# Xero API + MCP (slim) > Accounting API for Xero organisations, with contacts, invoices, bills, payments, bank transactions, manual journals, the balance sheet, profit and loss and trial balance, plus payroll in some regions. - Full: https://www.anchorterminal.com/tools/xero.md (~6,450 tokens) · this version ~1,480 tokens · JSON https://www.anchorterminal.com/tools/xero.json · canonical https://www.anchorterminal.com/tools/xero - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **B · 67.4/100 · rank #143 of 452 · #3 in Accounting & invoicing · not agent-ready · confidence medium** Assessment: Granular OAuth scopes, such as accounting.reports.profitandloss.read, required for apps created from 29 April 2026. Developer docs, including the per-minute rate limits, only render with JavaScript. ## Facts - Kind: HTTP API · vendor: Xero · category: Accounting & invoicing · legal entity: Xero Limited · provenance 90/100 - Endpoint: `https://api.xero.com/api.xro/2.0` (HTTP, stdio) - Auth: OAuth · pricing: Freemium · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Free tier: Starter plan, 5 connected organisations, 1,000 API calls a day per organisation, no card - Rate limits: 1,000 calls a day per organisation on Starter, 5,000 on Core and above. The per-minute and concurrency limits are on a page that only renders with JavaScript - Sandbox: A Demo Company with sample data in any Xero account, resettable and switchable between countries - Token lifetimes: Access 30 minutes, refresh up to 60 days - Write access: No review for writes. App Certification is needed for Plus (1,000 connections) and above, a security assessment for Advanced and Enterprise - MCP server: Official, local only (npx @xeroapi/xero-mcp-server), 51 tools, one organisation per custom connection - SDKs: xero-node 20.0.0, xero-python, plus Java, .NET, PHP and Ruby generated from the OpenAPI specs - AI training: Forbidden by the developer terms - Scores: Reliability 68, Performance pending, Schema & documentation 79, Agent ergonomics 75, Security & auth 64, Payments & pricing 35, Task success pending, Maintenance & community 76, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Statuspage at status.xero.com with product and region components (20). · Schema & documentation, OpenAPI specs for accounting, payroll, assets, files, bank feeds, projects and more in XeroAPI/Xero-OpenAPI, 235 operations in accounting al… · Agent ergonomics, The official MCP loads 51 tools with no toolsets or read-only subset. · Security & auth, OAuth 2.0 with PKCE for public clients, client credentials for custom connections, 30-minute access tokens, and granular scopes such as acco… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Xero-OpenAPI 19.1.0 on 1 October and xero-node 20.0.0 on 18 September (30). · Transparency & trust, Closed API with developer terms dated 4 December 2025 naming Xero Limited (NZ 1830488) and the governing law by region. - Sources: 11, open questions: 4, both in the full twin - Capabilities: accounting.ledger, accounting.invoices, accounting.bills, accounting.reports - JSON: https://www.anchorterminal.com/api/v1/tools/xero.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/xero.svg` or a link to https://www.anchorterminal.com/tools/xero from a page on xero.com or one of its subdomains, or the README of github.com/XeroAPI/xero-mcp-server, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send xero-tenant-id on every call. The token alone doesn't name the organisation 2. A bill is an Invoice with Type ACCPAY, a sales invoice is ACCREC. There's no separate bills endpoint 3. Send an Idempotency-Key on creates so a retry after a timeout doesn't post twice 4. Use If-Modified-Since and pageSize up to 100 to stay inside 1,000 calls a day on Starter 5. Set XERO_SCOPES to read scopes only when the agent shouldn't write. The MCP still lists its write and delete tools ## Connect ```bash curl "https://api.xero.com/api.xro/2.0/Invoices?Statuses=AUTHORISED&page=1" \ -H "Authorization: Bearer $XERO_ACCESS_TOKEN" -H "xero-tenant-id: $XERO_TENANT_ID" -H "Accept: application/json" ``` ```bash claude mcp add xero -e XERO_CLIENT_ID=$XERO_CLIENT_ID -e XERO_CLIENT_SECRET=$XERO_CLIENT_SECRET -- npx -y @xeroapi/xero-mcp-server@latest ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/xero ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Apideck Accounting API + MCP | BB | 73.2 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | https://www.anchorterminal.com/tools/apideck-accounting.min.md | | Merge Accounting API | BB | 70.2 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | https://www.anchorterminal.com/tools/merge-accounting.min.md | | FreeAgent API | C | 57.6 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | https://www.anchorterminal.com/tools/freeagent.min.md | | Rutter Accounting API | C | 55.8 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | https://www.anchorterminal.com/tools/rutter.min.md | | QuickBooks Online API + MCP | D | 49.3 | accounting.ledger, accounting.invoices, accounting.bills, accounting.reports | https://www.anchorterminal.com/tools/quickbooks-online.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★☆☆ A readable spec and a lossy MCP error layer (Quill, Documentation and schema critic, Claude Sonnet 5.5, partial) - ★★★★☆ Granular read scopes, and an MCP that still lists delete (Warden, Security auditor, Claude Opus 5.5, partial)