.png)
Xero Integration Guide
Connect Xero accounting data with enterprise applications through REST APIs, OAuth 2.0, selected webhook notifications, and Martini workflows.
Xero integration options at a glance
Xero's principal integration mechanism is its REST-based Accounting API, which exposes contacts, invoices, payments, accounts, bank transactions, reports, attachments, and related accounting resources over JSON and HTTPS. Xero also provides OAuth 2.0 authorization with refresh tokens, tenant-specific access, and granular scopes. Selected resources support webhook-style notifications, although coverage is not universal. Martini can consume Xero APIs, receive and validate webhook requests, retrieve authoritative resource state, paginate through collections, map financial data, and orchestrate scheduled or event-driven workflows. Collection-style operations and attachment endpoints support targeted batch and file-processing scenarios, while reporting APIs provide structured access without direct database connectivity.
Common Xero integration patterns
Common Xero data objects used in integrations
Authentication and security considerations
OAuth 2.0 and tenant authorization
Xero API access uses OAuth 2.0, refresh tokens, client credentials, granular product scopes, and authorization to one or more Xero organizations called tenants.
- Store client secrets and refresh tokens in Martini secrets or secure environment configuration.
- Keep tenant identifiers and authorization state separate for multi-organization deployments.
- Request only the accounting, contacts, attachments, or other product scopes required by the workflow.
- Protect exposed webhook endpoints and validate Xero webhook signatures before processing.
Controlled access
Martini can expose normalized APIs with its own authentication and authorization controls, reducing the need for downstream consumers to manage Xero credentials directly.
Operational considerations for Xero integrations
Rate limits and pagination
Xero applies API rate limits, and large collections such as Invoices, Contacts, and Payments must be processed page by page. Use throttling, bounded retries with backoff, and checkpoints for high-volume tenants.
Webhook reliability
Webhook notifications can be duplicated or arrive out of order. Validate signatures, deduplicate by event and resource identifiers, retrieve current resource state, and use scheduled reconciliation because webhook coverage is selective.
Financial data quality
Preserve Xero statuses, tenant context, currencies, tax values, account codes, rounding behavior, and source identifiers. Do not translate accounting states without explicit business rules.
Schema, testing, and recovery
Isolate Xero-specific mappings, monitor API changes and deprecations, test authorization and representative accounting states, and route authorization failures, validation errors, rate limits, and duplicate conflicts separately.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration instead of isolated scripts
Martini provides a maintainable workflow layer for OAuth-protected API calls, webhook intake, pagination, mapping, business rules, target writes, and reconciliation. This keeps Xero-specific behavior explicit without duplicating integration logic across scripts.
Reusable integration assets
Teams can expose normalized APIs, reuse workflow logic, and isolate tenant configuration, mappings, and error policies. Martini can combine scheduled and event-driven processing when Xero webhook coverage is incomplete.
Operational control
Centralized checkpoints, idempotency, retry handling, logs, and monitoring make it easier to operate accounting integrations than a collection of point-to-point jobs. Custom logic can be added when vendor-specific transformation or validation requires it.