Documentation / API
AI Assistants (MCP)
Connect Claude Code, Cursor, VS Code or another AI assistant to calmo.cloud and let it work with your team's Odoos, backups and servers.
calmo.cloud runs an MCP server, so an AI assistant can manage your team the way a script does through the REST API. MCP (Model Context Protocol) is the open standard that Claude, Cursor, VS Code and many other assistants use to call outside tools. Once connected, you ask in plain language: "Which of our Odoos are stopped?", "Make a test copy of the live Odoo" or "Back up the Müller GmbH database and give me the download link".
Every assistant connects to the same address:
https://calmo.cloud/api/mcp
The API Tokens page in the panel shows it too; click the address there to copy it.
The MCP server is part of the API, which is included from the Starter plan. See Plan.
What an assistant can do #
The assistant gets the capabilities of the REST API as tools it can call:
| Area | What the assistant can do |
|---|---|
| Odoos | List them and check their status, create, change and delete them, start, stop, restart and redeploy them, create copies for testing, and look up what your plan includes and how much of it your team uses |
| Backups | List backups, create one, get a download link, import a backup and restore one, and see your backup destinations |
| Caught emails | Read the emails a copy, preview or coding-agent sandbox sent instead of delivering them, look at their attachments and clear the mailbox |
| Domains and monitoring | Add, change and remove hostnames, check their DNS, and set up uptime monitors |
| Code and addons | Add addon repositories, attach them to an Odoo and deploy their addons |
| Sharing | Share an Odoo with another team, change its role or revoke it, and accept or decline invitations your team received |
| Coding agents | Start coding-agent sessions on an Odoo, follow what they do and reply to them, with files such as screenshots or sample data attached |
| Servers | Add and provision servers, reboot them or switch them off and on, and run provisioning templates |
The assistant cannot open a terminal or run arbitrary commands on your servers.
Sharing and coding agents are being rolled out team by team. If one of them isn't enabled for your team yet, the assistant is told so and can pass it on.
Create a token #
The assistant authenticates with an API token of your team. Owners and admins create one on the API Tokens page, in the Developer section of the panel menu (see Authentication). Give each assistant a token of its own and name it after the assistant, for example "Claude Code on my laptop", so you can revoke one without disconnecting the others. Allow it only what it needs: a token can be limited to some permissions, to specific Odoos and servers, and to the MCP server alone (see Limiting what a token can do).
The assistant sends the token in the Authorization header of every request:
Authorization: Bearer your-api-token
A token opens your whole team to whoever holds it. Never commit one to a repository or paste it into a chat.
Connect your assistant #
Claude Code #
The quickest way is the calmo.cloud plugin. It sets up the connection, asks for your token once and keeps it in your system's credential store, and adds skills such as moving an existing Odoo:
/plugin marketplace add havmedia/calmo-cloud-plugin
/plugin install calmo@calmo-cloud
To connect without the plugin, add the server from your terminal:
claude mcp add --transport http calmo https://calmo.cloud/api/mcp \
--header "Authorization: Bearer your-api-token"
The server is added to the current project; add --scope user to the command to have it in every project. Run /mcp in Claude Code to check that calmo is connected.
Claude desktop app #
The Claude desktop app reaches calmo.cloud through the mcp-remote bridge, which needs Node.js. Open Settings > Developer > Edit Config and add calmo.cloud to claude_desktop_config.json:
{
"mcpServers": {
"calmo": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://calmo.cloud/api/mcp", "--header", "Authorization:${CALMO_AUTH}"],
"env": {
"CALMO_AUTH": "Bearer your-api-token"
}
}
}
}
Restart the app afterwards. The header goes through an environment variable because some systems split the argument at the space after Bearer.
Cursor #
Add calmo.cloud to ~/.cursor/mcp.json to use it in every project, or to .cursor/mcp.json in one project. Cursor can read the token from an environment variable, which keeps it out of the file:
{
"mcpServers": {
"calmo": {
"url": "https://calmo.cloud/api/mcp",
"headers": {
"Authorization": "Bearer ${env:CALMO_API_TOKEN}"
}
}
}
}
calmo.cloud then appears in Cursor's MCP settings.
