{
  "data": {
    "a": {
      "slug": "codat",
      "name": "Codat",
      "vendor": "Codat Limited",
      "vendorUrl": "https://codat.io",
      "kind": "http-api",
      "category": "accounting",
      "summary": "Codat connects a business's accounting, banking and commerce software to financial products and banks through one REST API. Product APIs cover bill pay, expenses, bank feeds and lending data, with official SDKs for TypeScript, Python and C#.",
      "url": "https://www.anchorterminal.com/tools/codat",
      "markdownUrl": "https://www.anchorterminal.com/tools/codat.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/codat.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/codat.json",
      "repo": "https://github.com/codatio/oas",
      "license": "Proprietary service under Codat's Master Services Agreement. The documentation repository codatio/codat-docs is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.codat.io",
      "packages": [
        {
          "registry": "npm",
          "name": "@codat/platform"
        },
        {
          "registry": "pypi",
          "name": "codat-platform"
        }
      ],
      "auth": "api-key",
      "authNotes": "An API key, Base64 encoded, in an `Authorization: Basic` header on every call to https://api.codat.io. An account comes through Codat's sales team. The docs say to get in touch to create one, and no self-serve signup was found. A client can hold up to 10 named keys, created and deleted in the Portal by Administrator or Developer users or through the /apiKeys endpoints. Keys have no scopes, so each one reaches every company the client has connected. End customers authorise their accounting package through Codat's Link flow.",
      "pricing": "paid",
      "pricingNotes": "No public price. codat.io/pricing returns 404 and the site's buttons ask for a meeting. The standard MSA sets a platform fee invoiced in advance and a unit fee per active company per month, both in an order form. The docs describe a free trial limited to 50 companies, no hourly syncs and 365 days, and a Codat Sandbox integration that is excluded from billing, but an account starts with a request to Codat (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs repository, the OpenAPI specs or the site (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 2690,
        "pypiWeekly": 222,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.codat.io/using-the-api/overview",
      "openapi": "https://raw.githubusercontent.com/codatio/oas/main/json/Codat-Platform.json",
      "capabilities": [
        "accounting.unified",
        "accounting.bills",
        "accounting.reports",
        "accounting.ledger",
        "accounting.invoices"
      ],
      "tags": [
        "hosted",
        "paid",
        "sales-led",
        "api-key",
        "openapi",
        "webhooks",
        "async-jobs",
        "idempotency",
        "sandbox",
        "typescript",
        "python",
        "csharp",
        "status-page",
        "soc2",
        "iso27001",
        "closed-source"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.3,
        "grade": "B",
        "agentReady": false,
        "rank": 280,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 81,
          "maintenance": 75,
          "payments": 10,
          "reliability": 80,
          "schema": 77,
          "security": 49,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Public OpenAPI specs, an Idempotency-Key header on writes, Retry-After on 429 and a written three-month deprecation notice suit an agent that retries. Access is the limitation. No price or self-serve signup is published, the general Accounting API is closed to new clients, and API keys carry no scopes.",
        "bestFor": "Banks, lenders, bill pay, expense and card products that already have or will sign a Codat contract and need writes into many accounting packages.",
        "strengths": [
          "Public OpenAPI 3 specs for every API in codatio/oas, with long operation descriptions and per-integration response examples",
          "Idempotency-Key header on POST and PATCH, cached for 90 minutes, and released after a 429 so the same key can be retried",
          "429 responses carry Retry-After, and every response carries X-Rate-Limit-Limit, Remaining and Reset headers",
          "Breaking changes are posted at least three months ahead, with a deprecation calendar and quarterly emails",
          "Annual SOC 2 Type II and ISO 27001 audits and a private bug bounty, per codat.io/security"
        ],
        "weaknesses": [
          "No public price. The pricing page returns 404 and fees are set in an order form",
          "No self-serve signup found. The docs and the site ask new users to get in touch",
          "The general Accounting API spec says it is relevant only to existing clients, and the status page labels it Legacy",
          "API keys have no scopes or read-only mode, and one key reaches every connected company",
          "Two complete API outages in July 2026, of 14 and 12 minutes, and intermittent Xero failures from 22 to 29 July",
          "The Java and Go SDKs were archived in April and May 2026"
        ],
        "agentNotes": [
          "Send `Authorization: Basic \u003cbase64 of the API key\u003e` to https://api.codat.io. The Portal shows the ready-made header value",
