Skip to main content

Xplan and Intelliflo APIs: what advice firms can integrate

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 8 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

Xplan and intelliflo both publish documentation you can read without an account. Iress’s public Swagger reference lists 57 paths and 99 operations, but credentials come from its Integrations Team. intelliflo’s portal documents its v2 API and limits of 5,000 calls a day, and asks for a GitHub login to create an App. Neither publishes a price.

This guide is for UK advice firms that run Xplan or intelliflo and want their own tools to read and write client records. The two vendors publish different amounts: Iress publishes the reference and gates its guidance behind a sign-in, while intelliflo documents endpoints and rate limits openly and asks for a GitHub account before you can build. Both are third-party arrangements whose risk a firm is expected to manage. Notice of a material outsourcing arrangement is already part of Principle 11, and from 18 March 2027 the FCA’s wider reporting rules apply to the firms it lists. The sections cover what each vendor publishes, access, limits, prices and the SYSC 8 questions to settle first.

How Xplan and intelliflo API access is obtainedFive steps from reading the public documentation to living with the connection: read what the vendor publishes, ask for access (Iress's Integrations Team for Xplan, a GitHub login for intelliflo), receive credentials (API key and Xplan build site URL, or App credentials), build the integration and have Iress approve it, then let the client enable it while the firm oversees the supplier under SYSC 8.Read the publicdocsSwagger and portalpagesAsk for accessIress team or GitHubGet credentialsAPI key and site URLBuild andapproveIress approves thebuildActivate andoverseeClient enables it;SYSC 8
Reading is open on both platforms. Credentials, approval and installation are not.

What are the Xplan and Intelliflo APIs?

Xplan’s API access comes through the Iress Open Standard, a productised subset of the wider Iress Xplan API that third-party integrators use to connect to Xplan sites; intelliflo’s access comes through the intelliflo Platform API, one resource-oriented domain at https://api.gb.intelliflo.net/v2 where version 2 is ready for production use.

The Iress Open Standard is real-time and bi-directional over Swagger-documented endpoints, and it supports GET, POST, PATCH and DELETE. A backend-for-frontend layer groups existing Xplan calls, so one request returns the fields several calls would otherwise return.

The standard services core Xplan fields rather than custom ones. The field groups in scope are:

  • Address, Goal, Asset, Liability, Client
  • Expense, Contact, Income, Dependant
  • Retirement Income, Document Note, Pension
  • Insurance Summary, Portfolio, Insurance Detail (General, Medical, Life)

The Overview also lists locale-specific fields such as Australian superannuation, and it flags Document Note and Portfolio as having some restrictions on which verbs are allowed.

The intelliflo Platform API covers the same kind of work on the other platform: you create an App, create credentials, and call resources under a single domain. Authentication uses OAuth 2.0 and OpenID Connect, and the portal’s home page asks you to “Login now with your GitHub account to access the documentation and start creating apps”.

What API documentation is public today?

Iress publishes a Swagger UI and its specification at api.iressopen.co.uk without a login, and intelliflo publishes its guides, API reference and rate limits on a portal that also reads without signing in.

What is publishedXplan (Iress Open Standard)intelliflo Platform API
Public API referenceSwagger UI and spec: 57 paths, 99 operations, 21 tagsPortal pages for the platform API, authentication and rate limits
Read without an accountYes. The spec’s own Getting Started and OAuth 2.0 links open an Iress sign-in pageYes today. The home page still asks for a GitHub login to create an App
How you get credentialsIress’s Integrations Team: API key, Xplan build site URL, Xplan username and password, Developer Community accessSign in with GitHub, create an App, then create credentials
AuthenticationBasic auth with your Xplan credentials, your integrator’s API key and the target site; oauth2 supportedOAuth 2.0 and OpenID Connect
Published rate limitNot published in the spec5,000 calls a day and 50 requests a second (unpublished App)
Price for API accessNot publishedNot published; higher limits follow Store publishing
Who approves and activatesIress approves the build; mutual clients enable it site by siteYou create your own App; limits rise after Store publishing
Data locationNot stated in the public specNot stated; the docs note that regional endpoints exist

The gap sits in the guidance, not the endpoints. The specification describes what each call accepts, but its links for Getting Started and OAuth 2.0 redirect to an Iress ID sign-in, and the forum behind them holds the walkthroughs. intelliflo is the other way round: the walkthroughs read openly, and the GitHub login gates creating the App whose credentials you need for a first call.

