Odoo rarely works alone. It exchanges data with web shops, mobile apps, payment gateways and logistics platforms through Odoo’s external API, REST endpoints and webhooks. Each connection saves time, and each one is also a new entry point that attackers can probe.
This article covers the integration risks we see most often and how to close them. This article is part of our Odoo security series.
Key takeaways
- Give each integration its own user with minimal rights and its own API key — never an administrator login.
- Every custom
@http.routeneeds explicit authentication and input validation. - Verify incoming webhooks with an HMAC signature and timestamp.
- Rotate keys on a schedule and immediately when someone leaves.
Integration risks
- Unauthenticated endpoints. Custom controllers that accept data changes without checking a token or session.
- Unverified webhooks. Payloads accepted without checking a signature or timestamp, so anyone can forge or replay them.
- Shared admin credentials. An administrator’s login hardcoded in a storefront, script or config file.
- Over-sharing portals. Portal pages and controllers that return records without checking they belong to the logged-in customer.
Best practices
- Use dedicated integration users. Create one user per integration with only the access rights it needs, and authenticate with an API key instead of a password.
- Authenticate every custom route. Declare
authexplicitly; for public webhook endpoints, validate a shared secret or signature in the controller before touching any data. - Verify HMAC signatures. Compute the HMAC of the raw body with the shared secret, compare it in constant time, and reject requests with old timestamps to stop replays.
- Validate input. Check types, required fields and allowed values; never pass incoming data straight into
write()or a domain. - Rotate and revoke. Rotate API keys and webhook secrets regularly, and revoke them when a partner or employee leaves.
- Log and limit. Log integration calls and rate-limit public endpoints at the reverse proxy.
For the integration design itself, see our complete Odoo API integration guide and payment gateway integration. Custom endpoints follow the same rules as any custom module.
How Mediod can help
Mediod’s Odoo integration team designs, builds and audits integration layers — scoped users, signed webhooks, retry handling and logging — so data syncs stay fast and access stays controlled.
More from our Odoo security series
- Access Rights and Record Rules: Protecting Multi-Company Odoo Data
- The AI Coding Boom: Reducing Vulnerabilities in AI-Generated Odoo Code
- Custom Modules and Security Debt: Writing Safe Odoo Apps from Scratch
- Hardening a Dedicated Odoo Server (VPS or On-Premise): An Infrastructure Blueprint
- Odoo.sh Security: What’s Handled for You and What You Still Need to Protect
See all Odoo Security articles →
Want a second pair of eyes on your Odoo security?
Mediod Consulting is an Official Odoo Partner. We review custom modules, access rights, integrations and hosting set-ups, and give you a prioritised list of fixes. Book a free discovery call or request a quotation for a security review.
Frequently Asked Questions
How should external systems authenticate to Odoo?
Create a dedicated user for each integration with minimal access rights, and use an API key generated for that user instead of a password or an administrator account.
How do I verify a webhook sent to Odoo?
Have the sender sign the raw request body with a shared secret using HMAC, recompute the signature in your controller, compare it in constant time and reject requests with stale timestamps.



