Skip to main content

Xero API pricing, limits and integration: a 2026 guide

By Syed Husnain Khalid · Published 6 October 2026 · Last checked 8 October 2026 · 10 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

Since 2 March 2026 Xero prices API access by tier: Starter is free for up to 5 connected organisations, and Core costs $35 AUD a month for up to 50. Each organisation allows 60 calls a minute, 5 at once and 1,000 to 5,000 a day. Xero exempts bespoke integrations built for your own practice or a single client.

This guide is for UK accounting practices, and the developers they hire, planning an integration with their clients’ Xero organisations. Two things changed in 2026. On 2 March Xero replaced its revenue-share model with five priced tiers, and its updated Developer Terms now ban using API data to train AI models. The sections cover what the API is, how access and connections work, who pays and who is exempt, the tier prices and requirements, the rate limits and what happens when you hit one, and which records an integration can write as drafts for a person to approve.

What is the Xero API?

The Xero API is the set of interfaces that lets an app read and write data in a Xero organisation, such as contacts, invoices and bank transactions. Xero calls each account an app connects to a tenant: a Xero organisation, a Xero Practice Manager account or a XeroHQ practice (Xero tenants guide).

The Accounting, Payroll and Files APIs work within the context of an organisation tenant. The Xero developer platform, sometimes called Xero Developer, is where you register the app, choose its tier and see its usage.

How does Xero API access work?

Xero API access uses OAuth 2.0: a user signs in to Xero, approves your app’s requested scopes and chooses which tenants it may reach (Xero authorisation flow). Scopes are the permissions an app requests, such as accounting.invoices.

Your app then receives an access token that lasts 30 minutes. A refresh token, issued only if the app requests the offline_access scope, lasts 60 days and lets the app renew access without the user signing in again.

Each authorised tenant becomes one connection. If three users connect your app to the same organisation, only one connection counts towards your limit. So 60 client organisations connected to a practice’s integration are 60 connections. A connection stays active indefinitely, even with no API calls, until one of six things happens: the user disconnects the app, the user loses access to the tenant, the connection is deleted through the connections endpoint, the token is revoked, the tenant is deleted, or you delete the app.

Practices have two extra rules. Each organisation or practice can connect a maximum of five uncertified apps; certified apps have no limit (Xero API limits). Cashbook and ledger organisations, Xero’s partner edition plans, must be authorised by a member of the practice staff, because the managed client and cashbook client roles cannot authorise an API connection.

Who pays Xero’s API fees, and who is exempt?

App developers pay Xero’s API fees, but Xero excludes five types of app from the 2026 pricing model, “all as determined by Xero” (Xero pricing FAQ, question 6):

  • bespoke integrations for accountants and bookkeepers built for your own practice or a single client;
  • Custom Connections, which remain on the same commercial terms;
  • financial services apps in banking, credit and payments that operate on different commercial contracts;
  • conversion partners, apps that solely convert data from other accounting platforms into Xero;
  • franchise apps built specifically for franchise networks.

The first exemption covers the integration this guide is about. The tiers below apply to apps you distribute to other firms, and to any app Xero decides does not qualify. Xero’s FAQ does not say how the exemption treats one practice-owned integration that connects many client organisations, so ask Xero to confirm it in writing before you plan around it. The new Developer Terms apply to every app, exempt or not.

A Custom Connection is a separate option: a premium integration that connects to a single Xero organisation, for which the client pays an additional monthly subscription. It is available for UK organisations, cannot be used with Xero Practice Manager or XeroHQ, and does not count towards the five uncertified apps.

How much does the Xero API cost in 2026?

From 2 March 2026 the Xero API costs a flat monthly fee per tier, from free on Starter to $1,445 AUD on Advanced, set by the number of connections and the data your app downloads (Xero pricing). Xero calls that download “egress”. Prices are in Australian dollars and exclude tax.

TierMonthly fee (AUD, excl. tax)Connections (max)Egress included per monthCalls per organisation per day
StarterNo charge5Not applicable1,000
Core$355010 GB5,000
Plus$2451,00050 GB5,000
Advanced$1,44510,000250 GB5,000
EnterprisePrice on applicationNo limitVolume on application5,000

Egress above the allowance costs $2.40 AUD per GB on Core, Plus and Advanced (FAQ question 10). The allowance resets on the first of each calendar month (UTC), which is also the billing cycle. Calls to the organisation endpoint are excluded from egress, and Xero measures a GB as a gibibyte (230 bytes). Data sent into Xero (ingress) is unlimited on every tier.