How does an advice firm get API access?

For Xplan you speak to Iress’s Integrations Team, who provide four things: an API key, an Xplan build site URL, an Xplan username and password, and access to the Iress Developer Community. For intelliflo you sign in with GitHub, create an App, then create credentials.

The specification points third parties at a web enquiry form and at the Integrations Team directly, and Developer Community access comes with the forum and the associated resources. intelliflo’s route is self-service: the Platform API page makes an App and its credentials the first two steps.

Approval and activation are separate steps. On Xplan, the integration is built and approved by Iress first, after which mutual clients enable it site by site. Iress states that it is not responsible for actively or extensively vetting third-party integrators, and that ownership of third-party due diligence sits with the client electing to activate the integration. On intelliflo, you create the App yourself, and publishing it to the Store is the stated prerequisite for limits above the standard tier.

How does authentication work on each platform?

The Iress specification declares three security schemes for its calls: basic authentication with your Xplan credentials, your integrator’s API key (x-xplan-app-id), and the target Xplan site to authorise against (x-forwarded-host). It also states that the standard integration supports OAuth 2.0.

intelliflo uses OAuth 2.0 and OpenID Connect, and the portal makes the choice of flow a step you read once your credentials exist: the authentication pages describe each option and the shape of application it suits.

Support on the Xplan side runs through the developer forum and Iress Connect. A production ticket should carry the specific time, the Xplan site URL, the name or first four characters of your API key, the error, and the x-Iress-RequestId header returned on the call.

What are the rate limits and what does access cost?

intelliflo publishes its limits: 5,000 calls a day and 50 requests a second for an unpublished App; a published App typically gets 10,000 and 100 if it targets one tenant, and 20,000 and 200 if it targets all tenants. The Iress specification publishes no rate limit at all.

App stateCalls per dayRequests per second
Unpublished App (standard)5,00050
Published, single tenant (typical)10,000100
Published, all tenants (typical)20,000200

intelliflo applies its limits to every call an application makes, including invalid or malformed requests, and returns HTTP 429 (Too Many Requests) when it detects too many. Increases depend on how many customers an App targets, and the portal asks you to discuss a usage-plan upgrade atdeveloper@intelliflo.com.

Neither vendor publishes a price for API access in its public API documentation. What is published instead are the contact routes: the Iress Integrations Team for connection details, and the intelliflo address above for a higher usage plan.

Which workflows are worth connecting?

Connect the workflows where staff re-type the same client data or assemble figures by hand: client record sync, document and note intake, cashflow and goals reporting, and onboarding data.

WorkflowWhat the integration doesWhere a person signs off
Client record syncReads and writes client, contact and address fields between your tools and the platformBefore a record is created or changed in the platform
Document and note intakeFiles documents and notes against the right client recordBefore anything is filed as a client record
Cashflow and goals reportingPulls goal, income and liability data into one viewBefore figures reach a client or a file
Onboarding dataCreates client, consent and contact records from the form answersIdentity and suitability checks

Nothing should reach the platform without the approval step you design. Where AI drafts a record or a note, a person signs off on it, and the log of what was produced, who approved it and what changed is the evidence that the step was real.

How does SYSC 8 apply to an API connection?

SYSC 8.1.1R requires a common platform firm that relies on a third party for operational functions critical for its relevant services and activities to take reasonable steps to avoid undue additional operational risk. It also applies as a rule to MiFID optional exemption firms (SYSC 1 Annex 1, Table B), a status many advice firms hold. SYSC 8.1.1A says other firms should take account of the rule as if it were guidance.

The FCA defines outsourcing as an arrangement where a service provider performs a process, service or activity on behalf of a firm which the firm would otherwise carry out itself, and notes that third parties can also provide services that are not classed as outsourcing. FG16/5 puts the responsibility plainly: firms “cannot delegate any part of this responsibility to a third party”, so due diligence happens before the decision, not after. That matches the Iress position on integrator vetting, and it is the same check our FCA outsourcing rules (SYSC 8) guide works through for any supplier.