VS Code #
Add calmo.cloud to .vscode/mcp.json in a workspace, or to your user configuration with the MCP: Open User Configuration command. VS Code asks for the token once and stores it for you:
{
"inputs": [
{
"type": "promptString",
"id": "calmo-token",
"description": "calmo.cloud API token",
"password": true
}
],
"servers": {
"calmo": {
"type": "http",
"url": "https://calmo.cloud/api/mcp",
"headers": {
"Authorization": "Bearer ${input:calmo-token}"
}
}
}
}
Start the server from the file or with MCP: List Servers. The tools are then available in Copilot Chat's agent mode.
Other assistants #
Any assistant that supports remote MCP servers over HTTP (also called "streamable HTTP") and lets you set a request header connects with the same address and the header above. If it asks for a transport, choose HTTP, not SSE. An assistant that can only start local servers reaches calmo.cloud through the mcp-remote bridge, as the Claude desktop app does.
Assistants that can only connect by signing in, such as the Claude and ChatGPT web apps, can't connect to calmo.cloud yet.
What the assistant is allowed to do #
The assistant acts as the team its token belongs to, with the rights of that token. It is only offered the tools its token's permissions allow, and only sees the Odoos and servers the token is limited to. It can't create, change or revoke API tokens; that only happens in the panel. Only owners and admins can create tokens, and the role of whoever types the requests doesn't limit the assistant further.
- It sees your team's servers, Odoos, backups and repositories. It never sees anything that belongs to another team.
- On an Odoo another team shares with yours, your role on that Odoo applies: a Viewer can look, an Operator can also start, stop and back it up, and so on. See Roles. Deleting a shared Odoo, changing its backup configuration and sharing it further remain with the team that hosts it.
- It receives the same data the REST API returns. That includes an Odoo's admin credentials wherever your team is allowed to see them, and backup download links when it asks for one. Everything a tool returns goes to the company that runs your assistant.
Confirming destructive actions #
Some actions can't be undone or cost money: deleting something, restoring a backup over live data, switching off or rebooting a server, and ordering a server from your cloud provider. The assistant can only carry them out when it repeats the exact name of the target in its request, for example the name of the Odoo it is about to delete, and calmo.cloud tells it to ask you before it does.
Most assistants also ask you to approve each tool call that changes something. Keep that switched on and read what the assistant is about to do before you approve. Text the assistant reads from calmo.cloud, such as an Odoo's description or a coding agent's output, may contain instructions you didn't write.
Work that runs in the background #
Starting, stopping, redeploying, copying, backing up and restoring take a while, just as in the panel. The assistant gets an answer as soon as the work is queued and then checks the status until it is done; you can follow the same progress in the panel. While something is still running, let it finish instead of asking the assistant to start it again.
Rate limits #
calmo.cloud limits how many requests a team can send per minute, counted across all of its tokens and assistants. An assistant that goes over the limit gets a "Too Many Requests" answer and can continue a minute later. Copies share their hourly limit with copies created through the REST API.
Revoking access #
Open API Tokens in the Developer section of the panel menu and click Revoke next to the assistant's token. The assistant loses access at once.
Removing calmo.cloud from the assistant doesn't invalidate the token. When you stop using an assistant, revoke its token on calmo.cloud as well.
Plan #
The MCP server answers only teams whose plan includes the API, which is every plan from Starter up. The plan of the team the token belongs to counts, also for Odoos another team shares with it. See Pricing and billing.
Troubleshooting #
| What you see | What to do |
|---|---|
401 Unauthorized or "Unauthenticated." |
The token was revoked or is wrong. Create a new API token and put it into the assistant's configuration. |
403 Forbidden with "Your … plan does not include the API and command line." |
Your team's plan doesn't include the API. The Plan page in the team menu shows which plan your team is on. Some assistants only report a failed connection here, so check the plan first. |
403 Forbidden with "This API token is not allowed to use the MCP server." |
The token is limited to the REST API. Click Edit access next to it and tick the MCP server under Accepted by. |
| The assistant says the token does not have a scope, or it is missing tools | The token's permissions leave that out. Click Edit access next to the token and add the permission. |
429 Too Many Requests |
Your team sent too many requests in a short time. Wait a minute and try again. |
405 Method Not Allowed, or the connection fails straight away |
The assistant is trying the older SSE transport. Choose HTTP (streamable HTTP). |
| The assistant can't find an Odoo or a server | It belongs to a different team, or the token is limited to other Odoos or servers. Give the assistant a token of that team, or widen the token with Edit access. |
| The assistant says a feature isn't enabled for your team | Sharing and coding agents are being rolled out team by team. Get in touch and we switch them on. |
| The assistant won't delete or restore something | It needs the exact name of the target as confirmation. Tell it which one you mean. |