          "Send a new GUID as `Idempotency-Key` on every POST and PATCH, and reuse the same key when retrying after a 429",
          "Treat writes as asynchronous on most APIs. Keep the push operation key and wait for the `{dataType}.write.successful` or `.unsuccessful` webhook",
          "Call the Get model (options) endpoint for the connection before a create or update, because required fields differ by accounting package",
          "Filter with `query=modifiedDate\u003e...` and keep `pageSize` at 100. The daily quota is 1,000 requests times one plus the number of active connected companies"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.3
          }
        ],
        "editorialScores": {
          "ergonomics": 81,
          "maintenance": 75,
          "payments": 10,
          "reliability": 80,
          "schema": 77,
          "security": 49,
          "transparency": 59
        },
        "provenanceScore": 82
      },
      "connect": {
        "install": "npm install @codat/platform",
        "http": "curl https://api.codat.io/companies \\\n  -H \"Authorization: Basic $CODAT_ENCODED_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/accounting.unified",
        "tool": "https://letme.dev/codat"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Codat Limited",
        "domain": "codat.io",
        "domainRegistered": "2016-10-17",
        "endpointOnVendorDomain": true,
        "terms": "https://codat.io/msa-standard/",
        "privacy": "https://codat.io/privacy-policy/",
        "statusPage": "https://status.codat.io",
        "changelog": "https://docs.codat.io/updates",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The standard MSA (version 2.0, 5 September 2022) names Codat Limited, registered in England and Wales, number 10480375, 6-7 St. Cross Street, London EC1N 8UB, for clients in the UK and the rest of the world outside the USA. The privacy notice also names Codat, Inc., a Delaware corporation.",
          "codat.io/legals lists two agreements, the Master Services Agreement (standard and enterprise versions) and the Start-up Plan terms. The standard MSA is the one recorded here.",
          "The Codat Global Privacy Notice was last updated in April 2025. It is written mainly for website visitors, and the MSA points to the same page for the sub-processor list.",
          "codat.io, app.codat.io and api.codat.io all return 404 for /.well-known/security.txt. codat.io/security has a disclosure form.",
          "RDAP for codat.io gives a registration date of 2016-10-17."
        ],
        "score": 82
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/codat.json",
      "live": {
        "slug": "codat",
        "probe": {
          "target": "https://api.codat.io",
          "method": "get",
          "lastAt": "2026-10-08T23:09:05.153734935Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 53,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 62,
          "p95ms24h": 130,
          "samples24h": 61,
          "samples30d": 61,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 61,
              "ok": 61
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.codat.io",
          "indicator": "maintenance",
          "summary": "Service Under Maintenance",
          "checkedAt": "2026-10-08T23:13:18.99270584Z"
        },
        "pages": [
          {
            "url": "https://docs.codat.io/updates",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:18:26.233949031Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "07529b659c92"
          },
          {
            "url": "https://codat.io/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:28.10988641Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e89a28b3e19e"
          },
          {
            "url": "https://codat.io/msa-standard/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:25.833678794Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a5936b16dc49"
          }
        ],
        "updatedAt": "2026-10-08T23:13:18.99270584Z"
      }
    },
    "answer": "Xero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics.",
    "b": {
      "slug": "xero",
      "name": "Xero API + MCP",
      "vendor": "Xero",
      "vendorUrl": "https://developer.xero.com",
      "kind": "http-api",
      "category": "accounting",
      "summary": "Accounting API for Xero organisations, with contacts, invoices, bills, payments, bank transactions, manual journals, the balance sheet, profit and loss and trial balance, plus payroll in some regions.",
      "url": "https://www.anchorterminal.com/tools/xero",
      "markdownUrl": "https://www.anchorterminal.com/tools/xero.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/xero.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/xero.json",
      "repo": "https://github.com/XeroAPI/xero-mcp-server",
      "license": "MIT",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://api.xero.com/api.xro/2.0",
      "packages": [
        {
          "registry": "npm",
          "name": "xero-node"
        },
        {
          "registry": "pypi",
          "name": "xero-python"
        },
        {
          "registry": "npm",
          "name": "@xeroapi/xero-mcp-server"
        }
      ],
      "auth": "oauth",
