# Connect Xero

Create a Xero OAuth app and register `https://app.bakedbrie.com/settings/destinations/oauth/callback`. Give BakedBrie the client ID and pass its secret through `prepare_secret`. Select only the operations needed. Default reads request `offline_access`, `accounting.invoices.read`, `accounting.payments.read` and `accounting.contacts.read`. A payment write needs `accounting.payments`; invoice create or void needs `accounting.invoices`. Deprecated broad `accounting.transactions` scopes are not in this preset.

A person follows `connect_oauth`. Xero may list several organizations; that person chooses the right one in BakedBrie. The connection pins its `tenant_id`, and every call sends it as `xero-tenant-id` only to `api.xero.com`. Read the invoice `type`: `ACCREC` is an invoice sent to a customer; the unpaid list may also include bills. `contact.email` can address an approved draft. BakedBrie cannot use Xero's invoice email endpoint.

Xero does not charge per call, but the **app's developer tier** limits calls per organization per day. Starter apps begin with five connections and 1,000 calls per organization per day; higher tiers differ. Xero uses granular scopes for new and existing web apps since March 2026. Xero webhook events can make cards after a person enters the signing secret and daily cap in the web app. Source: [Xero auth flow](https://developer.xero.com/documentation/guides/oauth2/auth-flow), [scopes](https://developer.xero.com/documentation/guides/oauth2/scopes), [limits](https://developer.xero.com/documentation/guides/oauth2/limits), read 2026-09-29.
