Xero

Service ID: xero

Get paid sooner when you accept payments online straight from a Xero invoice. Give your customers different payment options, including PayPal and Stripe.

At a Glance

Difficulty
MODERATESelf-Service OAuth + App Partner Certification Required to Scale
Authentication
OAuth 2.0OAuth 2.0 (Authorization Code).
Webhooks
Native — invoice and bill events (created and updated).
Partnership Required
Yes(Required to scale: App Partner Program certification is mandatory from the Plus tier and to list on the Xero App Store. Free-tier access needs no approval.)
Partnership Application
Xero App Partner Program
Apideck Credentials
Not available
Costs
Free Starter tier; paid Core to Advanced ($895/mo) and Enterprise (custom), plus per-GB egress overage, effective March 2, 2026. Separate from Apideck pricing.
Sandbox Availability
AvailableAccess Sandbox(Free via Xero Developer Portal (demo company included).)
Account Type Required
Any active Xero subscription
Consumer Access Level
Standard or Adviser level user (Admin recommended for full data access)
Rate Limits
60 calls/minute and 5 concurrent calls per organisation; daily cap of 1,000 calls on Starter and 5,000 on Core and above; 10,000 calls/minute app-wide.

Responsibility matrix

TaskYou (Customer)Your ConsumerApideck
Create Xero Developer Account
Register Xero AppDocs provided
Add Credentials to Apideck
Apply for App Partner Certification✓ (if scaling to the Plus tier or above)Support available
Set Up Custom Domain (Vault)✓ (if certifying)Configures on request
Register Webhook (Optional)Webhook URL provided
Authorize Connection (OAuth)Handles OAuth flow
Build via Unified APIMaintains connector
Token Refresh✓ Automatic
Monitor ConnectionsVia dashboardCan revoke anytimeLogs and alerts

Environments

Sandbox & Production (shared credentials)
Xero uses the same credential structure for sandbox and production — the connected Xero organisation determines which data is accessed. Testing options: the Xero Demo Company (included with every developer account, sample data) and a 30-day full-featured free trial via xero.com/signup.
Multi-Organisation
When a consumer authorises your app, they choose which Xero organisation to connect. Consumers with multiple organisations require a separate connection per organisation.

🚨Important to Know About Xero

  • Connection caps are tier-based: 5 active connections on the free Starter tier, 50 on Core, and more only from Plus upward. Certification unlocks the higher tiers but itself requires at least 10 active customer connections, so start the process before you hit the cap.
  • Refresh tokens expire after 60 days if unused — consumer must re-authorise.
  • Consumers can install a maximum of 2 uncertified apps — if at the limit they must remove another uncertified app first.
  • Certification compliance requires hiding the Apideck callback — a custom Vault domain must be configured before certification.
  • From March 2, 2026 the Journals API is gated to the Advanced tier and new apps must use granular OAuth scopes (legacy umbrella scopes are rejected). General-ledger reads also need accounting.journals.read, which Apideck no longer requests by default; manual journals still work.
⚠️

40 gotchas across 22 resources

Connector-specific behaviors and limitations to be aware of

📦

23 supported resources

View field mappings, supported operations, and schema details