Connections and egress are counted per app: two apps from the same developer cannot share them. Xero takes payment by credit card only, on the first of the following month. Disconnecting inactive client organisations lowers your connection count.

What does each Xero API tier require?

Each tier above Starter adds a requirement: a payment method from Core, App Certification from Plus (Xero’s FAQ also lists Core), and a security assessment from Advanced. New apps start on Starter, and adding a sixth connection requires payment details, which moves the app to Core (FAQ question 24).

Xero API tiers and what each one requiresFive Xero API tiers from 2 March 2026. Starter: up to 5 connections, no charge, no payment method, the default for new apps. Core: up to 50 connections, $35 AUD a month, payment method required. Plus: up to 1,000 connections, $245 AUD, App Certification required, App Store listing optional. Advanced: up to 10,000 connections, $1,445 AUD, security assessment required, adds the Journals endpoint, Xero Practice Manager API and Bulk Connections. Enterprise: no connection limit, price on application, App Store listing required. A bespoke integration built for your own practice or a single client is exempt from this model, as Xero determines.Starter5 connections, freeCore50, payment methodPlus1,000, certificationAdvanced10,000, securityassessmentEnterpriseNo limit, App Storelisting
Moving up a tier means applying and meeting its requirements; connections are capped at the tier maximum until you do.

Xero’s plan table lists App Certification under Plus, Advanced and Enterprise and leaves Core blank, while FAQ question 22 names Core, Plus, Advanced and Enterprise. Ask Xero which applies before you move past Starter. Advanced and Enterprise require a security assessment, initial and annual. A Xero App Store listing is not available on Starter and Core, optional on Plus and Advanced, and required on Enterprise (FAQ question 19).

Three premium features need the Advanced tier, a security assessment and use-case approval: the Journals endpoint, the Xero Practice Manager (XPM) API and Bulk Connections, which lets one user connect many client organisations in a single authorisation (FAQ question 20). Manual journals are a different endpoint and stay available on every tier (FAQ question 7). Rapid Sync, which lifts the standard limits for the first 30 minutes of a new connection, is for certified apps.

If your connections grow mid-month, you must apply to move up and meet the next tier’s requirements; until then connections are capped at your tier’s maximum (FAQ question 14). You can ask Xero support to move down a tier twice a year.

What are the Xero API rate limits?

Xero API rate limits apply per connected organisation: 5 calls in progress at once, 60 calls a minute and 1,000 (Starter) or 5,000 calls a day, plus 10,000 calls a minute for the app across all organisations (Xero API limits). The limits are the same for every app, and Xero does not raise them on request (Xero limits FAQ).

LimitValueApplies to
Concurrent limit5 calls in progress at one timeEach organisation
Minute limit60 calls per minuteEach organisation
Daily limit1,000 (Starter) or 5,000 (Core and above) calls per dayEach organisation
App minute limit10,000 calls per minuteThe app, across all organisations
Request size10 MB maximum; Xero suggests batches of up to 50 itemsEach request

Integrations stay inside these limits by design:

  • Subscribe to webhooks instead of polling. Xero sends events for six categories: Contact, Credit Note, Invoice, Overpayment, Prepayment and Subscription.
  • Send the If-Modified-Since header so Xero returns only records changed since the last sync.
  • Page through invoices, credit notes, contacts, bank transactions and manual journals, 100 records at a time.
  • Create several invoices in one request instead of one call each.
  • Read the X-DayLimit-Remaining, X-MinLimit-Remaining and X-AppMinLimit-Remaining headers on every response.

Each organisation’s limit is separate: two client organisations each get their own 5,000 calls a day on Core.

What happens when you hit a Xero API rate limit?

Xero returns HTTP 429 (too many requests) with an X-Rate-Limit-Problem header naming the limit you reached. For the minute and daily limits it also sends a Retry-After header giving the seconds to wait (Xero API limits).

Xero counts requests in a fixed window that resets at a different time for each organisation, so pause calls to that organisation only and resume when Retry-After says. A 429 for the concurrent or app-wide limit carries no Retry-After: lower the number of parallel calls instead. Large extracts belong in a queue, which is what Xero recommends so no one expects an immediate response.

What can a Xero integration write as a draft?

Through the API, an integration can create sales invoices, bills and manual journals as drafts, but not bank transactions. Drafts create no journals and stay out of reports until a person approves them in Xero (Xero invoices API).

