Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0.
  • Connection: A user authorizes the connection in the provider’s consent screen.
  • Scopes: offline_access, accounting.transactions, accounting.contacts, accounting.settings, accounting.attachments.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.

Setup

  1. Create a Xero account: Sign up at https://www.xero.com/ - every Xero login includes the free Demo Company, which is ideal for testing API calls without touching real books.
  2. Create an app in the Xero developer portal: Go to https://developer.xero.com/app/manage and create a new app (Web app type). Set the redirect URI to your app’s /api/auth/xero/callback URL.
  3. Copy credentials: Copy the Client ID and generate a Client Secret from the app’s Configuration page. Set XERO_CLIENT_ID and XERO_CLIENT_SECRET in your .env.
  4. Connect and discover your tenant: Complete the OAuth flow, then run the List Connections tool. Copy the tenantId from the response - every other Xero tool requires it as the tenant_id parameter (sent as the xero-tenant-id header).

Provider notes

  • The offline_access scope is required - without it Xero issues no refresh token and access expires after 30 minutes
  • Refresh tokens are single-use and expire after 60 days of inactivity
  • The token endpoint authenticates with HTTP Basic (client_id:client_secret base64-encoded)
  • Every Accounting API call must include the xero-tenant-id header; use List Connections to find it
  • The accounting.attachments scope is required for the Create Invoice Attachment tool; attachment bodies are raw file bytes (max 10 MB)
  • Uncertified apps are limited to 25 connected organisations
Provider API reference.

Tools

Verify the connection

Call a read tool such as xero__list_connections with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.