X
Xero Identity API
Details
Authentication
Xero OAuth 2.0 app (client ID/secret for Auth Code or PKCE; yields bearer access tokens, optional refresh tokens) oauth2 discovered Set up OAuth ↗
Create an app in the Xero Developer Centre and choose the appropriate grant type. For standard web-server OAuth, select Auth Code; Xero assigns a client_id and lets you generate a client_secret in the app settings. For native/public apps, use the PKCE flow instead. Send users to Xero authorization, exchange the code at https://identity.xero.com/connect/token, then call GET https://api.xero.com/connections to discover authorized tenantId values. Request offline_access if you need refresh tokens.