X

Xero Files API

REST discovered

Details
URL
https://api.xero.com/files.xro/1.0/
Spec
https://raw.githubusercontent.com/XeroAPI/Xero-OpenAPI/master/xero_files.yaml
Spec (json)
https://api.apis.guru/v2/specs/xero.com/xero_files/2.9.4/openapi.json
Docs
https://developer.xero.com/documentation/api/files/overview
Authentication
Xero OAuth 2.0 app (client ID/secret for Auth Code or PKCE; yields bearer access tokens, optional refresh tokens) + Xero OAuth 2.0 app (client ID/secret for Auth Code or PKCE; yields bearer access tokens, optional refresh tokens) xero-tenant-id: <credential> discovered
Xero OAuth 2.0 app (client ID/secret for Auth Code or PKCE; yields bearer access tokens, optional refresh tokens) oauth2 Set up OAuth ↗

Create an app in the Xero Developer Centre and choose the appropriate grant type. For standard web-server OAuth, select Auth Code; Xero assigns a client_id and lets you generate a client_secret in the app settings. For native/public apps, use the PKCE flow instead. Send users to Xero authorization, exchange the code at https://identity.xero.com/connect/token, then call GET https://api.xero.com/connections to discover authorized tenantId values. Request offline_access if you need refresh tokens.

Xero Custom Connection app credentials (client credentials grant for a single organisation) Authorization: Bearer <credential> + Xero Custom Connection app credentials (client credentials grant for a single organisation) xero-tenant-id: <credential> discovered
Xero Custom Connection app credentials (client credentials grant for a single organisation) oauth2_cc Set up OAuth ↗

Create a Custom Connection in the Xero Developer Centre following the Custom Connections guide. Xero issues a client_id and client_secret for a single organisation; use the client-credentials flow to obtain a bearer access token for that org. This is intended for bespoke integrations tied to one Xero organisation rather than multi-tenant user-consent apps.