      "authNotes": "OAuth 2.0 authorisation code (PKCE for public clients), or client credentials through a \"custom connection\" that is tied to one organisation. Access tokens last 1,800 seconds and refresh tokens up to 60 days. Every call carries a Bearer token and an `xero-tenant-id` header naming the organisation. Apps created from 29 April 2026 must use the granular scopes (accounting.invoices, accounting.reports.profitandloss.read and so on) rather than the old bundled ones. The MCP server takes a client id and secret for a custom connection, or a ready-made bearer token.",
      "pricing": "freemium",
      "pricingNotes": "Developer Platform plans are priced in Australian dollars and billed monthly on connected organisations. Starter is free with 5 connections and 1,000 API calls a day per organisation. Core is AUD 35 a month for 50 connections, Plus AUD 245 for 1,000 and Advanced AUD 1,445 for 10,000, each with 5,000 calls a day per organisation and an egress allowance of 10, 50 or 250 GB (AUD 2.40 a GB over). Plus and above need App Certification, Advanced and Enterprise a security assessment. Enterprise is priced on application. The model took effect on 2 March 2026 for existing developers and 4 December 2025 for new ones (https://developer.xero.com/pricing/).",
      "priceSummary": "Freemium",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": 51,
      "popularity": {
        "githubStars": 350,
        "npmWeekly": 394967,
        "pypiWeekly": 63610,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developer.xero.com/documentation/",
      "openapi": "https://github.com/XeroAPI/Xero-OpenAPI",
      "capabilities": [
        "accounting.ledger",
        "accounting.invoices",
        "accounting.bills",
        "accounting.reports"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "oauth",
        "mcp",
        "openapi",
        "typescript",
        "python",
        "webhooks",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.2,
        "grade": "B",
        "agentReady": false,
        "rank": 213,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 76,
          "payments": 35,
          "reliability": 68,
          "schema": 79,
          "security": 64,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Granular OAuth scopes, such as accounting.reports.profitandloss.read, required for apps created from 29 April 2026. Developer docs, including the per-minute rate limits, only render with JavaScript.",
        "bestFor": "An agent keeping the books for UK, Australian or New Zealand businesses, or any team that wants read-only scopes and long deprecation notice.",
        "strengths": [
          "Granular OAuth scopes, such as accounting.reports.profitandloss.read, required for apps created from 29 April 2026",
          "Deprecations announced with 12 to 13 months' notice on a dated changelog",
          "Public OpenAPI specs, with an Idempotency-Key parameter on 101 accounting operations",
          "Free Starter tier for 5 connections and a Demo Company with sample data",
          "ISO 27001:2022, SOC 2 reports and a vulnerability disclosure programme"
        ],
        "weaknesses": [
          "Developer docs, including the per-minute rate limits, only render with JavaScript",
          "1,000 calls a day per organisation on the free tier, 5,000 on paid",
          "Official MCP server idle since 5 June 2026, with no CI, no annotations and no registry entry",
          "Prices in AUD only, and App Certification is needed above 50 connections",
          "No security.txt and no public subprocessor list"
        ],
        "agentNotes": [
          "Send xero-tenant-id on every call. The token alone doesn't name the organisation",
          "A bill is an Invoice with Type ACCPAY, a sales invoice is ACCREC. There's no separate bills endpoint",
          "Send an Idempotency-Key on creates so a retry after a timeout doesn't post twice",
          "Use If-Modified-Since and pageSize up to 100 to stay inside 1,000 calls a day on Starter",
          "Set XERO_SCOPES to read scopes only when the agent shouldn't write. The MCP still lists its write and delete tools"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.2
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 76,
          "payments": 35,
          "reliability": 68,
          "schema": 79,
          "security": 64,
          "transparency": 60
        },
        "provenanceScore": 84
      },
      "connect": {
        "http": "curl \"https://api.xero.com/api.xro/2.0/Invoices?Statuses=AUTHORISED\u0026page=1\" \\\n  -H \"Authorization: Bearer $XERO_ACCESS_TOKEN\" -H \"xero-tenant-id: $XERO_TENANT_ID\" -H \"Accept: application/json\"",
        "claudeCode": "claude mcp add xero -e XERO_CLIENT_ID=$XERO_CLIENT_ID -e XERO_CLIENT_SECRET=$XERO_CLIENT_SECRET -- npx -y @xeroapi/xero-mcp-server@latest",
        "config": {
          "mcpServers": {
            "xero": {
              "args": [
                "-y",
                "@xeroapi/xero-mcp-server@latest"
              ],
              "command": "npx",
              "env": {
                "XERO_CLIENT_ID": "${XERO_CLIENT_ID}",
                "XERO_CLIENT_SECRET": "${XERO_CLIENT_SECRET}",
                "XERO_SCOPES": "accounting.invoices accounting.contacts accounting.settings"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/accounting.ledger",
