Sound familiar?
- Web orders are re-keyed into Xero every morning
- The Xero app you installed posts a daily summary, but your accountant wants line detail
- Stripe payouts never match anything in the Xero bank feed
- Your bespoke system doesn't know when a Xero invoice has been paid
- An old integration broke and needs updating for Xero's granular scopes
- Tracking categories and VAT rates are applied by guesswork
Key facts
- We use the Xero Accounting API with OAuth 2.0; access tokens expire after 30 minutes and refresh tokens rotate on every use
- Xero allows 60 API calls per minute and 5 concurrent calls per connected organisation
- Daily call limits per organisation depend on the app's Xero developer tier: 1,000 on Starter and Core, 5,000 on Plus and above
- Xero's tiered developer pricing took effect on 2 March 2026; a single business connecting its own organisation usually fits the Starter tier
- Apps created from 2 March 2026 must request granular scopes such as accounting.invoices instead of the old accounting.transactions scope
- We verify Xero webhooks using the x-xero-signature HMAC header
- Fixed-price quote after a free chat; you own the code
What a custom Xero integration does
Xero has a large app marketplace, and if one of those apps fits your process exactly, use it. We build custom Xero integrations when it doesn't: when your sales come from a bespoke system, when you need line-level detail with specific account codes, when invoices must be split across companies, or when your own software needs to know the moment a customer pays.
A typical build creates or updates the Xero contact, raises the sales invoice with the right account code, tax type and tracking category for each line, records payments and refunds against it, and issues credit notes for cancellations. It's the same job we did with KashFlow and OpenCart years ago, using Xero's modern API.
The Xero API in practice
Some specifics that shape every Xero build:
- OAuth 2.0. Your Xero admin authorises the connection once. Access tokens expire after 30 minutes. Each refresh returns a new refresh token, and the old one stops working, so the integration must store the new token safely every time. If a refresh fails to save, Xero's developer blog notes a 30-minute grace period for retrying with the previous token. We build this carefully because a lost refresh token means someone has to reconnect.
- Tenants. One connection can cover several Xero organisations. Each request carries a
xero-tenant-idheader, which is useful for groups with more than one company. - Rate limits. Xero allows 60 calls per minute and 5 concurrent calls per organisation. The daily limit depends on the app's developer tier: Xero's pricing page lists 1,000 calls per day per organisation on Starter and Core and 5,000 on Plus and above. We batch invoices (Xero accepts many in one request), use the
If-Modified-Sinceheader to fetch only changes, and queue work when we approach a limit. - Granular scopes. Xero is replacing the broad
accounting.transactionsscope with narrower ones likeaccounting.invoicesandaccounting.payments. New apps from 2 March 2026 must use them; older apps must move over before the broad scopes are withdrawn in September 2027, and users need to re-authorise. - Webhooks. Xero sends webhooks for changes to contacts and invoices, signed with an HMAC-SHA256 signature in the
x-xero-signatureheader. We verify each one before acting on it.
Xero's 2026 developer pricing and what it means for you
Xero moved to tiered developer pricing on 2 March 2026, with Starter, Core, Plus, Advanced and Enterprise tiers based on the number of connected organisations and the volume of data pulled out of Xero. According to Xero's developer pricing page, Starter has no monthly fee and allows up to five connections. Xero's updated developer terms also prohibit using data from its APIs to train AI or machine learning models.
For most of our clients, a custom integration connects one business, or a small group, to its own Xero organisations, so it sits within Starter. The 1,000-calls-per-day limit on that tier is the bigger design constraint. A busy shop posting every order individually, then checking each payment, can reach it. We design around it by batching, by posting daily summaries for retail sales where your accountant is happy with that, and by using webhooks instead of polling. If your volumes need a higher tier, we'll tell you during scoping, before you commit.
Typical Xero integrations we build
- Shopify, WooCommerce or OpenCart to Xero, with refunds, discounts, shipping and gift cards mapped properly. See Shopify integration.
- Stripe to Xero, posting payments to a Stripe clearing account and fees as expenses, so payouts match the bank feed exactly.
- Bespoke billing to Xero, such as subscription or usage billing raising invoices and receiving payment status back. Our automated billing software work started with energy usage invoicing.
- CRM to Xero, turning won deals into invoices and showing outstanding balances to the sales team. See CRM integration.
- Multi-company groups, routing each sale to the right Xero organisation.
Xero handles your Making Tax Digital VAT submissions itself. Our job is to make sure every transaction arrives with the correct tax type so the return is right first time.
How we work
After a free chat, we scope the integration against Xero's free demo company, so development never touches your live books. You get a fixed-price quote. We build, test against the demo company, then connect to your organisation and run in parallel with your current process until the figures agree. You own the code, and it's documented so any developer can maintain it.
Comparing packages, or connecting more than Xero? See accounting software integration and our main API integration page.
What we deliver
- A Xero mapping agreed with your accountant: account codes, tax types, tracking categories, branding themes
- OAuth 2.0 connection flow with encrypted token storage and automatic refresh
- Contact, invoice, credit note and payment sync into Xero
- Webhook listener for invoice and contact changes, so your system knows when Xero changes
- Payment and fee posting that reconciles against your bank feed
- A sync log with retry controls and email alerts
How it works and what it costs
Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data.
Free chat
Tell us the problem in plain English: what you do now, what goes wrong and what "better" looks like. No charge, no obligation.
Scoping
We map the processes, systems and data involved, agree what is in and out, and write it down so there are no surprises.
Fixed-price quote
You get a fixed price for the agreed scope, or a phased plan for bigger builds, so you can start small and prove it works.
Build and test
We build in short stages you can see and try, test against real data, then go live carefully with a rollback plan.
Hand over and look after
You own the code and the data. We can host it, support it and keep improving it, or hand it to your own team.
Frequently asked questions
Do we have to pay Xero for API access?
Possibly, but usually not for a single business. Since 2 March 2026 Xero charges developers by tier. Starter has no monthly fee and allows up to five connected organisations, which covers most custom integrations for one business or a small group. dijitul developments checks which tier applies during scoping.
What are the Xero API rate limits?
Xero allows 60 calls per minute and 5 concurrent calls per connected organisation. The daily limit per organisation depends on the developer tier: 1,000 calls on Starter and Core, 5,000 on Plus and above, according to Xero's developer pricing page. dijitul designs integrations to batch and queue work to stay within these limits.
Will our Xero integration keep working when someone changes their password?
Yes. The integration uses OAuth 2.0 tokens, not a password, so password changes don't affect it. The connection only needs reauthorising if the token is revoked, the connecting user loses access, or Xero requires new scopes, as with its move to granular scopes. dijitul builds alerts so you know straight away.
Our old Xero integration has stopped working. Can you fix it?
Usually. Common causes are refresh tokens not being stored after rotation, deprecated scopes, or a developer app that was never moved to the right tier. dijitul developments can audit the existing code, fix it or rebuild it, and add logging so the next problem is visible immediately.
Can you post Stripe payments to Xero so they reconcile?
Yes. dijitul posts each Stripe payment to a clearing account in Xero, records Stripe's fees as an expense, and records each payout as a transfer to your bank account. The bank feed line then matches the payout exactly, and refunds and disputes are handled the same way.
Can one integration connect to several Xero organisations?
Yes. A single OAuth 2.0 connection can be authorised for several Xero organisations, and each API request specifies which one it is for. dijitul uses this for groups that route sales to different companies, or businesses with separate trading entities.
Related
Tell us what you need to build
Free chat, clear scope, fixed-price quote. You own everything we build.