Xero
Service ID: xero
Get paid sooner when you accept payments online straight from a Xero invoice. Give your customers different payment options, including PayPal and Stripe.
At a Glance
- Difficulty
- ⚡MODERATESelf-Service OAuth + App Partner Certification Required to Scale
- Authentication
- OAuth 2.0OAuth 2.0 (Authorization Code).
- Webhooks
- Native — invoice and bill events (created and updated).
- Partnership Required
- Yes(Required to scale: App Partner Program certification is mandatory from the Plus tier and to list on the Xero App Store. Free-tier access needs no approval.)
- Partnership Application
- Xero App Partner Program↗
- Apideck Credentials
- Not available
- Costs
- Free Starter tier; paid Core to Advanced ($895/mo) and Enterprise (custom), plus per-GB egress overage, effective March 2, 2026. Separate from Apideck pricing.
- Sandbox Availability
- Available — Access Sandbox↗(Free via Xero Developer Portal (demo company included).)
- Account Type Required
- Any active Xero subscription
- Consumer Access Level
- Standard or Adviser level user (Admin recommended for full data access)
- Rate Limits
- 60 calls/minute and 5 concurrent calls per organisation; daily cap of 1,000 calls on Starter and 5,000 on Core and above; 10,000 calls/minute app-wide.
Responsibility matrix
| Task | You (Customer) | Your Consumer | Apideck |
|---|---|---|---|
| Create Xero Developer Account | ✓ | — | — |
| Register Xero App | ✓ | — | Docs provided |
| Add Credentials to Apideck | ✓ | — | — |
| Apply for App Partner Certification | ✓ (if scaling to the Plus tier or above) | — | Support available |
| Set Up Custom Domain (Vault) | ✓ (if certifying) | — | Configures on request |
| Register Webhook (Optional) | ✓ | — | Webhook URL provided |
| Authorize Connection (OAuth) | — | ✓ | Handles OAuth flow |
| Build via Unified API | ✓ | — | Maintains connector |
| Token Refresh | — | — | ✓ Automatic |
| Monitor Connections | Via dashboard | Can revoke anytime | Logs and alerts |
Environments
- Sandbox & Production (shared credentials)
- Xero uses the same credential structure for sandbox and production — the connected Xero organisation determines which data is accessed. Testing options: the Xero Demo Company (included with every developer account, sample data) and a 30-day full-featured free trial via xero.com/signup.
- Multi-Organisation
- When a consumer authorises your app, they choose which Xero organisation to connect. Consumers with multiple organisations require a separate connection per organisation.
🚨Important to Know About Xero
- Connection caps are tier-based: 5 active connections on the free Starter tier, 50 on Core, and more only from Plus upward. Certification unlocks the higher tiers but itself requires at least 10 active customer connections, so start the process before you hit the cap.
- Refresh tokens expire after 60 days if unused — consumer must re-authorise.
- Consumers can install a maximum of 2 uncertified apps — if at the limit they must remove another uncertified app first.
- Certification compliance requires hiding the Apideck callback — a custom Vault domain must be configured before certification.
- From March 2, 2026 the Journals API is gated to the Advanced tier and new apps must use granular OAuth scopes (legacy umbrella scopes are rejected). General-ledger reads also need accounting.journals.read, which Apideck no longer requests by default; manual journals still work.
⚠️
40 gotchas across 22 resources
Connector-specific behaviors and limitations to be aware of
📦
23 supported resources
View field mappings, supported operations, and schema details