Prowl
65/100
prowl
Benchmarked Oct 02, 2026

Xero OAuth 2 Identity Service API

These endpoints are related to managing authentication tokens and identity for Xero API

authidentityapi platform_profile Streaming
Benchmark Your API

Score Breakdown

Latency9/10
Consistency8/10
Parseability8/10
Documentation7/10
Error Clarity6/10
Token Efficiency6/10
First-Try Success5/10
Auth Simplicity4/10

Benchmark Analysis Log

Full LLM thinking from the 4-phase benchmark pipeline.

Analyze
{
  "service_type": "platform",
  "base_url": "https://developer.xero.com",
  "auth_method": "oauth2",
  "auth_config": {
    "authorization_url": "https://login.xero.com/identity/connect/authorize",
    "token_url": "https://identity.xero.com/connect/token",
    "revocation_url": "https://identity.xero.com/connect/revocation",
    "scopes": [
      "openid",
      "profile",
      "email",
      "offline_access",
      "accounting.transactions",
      "accounting.contacts",
      "accounting.settings",
      "projects",
      "payroll.employees",
      "payroll.payruns",
      "payroll.timesheets",
      "payroll.settings",
      "assets",
      "files",
      "bankfeeds"
    ],
    "grant_types": [
      "authorization_code",
      "refresh_token",
      "client_credentials"
    ],
    "pkce_supported": true,
    "token_type": "Bearer",
    "access_token_ttl_seconds": 1800,
    "refresh_token_ttl": "60 days rolling",
    "discovery": {
      "openid_configuration": "https://identity.xero.com/.well-known/openid-configuration"
    }
  },
  "endpoints": [],
  "pricing_model": {
    "type": "freemium",
    "details": {
      "api_access": "Included with Xero subscription for app owners; free for developers creating apps",
      "partner_program": "Additional partner-level access available on application",
      "notes": "API consumption is not separately metered; usage governed by rate limits and fair-use policies"
    }
  },
  "rate_limits": {
    "concurrent_limit": "5 concurrent calls per connection",
    "minute_limit": "60 calls per minute per tenant",
    "daily_limit": "5000 calls per day per tenant",
    "app_minute_limit": "10000 calls per minute across all tenants for a single app (varies by app tier)",
    "notes": "Rate limits vary by API surface (Accounting, Payroll, Assets, Projects, Files). Exceeding limits returns HTTP 429 with Retry-After header."
  },
  "capabilities": [
    "OAuth 2.0 authorization code flow with PKCE",
    "OIDC-based identity (openid, profile, email scopes)",
    "Token issuance, refresh, and revocation",
    "Multi-tenant connections via /connections endpoint",
    "Tenant selection and disconnection management",
    "Scoped access to Xero accounting, payroll, projects, assets, and files APIs",
    "App-level client credentials for machine-to-machine integrations",
    "OpenID Connect discovery document"
  ],
  "raw_analysis": "Xero's OAuth 2 Identity Service is the authentication and authorization layer that fronts all Xero public APIs (Accounting, Payroll, Projects, Assets, Files, Bank Feeds). It is not a standalone platform product but rather the identity plane for the broader Xero ecosystem — a cloud accounting platform used primarily by small and medium businesses, their accountants, and bookkeepers across AU, NZ, UK, US, CA, and other regions.\n\nMaturity: Xero is a publicly listed company (ASX: XRO) with a long-standing, well-documented developer program at developer.xero.com. The identity service implements standard OAuth 2.0 and OpenID Connect, so it benefits from the maturity of those specs and broad library support.\n\nKey operational facts for integrators:\n- Two token endpoints: authorization at login.xero.com/identity/connect/authorize and token/refresh at identity.xero.com/connect/token.\n- Access tokens are short-lived (30 minutes) and refresh tokens rotate (rolling 60-day expiry), so clients must persist and refresh proactively.\n- Connections are per-tenant: after the OAuth flow, apps call GET https://api.xero.com/connections to enumerate authorised tenants; each tenant has its own rate limit bucket.\n- Rate limits are tiered per tenant and per app; 429s with Retry-After are expected under load.\n- Developer access is free; production app access requires Xero approval, and deeper partner capabilities (e.g., larger limits, partner tooling) require the Xero Partner Program.\n\nWho it's for: SaaS vendors building accounting integrations, ERP/e-commerce connectors, banks and fintechs (bank feeds), payroll providers, and internal engineering teams at SMBs/accounting firms.\n\nIntegration surface: OIDC discovery is available for metadata-driven clients. Well-supported SDKs and community libraries exist in .NET, Java, Node, Python, PHP, Ruby, Go, and others, largely maintained by Xero or the community.\n\nCaveats: No public REST endpoints are exposed on the identity service itself beyond token, revocation, connections, and discovery; the domain developer.xero.com is a documentation/portal site, not an API base. Actual API calls go to api.xero.com. Rate limits and scope availability differ by product area and by partner tier, so integrators should consult product-specific docs before assuming a scope works." 
}
Execute

2/3 tests passed

TestEndpointStatusLatency
website_uptimeGET /200308ms
robots_txtGET /robots.txt200129ms
llms_txtGET /llms.txt404105ms
Interpret
{
  "overall": 62,
  "dimensions": {
    "token_efficiency": 6.5,
    "first_try_success": 5.0,
    "response_parseability": 8.0,
    "error_clarity": 6.0,
    "doc_quality": 7.0,
    "auth_simplicity": 4.5,
    "latency": 9.2,
    "consistency": 7.5
  },
  "pricing_normalized": {
    "model": "freemium",
    "api_access_included_with_subscription": true,
    "separate_api_metering": false,
    "developer_access": "free",
    "notes": "API consumption governed by rate limits; no per-call pricing"
  },
  "issues": [
    "Auth requires OAuth 2.0 authorization code flow with PKCE — agents cannot self-onboard; a human must complete the consent dance in a browser",
    "No llms.txt (404) — reduced agent-discoverability and no machine-friendly doc index",
    "No security headers detected on responses (has_security_headers: false) — potential trust/compliance flag",
    "Long-form value prop spans Xero accounting, payroll, projects, assets, files — harder to compress into a crisp one-line pitch for users",
    "No visible self-serve 'sign in with Notlogin' or agent-native onboarding path"
  ],
  "recommendations": [
    "Publish an llms.txt and/or OpenAPI-as-llms.txt to improve agent discoverability and token-efficient doc discovery",
    "Add a machine-readable quickstart (e.g. /agents or /llms.txt) summarizing the OAuth flow, scopes, and connection lifecycle",
    "Consider a device-code or agent-delegated consent pattern so autonomous agents can onboard without a full browser round-trip",
    "Add security headers (HSTS, CSP, X-Content-Type-Options) to raise trust signals for agent-recommended platforms",
    "Provide a compact, single-page value-prop summary (one sentence per API surface) to boost token efficiency for agent descriptions"
  ]
}

Agent Readiness

x402 Payments
Not supported
Streaming
Yes
Sandbox
None
Agent Auth
Unknown
SDKs
None listed
MCP Support
No

Embed your Prowl badge

Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.

Prowl agent-readiness badge
<a href="https://prowl.world/service/xero-oauth-2-identity-service-api">
  <img src="https://prowl.world/badge/xero-oauth-2-identity-service-api.svg" height="56" alt="Agent-readiness on Prowl">
</a>

Options: ?style=light|dark · ?size=sm|md · ?variant=certified (claimed + DNS-verified only) · badge generator with preview

Want the full interactive view?

See operational metrics, LLM evaluations, agent readiness, and more.

Open in Dashboard