Xero
Service ID: xero
Get paid sooner when you accept payments online straight from a Xero invoice. Give your customers different payment options, including PayPal and Stripe.
At a Glance
- Difficulty
- ⚡MODERATESelf-Service OAuth + App Partner Certification Required to Scale
- Authentication
- OAuth 2.0Authorization Code flow.
- Webhooks
- Native — invoice and bill events (created and updated).
- Partnership Required
- Yes(App Partner Program certification is mandatory from the Plus tier and to list on the Xero App Store; Starter and Core tiers need no approval.)
- Partnership Application
- Xero App Partner Program↗
- Apideck Credentials
- Not available
- Costs
- Free Starter tier; Core ~$22, Plus ~$152, Advanced ~$895 USD/month by connection count; Enterprise custom; plus per-GB egress overage. Effective March 2, 2026.
- Sandbox Availability
- Available — Access Sandbox↗(Free via Xero Developer Portal (demo company included).)
- Account Type Required
- Any active Xero subscription
- Consumer Access Level
- Standard or Adviser level user (Admin recommended for full data access)
- Rate Limits
- 60 calls/minute and 5 concurrent calls per organisation; daily cap of 1,000 calls on Starter and 5,000 on Core and above; 10,000 calls/minute app-wide.
Responsibility matrix
| Task | You (Customer) | Your Consumer | Apideck |
|---|---|---|---|
| Create Xero Developer Account | ✓ | — | — |
| Register Xero App | ✓ | — | Docs provided |
| Add Credentials to Apideck | ✓ | — | — |
| Apply for App Partner Certification | ✓ (if scaling to the Plus tier or above) | — | Support available |
| Set Up Custom Domain (Vault) | ✓ (if certifying) | — | Configures on request |
| Register Webhook (Optional) | ✓ | — | Webhook URL provided |
| Authorize Connection (OAuth) | — | ✓ | Handles OAuth flow |
| Build via Unified API | ✓ | — | Maintains connector |
| Token Refresh | — | — | ✓ Automatic |
| Monitor Connections | Via dashboard | Can revoke anytime | Logs and alerts |
Environments
- Sandbox & Production (shared credentials)
- Xero uses the same credential structure for sandbox and production — the connected Xero organisation determines which data is accessed. Testing options: the Xero Demo Company (included with every developer account, sample data) and a 30-day full-featured free trial via xero.com/signup.
- Multi-Organisation
- When a consumer authorises your app, they choose which Xero organisation to connect. Consumers with multiple organisations require a separate connection per organisation.
🚨Important to Know About Xero
- Connection caps are tier-based: 5 active connections on the free Starter tier, 50 on Core, and more only from Plus upward. Certification unlocks the higher tiers but itself requires at least 10 active customer connections, so start the process before you hit the cap.
- Xero expires a refresh token after 60 days unused, but Apideck renews it before then, so an idle connection does not lapse. Re-authorising is needed if access is withdrawn in Xero, a renewal fails, or a new permission is requested.
- Consumers can install a maximum of 2 uncertified apps — if at the limit they must remove another uncertified app first.
- Certification compliance requires hiding the Apideck callback — a custom Vault domain must be configured before certification.
- From March 2, 2026 the Journals API is gated to the Advanced tier and new apps must use granular OAuth scopes; older apps must migrate by September 2027. General-ledger reads need accounting.journals.read, which Apideck no longer requests by default; manual journals still work.
⚠️
52 gotchas across 33 resources
Connector-specific behaviors and limitations to be aware of
📦
25 supported resources
View field mappings, supported operations, and schema details