# How to Connect Your Website to Xero

Source: https://dijituldevelopments.co.uk/guides/connect-your-website-to-xero/
Updated: 2026-10-10

> You connect a website to Xero either with a ready-made connector app or with a custom integration using the Xero API, which uses OAuth 2.0 to create contacts, invoices and payments automatically. dijitul builds custom Xero integrations for UK businesses, quoted at a fixed price after a free chat.

## Key facts

- The Xero Accounting API uses OAuth 2.0; access tokens last 30 minutes and are renewed with refresh tokens
- Xero limits each connected organisation to 60 API calls a minute and 5,000 a day
- Xero webhooks can notify your system when contacts or invoices change
- Since 2 March 2026 Xero charges app developers by tier, based on connections and data egress
- Common syncs: contacts, invoices, payments, credit notes, items and tracking categories
- dijitul has built accounting integrations since the KashFlow and OpenCart days

## Two routes: a connector app or a custom integration

**Connector apps** from the Xero App Store link popular platforms (Shopify, WooCommerce, Stripe) to Xero for a monthly fee. If your website is on a mainstream platform and your process is standard, start there.

**A custom integration** makes sense when the app does not support your platform, posts data in a way your accountant dislikes, cannot handle your rules (trade accounts, deposits, split VAT, tracking categories by branch) or when the website is bespoke. It talks directly to the Xero Accounting API and does exactly what you need.

## How a Xero API integration works

- **Authorisation.** Someone with access to the Xero organisation approves the connection through Xero's OAuth 2.0 screen. The integration receives an access token, which lasts 30 minutes, and a refresh token used to get new ones. Tokens must be stored securely and refreshed reliably, or the sync silently stops.
- **Mapping.** Website customers become Xero contacts, orders become invoices or receipts, products map to item codes and account codes, and VAT rates map to Xero tax types. Agree this mapping with your accountant first.
- **Sending data.** When an order is paid, the integration creates or updates the contact, raises the invoice and records the payment against the right bank account.
- **Receiving changes.** Xero webhooks can notify your system when invoices or contacts change, so your website can show paid status or updated account details.
- **Error handling.** Failed calls are logged, retried and flagged to a person, never just dropped.

## Limits and rules to design around

- **Rate limits.** Xero allows 60 calls a minute and 5,000 a day per connected organisation, with a cap on concurrent requests. A busy shop should batch invoices and queue work (for example with Redis-backed queues in Laravel) rather than calling Xero on every page view.
- **Idempotency.** If a call times out, the retry must not create a second invoice. Store Xero's IDs against your orders and check before creating.
- **Developer pricing.** From 2 March 2026 Xero moved app developers to tiered plans based on the number of connected organisations and data egress, published at developer.xero.com/pricing. A private integration for one business normally sits in the smallest tier, but check the current rules when planning.
- **Locked periods.** Once your accountant locks a period, backdated changes will be rejected. The integration needs a sensible way to handle that.

## What to sync, and what not to

Sync the documents your accountant needs and nothing more. Usually that means contacts, sales invoices or receipts, payments, refunds as credit notes and, for stock businesses, item codes. Leave stock control in the system that runs your warehouse unless Xero is genuinely the master. Decide which system "owns" each field, so two systems do not overwrite each other. For card payments, settlement fees and payouts need their own treatment; our Shopify accounts guide covers the same issue.

## A typical order-to-Xero flow, step by step

To make the mechanics concrete, here is how a well-built integration usually handles a paid web order:

- The customer pays. Your payment provider confirms it, ideally by a signed webhook, not just the customer landing on a thank-you page.
- Your website records the order as paid and adds a job to a queue, rather than calling Xero while the customer waits.
- A background worker picks up the job and checks whether the customer already exists in Xero, matching on a stored Xero ContactID, then email address. It creates or updates the contact.
- It creates the invoice with line items, account codes, tax types and any tracking categories (for example sales channel or branch), using the order number as the reference so it can be found later.
- It records the payment against the invoice, using the bank or clearing account agreed with your accountant.
- It stores the Xero InvoiceID against the order. If the job is retried, the stored ID stops a duplicate being created.
- If anything fails (an expired token, a locked period, a rate limit), the job waits and retries. After a set number of failures it alerts a named person with a readable message.

Refunds follow a similar path, creating a credit note allocated against the original invoice. Daily, a reconciliation job compares orders and Xero records and lists any differences. This structure is what separates an integration finance can trust from one they quietly double-check by hand.

## When to talk to dijitul

dijitul has built accounting integrations since around 2011, including a full KashFlow and OpenCart integration that created customers, raised invoices on payment, synced stock and prices and issued credit notes for cancelled orders. Today we build Xero integrations for bespoke websites, ecommerce shops and web apps. Every project starts with a free chat and gets a fixed-price quote. You own the code. Tell us what you want to connect.

## FAQs

### Can I connect my website directly to Xero?

Yes. Either install a connector app from the Xero App Store, if one supports your platform, or build a custom integration with the Xero Accounting API. dijitul builds custom integrations when apps do not fit, quoted at a fixed price after a free chat.

### What are the Xero API rate limits?

Xero allows 60 API calls per minute and 5,000 per day for each connected organisation, plus a limit on concurrent requests. Well-built integrations batch and queue requests so a busy day does not hit the limit.

### Does the Xero API cost money?

Since 2 March 2026 Xero charges app developers through tiered plans based on connected organisations and data egress, as set out at developer.xero.com/pricing. A single-business integration usually falls in the smallest tier, but check the current terms during scoping.

### Why does my Xero integration keep disconnecting?

Usually a token problem. Xero access tokens last 30 minutes and refresh tokens expire if not used regularly, so an integration that does not refresh reliably, or stores tokens badly, will drop its connection. Logging and alerts catch this early.

### Should orders go into Xero as invoices or receipts?

It depends on how you are paid and what your accountant prefers. Prepaid web orders often post as paid invoices with a payment, while account customers get unpaid invoices. Agree the treatment with your accountant before anything is built.

### Can dijitul fix an existing Xero integration?

Yes. dijitul can audit an integration that duplicates invoices, misses payments or disconnects, then fix it or rebuild the weak parts. It starts with a free chat and a fixed-price quote for the work.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