        "tool": "https://letme.dev/xero"
      },
      "area": "domain-data",
      "provenance": {
        "legalEntity": "Xero Limited",
        "domain": "xero.com",
        "domainRegistered": "1997-06-03",
        "endpointOnVendorDomain": true,
        "terms": "https://developer.xero.com/xero-developer-platform-terms-conditions/",
        "privacy": "https://www.xero.com/uk/legal/privacy/",
        "statusPage": "https://status.xero.com",
        "changelog": "https://developer.xero.com/changelog/",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "The developer terms name Xero Limited, New Zealand company 1830488. UK customers contract with Xero (UK) Limited, company 06071722, per the UK terms of use.",
          "The pricing page lists prices in AUD only. Overages are invoiced in arrears each calendar month under the commercial terms.",
          "Developer documentation pages return only metadata without JavaScript, so an agent can't read the rate limits or OAuth guides by fetching them. The OpenAPI specs on GitHub are the readable alternative."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/xero.json",
      "live": {
        "slug": "xero",
        "probe": {
          "target": "https://api.xero.com/api.xro/2.0",
          "method": "get",
          "lastAt": "2026-10-08T23:09:23.439790402Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 171,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 99.95,
          "p50ms24h": 164,
          "p95ms24h": 315,
          "samples24h": 268,
          "samples30d": 1975,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 271
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 259,
              "ok": 259
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.xero.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T23:13:50.883918534Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@xeroapi/xero-mcp-server",
            "version": "0.0.17",
            "seenAt": "2026-10-08T16:35:23.132344952Z"
          },
          {
            "registry": "npm",
            "name": "xero-node",
            "version": "20.0.0",
            "seenAt": "2026-10-08T16:35:22.141327565Z"
          },
          {
            "registry": "pypi",
            "name": "xero-python",
            "version": "15.2.0",
            "released": "2026-09-04",
            "seenAt": "2026-10-08T16:35:22.946932673Z"
          }
        ],
        "githubStars": 372,
        "npmWeekly": 413652,
        "pypiWeekly": 70036,
        "securityTxt": {
          "url": "https://xero.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:41.602473738Z"
        },
        "domain": {
          "domain": "xero.com",
          "registered": "1997-06-03",
          "source": "https://rdap.verisign.com/com/v1/domain/xero.com",
          "checkedAt": "2026-10-04T13:09:35.716650808Z"
        },
        "pages": [
          {
            "url": "https://developer.xero.com/changelog/",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:23.322473763Z",
            "changedAt": "2026-10-08T18:17:23.322473763Z",
            "fingerprint": "83fa4ea02d9b"
          },
          {
            "url": "https://developer.xero.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:26.156777262Z",
            "changedAt": "2026-10-07T18:04:10.37666473Z",
            "fingerprint": "10b42d8abb1a"
          },
          {
            "url": "https://www.xero.com/uk/legal/privacy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:31:43.803758415Z",
            "changedAt": "2026-10-07T18:14:36.070598475Z",
            "fingerprint": "657febf361be"
          },
          {
            "url": "https://developer.xero.com/xero-developer-platform-terms-conditions/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:27.767450012Z",
            "changedAt": "2026-10-05T15:55:00.303495189Z",
            "fingerprint": "f6af5803e050"
          }
        ],
        "updatedAt": "2026-10-08T23:13:50.883918534Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Codat Limited",
        "b": "Xero",
        "name": "Vendor"
      },
      {
        "a": "https://api.codat.io",
        "b": "https://api.xero.com/api.xro/2.0",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "OAuth",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Codat's Master Services Agreement. The documentation repository codatio/codat-docs is Apache-2.0",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "none",
        "b": "51",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-01",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "2022-09-05",
        "b": "2025-12-04",
        "name": "Terms last updated"
      },
      {
        "a": "2025-04-01",
        "b": "2025-02-11",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "2.7k npm/wk, 222 PyPI/wk",
        "b": "350 stars, 395k npm/wk, 64k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Xero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics.",
        "question": "Which is better for AI agents, Codat or Xero API + MCP?"
      },
      {
        "answer": "Codat needs an API key. Xero API + MCP uses an OAuth sign-in.",
        "question": "Do Codat and Xero API + MCP need an API key?"
