What's Xero?
Xero is cloud accounting software for small to medium businesses who think QuickBooks is ugly and want something that actually works. It handles invoicing, bank reconciliation, expense tracking, and payroll. All the standard accounting stuff, but with a UI that doesn't make you want to quit. You're here because you need to connect Xero to your app, sync data, or automate workflows. Here's how to get API access in under 10 minutes.
Note: Xero doesn't use traditional API keys. Instead, it uses OAuth 2.0 authentication with Client ID and Client Secret credentials. This guide walks you through obtaining those credentials and setting up the OAuth flow.
Prerequisites
- Xero account (any plan, even a trial works)
- Know if you're building for just yourself or multiple organizations
- Developer account (free, takes 30 seconds to create)
Step 1: Create a Xero Developer Account
Go to https://developer.xero.com and sign up. Use the same email address as your Xero account to avoid confusion later.
Step 2: Create Your App
Hit MyApps → New app
Fill this out:
- App name: Something you'll recognize in 6 months
- Company or application URL: Your website (or use http://localhost for testing)
- OAuth 2.0 redirect URI: Where Xero sends users after auth
- Testing: http://localhost:8080/callback
- Production: https://yourapp.com/auth/xero/callback
Pick your integration type:
- Web app: For multi-tenant apps serving multiple Xero orgs
- Desktop or mobile app: For PKCE flow without client secrets
- Custom connection: For internal tools accessing only YOUR organization
Save it. You get a Client ID immediately.
Step 3: Get Your Client Secret
Click your app name, then Configuration.
Generate a client secret. Copy it now. Xero shows it once, then it's gone forever.
Step 4: Choose Your Scopes
For a web app, you don't tick scopes in the portal. You request them in the scope parameter of the authorization URL (Step 5), space-separated. Only custom connections pick scopes in the portal.
Apps created from March 2, 2026 can't use the old broad accounting.transactions scope. Xero split it into granular scopes, and older apps have to switch by September 13, 2027. The ones you'll likely need:
- accounting.invoices: Invoices, credit notes, and items
- accounting.payments: Payments
- accounting.banktransactions: Bank transactions
- accounting.manualjournals: Manual journals
- accounting.contacts: Customer and supplier data
- accounting.settings: Company info, chart of accounts, tax rates
- offline_access: Gives you a refresh token, so you can get new access tokens without sending the user back through login
For new apps, the balance sheet, profit and loss, and journals scopes aren't available on standard apps. They need Xero App Partner Program enrolment.
Don't be greedy. Pick only what you need or users will bail at the consent screen.
Step 5: Connect Your Organization
For testing with your own org:
- Send the user (yourself, for now) to
https://login.xero.com/identity/connect/authorizewith yourclient_id,redirect_uri,response_type=code,scope, and astatevalue - Select your organization
- Approve the permissions
- You're redirected to your callback URL with an authorization code
Step 6: Exchange Code for Tokens
POST the authorization code to Xero's token endpoint (https://identity.xero.com/connect/token). You get:
- Access token (expires in 30 minutes)
- Refresh token (expires in 60 days if unused, and only if you requested
offline_access) - ID token (contains user info, only if you requested the
openidscope)
Then call GET https://api.xero.com/connections to get the tenant ID of each organization the user connected. Store it: you need it for every API call.
Common Screwups to Avoid
-
Wrong Redirect URI: Must match EXACTLY what's in your app config. Trailing slashes matter. http vs https matters.
-
Expired Tokens: Access tokens die in 30 minutes. Implement refresh token rotation or your integration breaks during lunch.
-
Missing Tenant ID: Every API call needs the tenant ID in the
xero-tenant-idheader. No tenant ID = 401 errors. -
Rate Limits:
- Minute limit: 60 calls per organization
- Concurrent limit: 5 calls per organization
- Daily limit: 5,000 calls per organization (1,000 on Xero's free Starter tier)
- App-wide: 10,000 calls per minute across all organizations
- Hit these = 429 errors for up to 60 seconds
-
Sandbox vs Production: Xero has a Demo Company for testing. Use it. Don't test on real books like an amateur. There are no separate sandbox credentials: the same app connects to the Demo Company or a real organization, and the connected org decides which data you see.
App Types: Which One?
- Custom Connection: You're building internal tools for YOUR company only
- Public App: You're building for multiple Xero organizations
- Partner App: You want to be listed in Xero's app marketplace (requires approval)
Pick one. Stop overthinking it. If you want a detailed guide on the partner app, please check out our guide here.
Connection limits depend on your Xero developer pricing tier. The free Starter tier allows up to 5 connections, Core up to 50, and from Plus (51+ connections) upward you need App Partner certification. Until you're certified, each Xero organization can connect at most 2 uncertified apps.
Testing Your Connection
- Use the Demo Company (create one in your Xero account)
- Make a simple GET request to /api.xro/2.0/organisation
- If you get JSON back with your company details, you're connected
- If you get 401, check your tenant ID and token
Security Requirements That Actually Matter
- Store tokens encrypted, not in plain text
- Use PKCE for mobile/desktop apps (no client secret needed)
- Rotate refresh tokens before they expire
- Never commit credentials to git (use environment variables)
That's it. You now have Xero API access. Stop reading documentation and start pulling data.
And if you want to know more about Xero authentication, integration, and bank feeds, check out the guides below:
- Bank Feeds Guide: https://developers.apideck.com/guides/bank-feeds-xero
- Authentication and Account Receivables Guide: https://www.apideck.com/blog/xero-integration-authentication-and-accounts-receivable-best-practices#challenges-and-complexities-of-integrating-with-the-xero-api
Managing Xero API connectivity with Apideck's Vault
If you want to integrate with Xero and other accounting systems, managing API connections can be challenging. You can use Apideck to connect to accounting applications. Apideck's Vault allows for:
- Secure credential storage with automatic token refresh - No need to build token management infrastructure or handle OAuth flows manually.
- Pre-built authentication UI - Embedded Vault components handle credential input and OAuth authorization without custom UI development.
- Centralized connection monitoring - Track connection states, validate credentials, and manage multiple accounting platforms from a single dashboard.
Xero doesn't support shared credentials, so even for testing through Apideck you use your own Xero app from the steps above. Add Apideck's redirect URI (https://unify.apideck.com/vault/callback) to your Xero app, then paste your Client ID and Client Secret into the Xero connector settings in your Apideck dashboard. Apideck then runs the OAuth flow and renews tokens before Xero's 60-day expiry, so idle connections don't drop. If you later certify as a Xero App Partner, you'll need a custom Vault domain first so the Apideck callback is hidden.
And here's how you can easily connect and manage permissions for your API Access. Go to the platform, select Xero, and add the required credentials that you obtained.

Save and then click on test-vault. Click Authorize, then authenticate via Xero.

This will then authenticate and you can start using Xero via Apideck. After this, if you want to integrate with Xero:
- Xero Integration Guide
- Xero Docs to get your started.
Create a free Apideck account to get started, and build something awesome.
Ready to get started?
Scale your integration strategy and deliver the integrations your customers need in record time.