Notice already exists. SUP 15.3.8G treats giving the FCA notice of entering into, or significantly changing, a material outsourcing arrangement as part of compliance with Principle 11. From 18 March 2027 the FCA’s third-party reporting rules add a wider duty for the firms they list: tell the FCA when you enter into or significantly change a material third-party arrangement, and report annually by submitting a register. Other firms keep their existing obligations, for example under Principle 11.

Under those rules an arrangement is material where its disruption or failure could:

  • cause intolerable levels of harm to the firm’s clients
  • pose a risk to the soundness, stability, resilience, confidence or integrity of the UK financial system
  • cast serious doubt on the firm’s ability to satisfy the threshold conditions, or to meet its obligations under the Principles, or under SYSC 15A (Operational resilience)

The firms the rules list are enhanced-scope SMCR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK recognised investment exchanges, authorised electronic money institutions and authorised payment institutions, and consolidated tape providers.

Whatever the connection carries, it sits inside the software the firm runs day to day. Our AI software for financial advisers under Consumer Duty page explains how that system holds the evidence a board needs, and software for financial advisers is what we build. Where a vendor publishes everything openly, the same map looks different: see the Xero API pricing, limits and integration: a 2026 guide.

A one-page brief for your developer

  1. The workflow, step by step, and who does each step today.
  2. Which platform it runs on, and which of the two access routes you will use.
  3. The field groups the integration reads and writes, from the list above.
  4. How often data moves, in which direction, and what happens when a call fails.
  5. Where a person approves, and what they need to see to decide.
  6. The call volume you expect, against the published limits.
  7. Who owns the vendor account, the App and the code. It should be your firm.

Frequently asked questions

Can we read the Xplan API documentation without an Iress login?

Yes. The public Swagger reference and its specification open without an account and show 57 paths and 99 operations. The reference's own Getting Started and OAuth 2.0 links open an Iress sign-in page, and credentials come from the Integrations Team.

How many calls does intelliflo allow?

5,000 calls a day and 50 requests a second for an unpublished App. A published App targeting one tenant typically gets 10,000 a day and 100 a second, and one targeting all tenants typically gets 20,000 a day and 200 a second. Exceeding a limit returns HTTP 429.

Does Iress have to approve an Xplan integration?

Yes. The Iress Open Standard overview says an integration is built and approved by Iress, after which mutual clients enable it site by site. Iress also states that it is not responsible for actively or extensively vetting third-party integrators, and that due diligence sits with the client activating the integration.

Is an API connection outsourcing under SYSC 8?

It depends on what the connection does. The FCA defines outsourcing as a service provider performing a process, service or activity on behalf of a firm which the firm would otherwise carry out itself, and notes that other third-party services are not classed as outsourcing. SYSC 8.1.1R is a rule for common platform firms and for MiFID optional exemption firms (SYSC 1 Annex 1, Table B), and guidance for other firms under SYSC 8.1.1A.

What do we tell the FCA about the connection?

SUP 15.3.8G(1)(e) treats notice of entering into, or significantly changing, a material outsourcing arrangement as part of Principle 11. From 18 March 2027 the firms the FCA lists must report material third-party arrangements when they are entered into or significantly changed, and submit an annual register.

Sources

  1. FCA Handbook: SYSC 8.1 General outsourcing requirements
  2. FCA Handbook: SYSC 1 Annex 1 (detailed application of SYSC)
  3. FCA: Outsourcing and operational resilience
  4. FCA: Reporting material third party arrangements
  5. FCA FG16/5: Guidance for firms outsourcing to the cloud and other third-party IT services
  6. FCA Handbook: SUP 15.3 General notification requirements
  7. intelliflo developer platform: home
  8. intelliflo developer platform: Platform API
  9. intelliflo developer platform: Rate Limits
  10. Iress Open API 3.0 specification (Swagger)
  11. Iress Community: Iress Open Standard Overview

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.