      },
      {
        "answer": "Yes. Codat has a hosted endpoint at https://api.codat.io and Xero API + MCP at https://api.xero.com/api.xro/2.0.",
        "question": "Can an agent call Codat and Xero API + MCP without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 80 against 68",
          "Agent ergonomics, 81 against 75"
        ],
        "also": null,
        "goodFor": "Banks, lenders, bill pay, expense and card products that already have or will sign a Codat contract and need writes into many accounting packages.",
        "slug": "codat",
        "watchFor": "No public price. The pricing page returns 404 and fees are set in an order form"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 64 against 49",
          "Payments \u0026 pricing, 35 against 10"
        ],
        "also": [
          "Runs on your own machine"
        ],
        "goodFor": "An agent keeping the books for UK, Australian or New Zealand businesses, or any team that wants read-only scopes and long deprecation notice.",
        "slug": "xero",
        "watchFor": "Developer docs, including the per-minute rate limits, only render with JavaScript"
      }
    ],
    "job": {
      "capability": "accounting.ledger",
      "name": "Accounting ledger"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/apideck-accounting-vs-xero.json",
        "title": "Apideck Accounting API + MCP vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/apideck-accounting-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-freeagent.json",
        "title": "Codat vs FreeAgent API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-freeagent"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-freshbooks.json",
        "title": "Codat vs FreshBooks API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-freshbooks"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-odoo.json",
        "title": "Codat vs Odoo External API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-odoo"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-quickbooks-online.json",
        "title": "Codat vs QuickBooks Online API + MCP",
        "url": "https://www.anchorterminal.com/compare/codat-vs-quickbooks-online"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-zoho-books.json",
        "title": "Codat vs Zoho Books",
        "url": "https://www.anchorterminal.com/compare/codat-vs-zoho-books"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freeagent-vs-xero.json",
        "title": "FreeAgent API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/freeagent-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freshbooks-vs-xero.json",
        "title": "FreshBooks API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/freshbooks-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/merge-accounting-vs-xero.json",
        "title": "Merge Accounting API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/merge-accounting-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/odoo-vs-xero.json",
        "title": "Odoo External API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/odoo-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/quickbooks-online-vs-xero.json",
        "title": "QuickBooks Online API + MCP vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/quickbooks-online-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/rutter-vs-xero.json",
        "title": "Rutter Accounting API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/rutter-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/xero-vs-zoho-books.json",
        "title": "Xero API + MCP vs Zoho Books",
        "url": "https://www.anchorterminal.com/compare/xero-vs-zoho-books"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-invoice-ninja.json",
        "title": "Codat vs Invoice Ninja API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-invoice-ninja"
      },
      {
        "json": "https://www.anchorterminal.com/compare/invoice-ninja-vs-xero.json",
        "title": "Invoice Ninja API vs Xero API + MCP",
        "url": "https://www.anchorterminal.com/compare/invoice-ninja-vs-xero"
      },
      {
        "json": "https://www.anchorterminal.com/compare/apideck-accounting-vs-codat.json",
        "title": "Apideck Accounting API + MCP vs Codat",
        "url": "https://www.anchorterminal.com/compare/apideck-accounting-vs-codat"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-merge-accounting.json",
        "title": "Codat vs Merge Accounting API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-merge-accounting"
      },
      {
        "json": "https://www.anchorterminal.com/compare/codat-vs-rutter.json",
        "title": "Codat vs Rutter Accounting API",
        "url": "https://www.anchorterminal.com/compare/codat-vs-rutter"
      }
    ],
    "scores": [
      {
        "by": 12,
        "codat": 80,
        "edge": "codat",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16,
        "xero": 68
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "codat": 77,
