Xero

Service ID: xero

Get paid sooner when you accept payments online straight from a Xero invoice. Give your customers different payment options, including PayPal and Stripe.

At a Glance

Difficulty
⚡MODERATESelf-Service OAuth + App Partner Certification Required to Scale
Authentication
OAuth 2.0Authorization Code flow.
Webhooks
Native — invoice and bill events (created and updated).
Partnership Required
Yes(App Partner Program certification is mandatory from the Plus tier and to list on the Xero App Store; Starter and Core tiers need no approval.)
Partnership Application
Xero App Partner Program↗
Apideck Credentials
Not available
Costs
Free Starter tier; Core ~$22, Plus ~$152, Advanced ~$895 USD/month by connection count; Enterprise custom; plus per-GB egress overage. Effective March 2, 2026.
Sandbox Availability
Available — Access Sandbox↗(Free via Xero Developer Portal (demo company included).)
Account Type Required
Any active Xero subscription
Consumer Access Level
Standard or Adviser level user (Admin recommended for full data access)
Rate Limits
60 calls/minute and 5 concurrent calls per organisation; daily cap of 1,000 calls on Starter and 5,000 on Core and above; 10,000 calls/minute app-wide.

Responsibility matrix

TaskYou (Customer)Your ConsumerApideck
Create Xero Developer Account✓——
Register Xero App✓—Docs provided
Add Credentials to Apideck✓——
Apply for App Partner Certification✓ (if scaling to the Plus tier or above)—Support available
Set Up Custom Domain (Vault)✓ (if certifying)—Configures on request
Register Webhook (Optional)✓—Webhook URL provided
Authorize Connection (OAuth)—✓Handles OAuth flow
Build via Unified API✓—Maintains connector
Token Refresh——✓ Automatic
Monitor ConnectionsVia dashboardCan revoke anytimeLogs and alerts

Environments

Sandbox & Production (shared credentials)
Xero uses the same credential structure for sandbox and production — the connected Xero organisation determines which data is accessed. Testing options: the Xero Demo Company (included with every developer account, sample data) and a 30-day full-featured free trial via xero.com/signup.
Multi-Organisation
When a consumer authorises your app, they choose which Xero organisation to connect. Consumers with multiple organisations require a separate connection per organisation.

🚨Important to Know About Xero

  • Connection caps are tier-based: 5 active connections on the free Starter tier, 50 on Core, and more only from Plus upward. Certification unlocks the higher tiers but itself requires at least 10 active customer connections, so start the process before you hit the cap.
  • Xero expires a refresh token after 60 days unused, but Apideck renews it before then, so an idle connection does not lapse. Re-authorising is needed if access is withdrawn in Xero, a renewal fails, or a new permission is requested.
  • Consumers can install a maximum of 2 uncertified apps — if at the limit they must remove another uncertified app first.
  • Certification compliance requires hiding the Apideck callback — a custom Vault domain must be configured before certification.
  • From March 2, 2026 the Journals API is gated to the Advanced tier and new apps must use granular OAuth scopes; older apps must migrate by September 2027. General-ledger reads need accounting.journals.read, which Apideck no longer requests by default; manual journals still work.
⚠️

52 gotchas across 33 resources

Connector-specific behaviors and limitations to be aware of

📦

25 supported resources

View field mappings, supported operations, and schema details