RecordStatuses a new record can haveCan a person approve it in Xero first?
Sales invoices (ACCREC) and bills (ACCPAY)DRAFT, SUBMITTED or AUTHORISEDYes: DRAFT is the default
Manual journalsDRAFT or POSTEDYes
Bank transactions (spend and receive money)AUTHORISED or DELETEDNo: review before the API call

The status lists come from Xero’s status codes, the manual journals API and Xero’s OpenAPI specification. The bank transactions endpoint also gives no access to bank statements or bank feeds. So an integration that turns statement lines into spend or receive money entries needs its review step in the integration, before anything is sent to Xero.

Which Xero integrations do practices build?

Practices build Xero integrations where their own workflow falls between the apps they already use. If an app on the Xero App Store already does the job, use it.

WorkflowWhat the integration doesWhere a person signs off
Document intakeAI reads receipts and supplier bills, checks totals, and creates draft billsIn Xero, before a bill is approved
Bank statement linesReads statement data and prepares spend or receive money entriesIn the integration, before anything is sent
Client onboardingForm answers create the Xero contact and the practice record togetherEngagement and ID checks
Cross-client reportingPulls figures from every connected organisation into one viewBefore reports go to clients

Log which document produced which entry, who approved it and what they changed. That gives you an audit trail and real human involvement in each entry. If an AI-assisted step ever makes a significant decision about a person, one with a legal or similarly significant effect, UK GDPR Article 22A treats it as solely automated unless the human involvement is meaningful; our guide to human in the loop AI under Article 22Aexplains that test. Xero’s Developer Terms add one AI rule of their own: data obtained through the API may not be used to train or contribute to any AI or machine learning model (FAQ question 4).

Statement lines become bank transactions, which cannot be drafts, so the checks in bank statement extraction software: checks for accountants apply before any bank transaction reaches Xero. The review gates for every AI use in a practice are in AI for accountants in the UK: safe uses and review steps, and our Xero integration servicesbuild these integrations at £900–2,000 per integration, fixed in writing before we start. Prices exclude VAT; Xero’s own API fees are separate.

A one-page brief for your developer

  1. The workflow, step by step, and who does each step today.
  2. Whether the integration serves only your practice or a single client (Xero’s exemption), and if not, how many client organisations will connect now and in a year.
  3. Which data moves, in which direction, how often, and roughly how much you download each month.
  4. Which records Xero receives as drafts, and where a person reviews records that cannot be drafts.
  5. What gets logged, and for how long.
  6. Who owns the Xero developer account and the code. It should be your practice.

Frequently asked questions

Does Xero charge for API access?

It depends on the app. Since 2 March 2026 Starter has been free for up to 5 connected organisations and Core costs $35 AUD a month for up to 50. Xero exempts bespoke integrations built for an accountant's own practice or a single client, as Xero determines.

What counts as a Xero API connection?

Each Xero organisation that authorises your app is one connection. Several users connecting the same organisation still count as one.

How many Xero API calls can we make per day?

Per organisation, 1,000 a day on Starter and 5,000 on Core and above, with 60 calls a minute and 5 at once. The app as a whole is limited to 10,000 calls a minute.

Can an integration post straight to the ledger?

Yes for bank transactions, which the API only creates as authorised. Invoices, bills and manual journals can be sent as drafts so a person approves them in Xero first.

What is the difference between a Custom Connection and an app?

A Custom Connection links to one Xero organisation, the client pays a monthly subscription for it, and it stays on its existing commercial terms. An app uses OAuth 2.0 and can connect to many organisations.

Sources

  1. Xero Developer: Pricing
  2. Xero Developer: Pricing and policy updates FAQ (questions 3–27)
  3. Xero Developer: OAuth 2.0 API limits
  4. Xero Developer: Limits FAQ
  5. Xero Developer: Xero tenants and connections
  6. Xero Developer: OAuth 2.0 authorisation flow
  7. Xero Developer: Custom Connections
  8. Xero Developer: Invoices API (invoice status codes)
  9. Xero Developer: Bank transactions API
  10. Xero Developer: Accounting API types (bank transaction status codes)
  11. Xero Developer: Manual journals API
  12. Xero Developer: Webhooks overview
  13. Xero: Xero-OpenAPI accounting specification
  14. UK GDPR Article 22A (legislation.gov.uk)

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.