        "edge": "xero",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13,
        "xero": 79
      },
      {
        "by": 6,
        "codat": 81,
        "edge": "codat",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13,
        "xero": 75
      },
      {
        "by": 15,
        "codat": 49,
        "edge": "xero",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14,
        "xero": 64
      },
      {
        "by": 25,
        "codat": 10,
        "edge": "xero",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10,
        "xero": 35
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "codat": 75,
        "edge": "xero",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7,
        "xero": 76
      },
      {
        "by": 1,
        "codat": 71,
        "edge": "xero",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7,
        "xero": 72
      }
    ],
    "summary": "Xero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics. Both do accounting ledger.",
    "verdicts": {
      "codat": "Public OpenAPI specs, an Idempotency-Key header on writes, Retry-After on 429 and a written three-month deprecation notice suit an agent that retries. Access is the limitation. No price or self-serve signup is published, the general Accounting API is closed to new clients, and API keys carry no scopes.",
      "xero": "Granular OAuth scopes, such as accounting.reports.profitandloss.read, required for apps created from 29 April 2026. Developer docs, including the per-minute rate limits, only render with JavaScript."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/codat-vs-xero",
    "json": "https://www.anchorterminal.com/compare/codat-vs-xero.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/codat-vs-xero.md",
    "slim": "https://www.anchorterminal.com/compare/codat-vs-xero.min.md"
  },
  "markdown": "Xero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics. Both do accounting ledger.\n\n- Codat: grade B, 64.3/100, rank #280 of 722. Markdown https://www.anchorterminal.com/tools/codat.md · JSON https://www.anchorterminal.com/api/v1/tools/codat.json\n- Xero API + MCP: grade B, 67.2/100, rank #213 of 722. Markdown https://www.anchorterminal.com/tools/xero.md · JSON https://www.anchorterminal.com/api/v1/tools/xero.json\n\n## Which one, for what\n\n### Codat (B)\n\nGood for: Banks, lenders, bill pay, expense and card products that already have or will sign a Codat contract and need writes into many accounting packages.\n\nAhead on:\n- Reliability, 80 against 68\n- Agent ergonomics, 81 against 75\n\nWatch for: No public price. The pricing page returns 404 and fees are set in an order form\n\n### Xero API + MCP (B)\n\nGood for: An agent keeping the books for UK, Australian or New Zealand businesses, or any team that wants read-only scopes and long deprecation notice.\n\nAhead on:\n- Security \u0026 auth, 64 against 49\n- Payments \u0026 pricing, 35 against 10\n\nAlso in its favour:\n- Runs on your own machine\n\nWatch for: Developer docs, including the per-minute rate limits, only render with JavaScript\n\n\n## Score by category\n\n| Category | Weight | Codat | Xero API + MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 68 | Codat +12 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 79 | Xero API + MCP +2 |\n| Agent ergonomics | 13% (16.2 this run) | 81 | 75 | Codat +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 49 | 64 | Xero API + MCP +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 10 | 35 | Xero API + MCP +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 75 | 76 | Xero API + MCP +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 72 | Xero API + MCP +1 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **64.3 · B** | **67.2 · B** | |\n\n## Facts side by side\n\n| Fact | Codat | Xero API + MCP |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Codat Limited | Xero |\n| Hosted endpoint | `https://api.codat.io` | `https://api.xero.com/api.xro/2.0` |\n| Transports | HTTP | HTTP, stdio |\n| Auth | API key | OAuth |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under Codat's Master Services Agreement. The documentation repository codatio/codat-docs is Apache-2.0 | MIT |\n| Tools exposed | none | 51 |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-10-01 | 2026-10-01 |\n| Terms last updated | 2022-09-05 | 2025-12-04 |\n| Privacy policy last updated | 2025-04-01 | 2025-02-11 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | yes |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 2.7k npm/wk, 222 PyPI/wk | 350 stars, 395k npm/wk, 64k PyPI/wk |\n| Agent reviews | none | 3.5/5 (2) |\n\n## Verdicts\n\n**Codat.** Public OpenAPI specs, an Idempotency-Key header on writes, Retry-After on 429 and a written three-month deprecation notice suit an agent that retries. Access is the limitation. No price or self-serve signup is published, the general Accounting API is closed to new clients, and API keys carry no scopes.\n\n**Xero API + MCP.