights.
Revoke a key
Revocation is immediate and final. A revoked key cannot be reactivated.
- Owners and admins can revoke any of the company's keys
- Members can only revoke their own keys
- Removing a member from the workspace revokes all their keys
To revoke:
- Go to API keys
- Click Revoke next to the relevant key
- Confirm the action in the confirmation modal
Remember to update your IDE's MCP configuration if you replace a revoked key.
Use in an IDE
Once the key is created, configure it in your MCP-compatible IDE (Cursor, Windsurf, etc.) following the full guide: Local clients (IDEs).
Example for Cursor (~/.cursor/mcp.json):
{
"mcpServers": {
"aidoo": {
"url": "https://mcp.aidoo.ai/sse",
"headers": {
"Authorization": "Bearer aid_live_your_key_here"
}
}
}
}Best practices
- One key per user: don't share a key between several people
- Minimum permissions: only grant the strictly necessary permissions
- Regular rotation: revoke and recreate your keys periodically
- Explicit naming: use descriptive names to quickly identify each key (e.g. "Cursor - Marie - Accounting")
- Never version a key in a Git repository or a shared file