| name | xero-mcp-connector |
| description | MCP connector for Xero accounting – enables AI-powered bookkeeping, invoicing, and financial management through Claude |
| license | Proprietary/API |
| tags | ["business","accounting","mcp","xero","finance"] |
| difficulty | intermediate |
| time_to_master | 4-8 weeks |
| version | 1.0.0 |
Xero MCP Connector
Overview
This skill enables Claude to interact with Xero through the Model Context Protocol (MCP). It provides a bridge between Claude's AI capabilities and Xero's REST API (OAuth 2.0), allowing natural language control of Xero operations, intelligent automation, and AI-powered assistance for Xero workflows.
When to Use This Skill
- Invoice and bill creation via natural language
- Bank feed reconciliation assistance
- Financial report generation
- Contact and organization management
- Payroll processing and reporting
Architecture
┌─────────────┐ ┌─────────────────┐ ┌──────────────────┐
│ Claude │────▶│ MCP Server │────▶│ Xero │
│ (Client) │◀────│ (TypeScript) │◀────│ (REST API (OAut)│
└─────────────┘ └─────────────────┘ └──────────────────┘
Core Concepts
MCP Server Setup
The connector implements an MCP server that exposes Xero operations as tools Claude can invoke. The server translates natural language intentions into REST API (OAuth 2.0) calls.
Key Endpoints/Interfaces
/api.xro/2.0/Invoices, /api.xro/2.0/Contacts, /api.xro/2.0/Accounts, /api.xro/2.0/Reports
Implementation
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StdioServerTransport } from "@modelcontextprotocol/sdk/server/stdio.js";
import { z } from "zod";
const server = new McpServer({
name: "xero-mcp-connector",
version: "1.0.0",
});
server.tool(
"list_resources",
"List and query Xero resources with optional filters",
{
query: z.string().optional().describe("Search query or filter"),
limit: z.number().optional().describe("Max results to return"),
},
async ({ query, limit }) => {
const response = await fetch(`${BASE_URL}/api.xro/2.0/Invoices`, {
headers: { "Authorization": `Bearer ${API_KEY}` },
});
const data = await response.json();
return {
content: [{ type: "text", text: JSON.stringify(data, null, 2) }],
};
}
);
server.tool(
"create_resource",
"Create a new resource in Xero",
{
name: z.string().describe("Resource name"),
config: z.object({}).passthrough().optional().describe("Resource configuration"),
},
async ({ name, config }) => {
const response = await fetch(`${BASE_URL}/api.xro/2.0/Invoices`, {
method: "POST",
headers: {
"Authorization": `Bearer ${API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({ name, ...config }),
});
const data = await response.json();
return {
content: [{ type: "text", text: `Created: ${JSON.stringify(data)}` }],
};
}
);
server.tool(
"analyze",
"AI-powered analysis of Xero data",
{
type: z.string().describe("Analysis type"),
timeframe: z.string().optional().describe("Time range for analysis"),
},
async ({ type, timeframe }) => {
const response = await fetch(`${BASE_URL}/api.xro/2.0/Invoices`, {
headers: { "Authorization": `Bearer ${API_KEY}` },
});
const data = await response.json();
return {
content: [{ type: "text", text: JSON.stringify(data, null, 2) }],
};
}
);
const transport = new StdioServerTransport();
await server.connect(transport);
Claude Desktop Configuration
{
"mcpServers": {
"xero-mcp-connector": {
"command": "node",
"args": ["path/to/xero-mcp-connector/index.js"],
"env": {
"XERO_API_KEY": "your-api-key",
"XERO_BASE_URL": "https://your-instance-url"
}
}
}
}
Best Practices
- Authentication: Store API keys securely using environment variables; never hardcode credentials
- Rate Limiting: Implement request throttling to respect Xero API rate limits
- Error Handling: Provide clear, actionable error messages for common failure scenarios
- Pagination: Handle paginated responses for large datasets efficiently
- Caching: Cache frequently accessed read-only data to reduce API calls
- Security: Validate all inputs before passing to the Xero API; sanitize outputs
- Logging: Log all API interactions for debugging and audit purposes
Example Prompts
"Reconcile all pending bank transactions and generate an aged receivables report"
Security Considerations
- All API credentials must be stored as environment variables
- Implement input validation and sanitization for all tool parameters
- Use HTTPS for all API communications
- Follow the principle of least privilege for API token permissions
- Audit log all write operations for compliance tracking
Resources
Changelog
| Version | Date | Changes |
|---|
| 1.0.0 | 2026-04-01 | Initial MCP connector skill |
Part of SkillGalaxy - 10,000+ comprehensive skills for AI-assisted development.