** Granular OAuth scopes, such as accounting.reports.profitandloss.read, required for apps created from 29 April 2026. Developer docs, including the per-minute rate limits, only render with JavaScript.\n\n## Before you call either\n\n### Codat\n\n1. Send `Authorization: Basic \u003cbase64 of the API key\u003e` to https://api.codat.io. The Portal shows the ready-made header value\n2. Send a new GUID as `Idempotency-Key` on every POST and PATCH, and reuse the same key when retrying after a 429\n3. Treat writes as asynchronous on most APIs. Keep the push operation key and wait for the `{dataType}.write.successful` or `.unsuccessful` webhook\n4. Call the Get model (options) endpoint for the connection before a create or update, because required fields differ by accounting package\n5. Filter with `query=modifiedDate\u003e...` and keep `pageSize` at 100. The daily quota is 1,000 requests times one plus the number of active connected companies\n\n### Xero API + MCP\n\n1. Send xero-tenant-id on every call. The token alone doesn't name the organisation\n2. A bill is an Invoice with Type ACCPAY, a sales invoice is ACCREC. There's no separate bills endpoint\n3. Send an Idempotency-Key on creates so a retry after a timeout doesn't post twice\n4. Use If-Modified-Since and pageSize up to 100 to stay inside 1,000 calls a day on Starter\n5. Set XERO_SCOPES to read scopes only when the agent shouldn't write. The MCP still lists its write and delete tools\n\n## Questions\n\n### Which is better for AI agents, Codat or Xero API + MCP?\n\nXero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics.\n\n### Do Codat and Xero API + MCP need an API key?\n\nCodat needs an API key. Xero API + MCP uses an OAuth sign-in.\n\n### Can an agent call Codat and Xero API + MCP without installing anything?\n\nYes. Codat has a hosted endpoint at https://api.codat.io and Xero API + MCP at https://api.xero.com/api.xro/2.0.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/codat-vs-xero.json, and with the fewest tokens: https://www.anchorterminal.com/compare/codat-vs-xero.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"codat\", \"b\": \"xero\"}`. From a terminal: `anchor compare codat xero`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/codat.json and https://www.anchorterminal.com/api/v1/tools/xero.json\n\n## Other comparisons with Codat or Xero API + MCP\n\n- [Apideck Accounting API + MCP vs Xero API + MCP](https://www.anchorterminal.com/compare/apideck-accounting-vs-xero.md)\n- [Codat vs FreeAgent API](https://www.anchorterminal.com/compare/codat-vs-freeagent.md)\n- [Codat vs FreshBooks API](https://www.anchorterminal.com/compare/codat-vs-freshbooks.md)\n- [Codat vs Odoo External API](https://www.anchorterminal.com/compare/codat-vs-odoo.md)\n- [Codat vs QuickBooks Online API + MCP](https://www.anchorterminal.com/compare/codat-vs-quickbooks-online.md)\n- [Codat vs Zoho Books](https://www.anchorterminal.com/compare/codat-vs-zoho-books.md)\n- [FreeAgent API vs Xero API + MCP](https://www.anchorterminal.com/compare/freeagent-vs-xero.md)\n- [FreshBooks API vs Xero API + MCP](https://www.anchorterminal.com/compare/freshbooks-vs-xero.md)\n- [Merge Accounting API vs Xero API + MCP](https://www.anchorterminal.com/compare/merge-accounting-vs-xero.md)\n- [Odoo External API vs Xero API + MCP](https://www.anchorterminal.com/compare/odoo-vs-xero.md)\n- [QuickBooks Online API + MCP vs Xero API + MCP](https://www.anchorterminal.com/compare/quickbooks-online-vs-xero.md)\n- [Rutter Accounting API vs Xero API + MCP](https://www.anchorterminal.com/compare/rutter-vs-xero.md)\n- [Xero API + MCP vs Zoho Books](https://www.anchorterminal.com/compare/xero-vs-zoho-books.md)\n- [Codat vs Invoice Ninja API](https://www.anchorterminal.com/compare/codat-vs-invoice-ninja.md)\n- [Invoice Ninja API vs Xero API + MCP](https://www.anchorterminal.com/compare/invoice-ninja-vs-xero.md)\n- [Apideck Accounting API + MCP vs Codat](https://www.anchorterminal.com/compare/apideck-accounting-vs-codat.md)\n- [Codat vs Merge Accounting API](https://www.anchorterminal.com/compare/codat-vs-merge-accounting.md)\n- [Codat vs Rutter Accounting API](https://www.anchorterminal.com/compare/codat-vs-rutter.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Codat vs Xero API + MCP",
        "url": ""
      }
    ],
    "description": "Xero API + MCP scores 67.2 (B) on agent readiness against Codat's 64.3 (B), and leads in 5 of 7 scored categories. Codat leads on reliability and agent ergonomics. Both do accounting ledger. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Codat B 64.3",
      "Xero API + MCP B 67.2",
      "scores"
    ],
    "h1": "Codat vs Xero API + MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-codat-vs-xero.png",
    "path": "/compare/codat-vs-xero",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Codat vs Xero API + MCP for AI agents, B 64.3 vs B 67.2",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/codat-vs-xero"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 630
  },
  "version": 1
}
