A Lovable Xero integration is a first-party connector, live in the product since 28 July 2026, that lets an app you build with Lovable read and write real accounting data in one Xero organisation. It covers contacts, invoices, bills, payments and bank transactions, and reads the profit and loss, balance sheet and aged reports. Reports are read-only; the transactional endpoints are not.
That one paragraph already contradicts most of what ranks for this keyword. The guide sitting at the top of the results on the day of writing still explains how to proxy the Xero REST API through an edge function with OAuth 2.0 PKCE, which was the only route before the connector shipped and is now unnecessary work. Other pages call the connector read-only. It is not.
Everything below was verified in the browser on 10 October 2026: Lovable's connector documentation, the live Connectors catalogue inside a real Lovable workspace, Xero's developer pricing page, Xero's rate-limit documentation, the Xero Developer Platform Terms, and lovable.dev/pricing. Where Xero and Lovable say different things, both pages are quoted with their dates.
The Connector Is Real, Not Just Documented
This matters more than it sounds. A documentation page is not proof that a connector shipped. When MoneyFlock checked the QuickBooks connector on 9 October, the docs page returned a full guide while the live catalogue returned nothing for a QuickBooks search.
Xero behaves the opposite way. Searching a real workspace's Connectors catalogue for "xero" on 10 October 2026 returns a card titled Xero, described as "Connect accounting data from Xero", out of 142 connectors in the catalogue. It also appears in the Lovable changelog under 28 July 2026, announced alongside Google Analytics, and Xero's own developer blog published an introduction to the connector on 29 July 2026. Xero's main blog followed on 21 August with a post on custom app builders that says Xero "worked with Lovable on their new Xero Connector".
So there are three independent confirmations: the vendor's documentation, the vendor's product, and the data provider's own blog. That is the standard worth applying to every connector claim you read, including the ones in this series. The wider catalogue is mapped in the Lovable connectors guide for a finance stack.
What kind of connector it is
Xero is an app plus chat connector. One shared connection works in two places: inside the project chat while Lovable builds for you, and inside the app once it is published. You are not wiring one set of credentials for development and another for production. The connection reaches the single Xero organisation you pick during authorisation, and Lovable resolves its tenant ID for you.
You can create several Xero connections against different Xero apps or accounts, which is the normal way to keep a demo organisation separate from live books.
Read-Only or Read and Write? Settling the Disagreement
This is the question the ranking pages get wrong in both directions, and the answer is a split, not a verdict.
Lovable's Xero connector documentation, read on 10 October 2026, lists what an app can do. Three of the five capabilities are explicitly write capabilities:
- Read and manage contacts, including customers and suppliers
- Create, update and read sales invoices and bills
- Record and read payments and bank transactions
- Read organisation settings, currencies and tax rates
- Read financial reports such as profit and loss, balance sheet, and aged receivables and payables
Xero's own post, written by Corey Leung and published 29 July 2026, describes the same connector with one line that explains the split precisely: "Every permission is opt-in, and reports are always read-only." That is not a contradiction of Lovable's list. Xero is saying the report endpoints never write, which is true, while the transactional endpoints do.
The practical reading: your app can create a draft invoice in Xero. It cannot write a profit and loss statement back into Xero. Nothing in either source supports calling the whole connector read-only, and the top-ranked third-party guide's edge-function proxy is a workaround for a problem Lovable solved in July.
Where write access stops
Two published limitations are worth knowing before you design anything:
- No umbrella scopes. The connector cannot use Xero's broad accounting.transactions or accounting.reports.read scopes. You select granular scopes instead, which is stricter and better, but it means a scope you forgot is a feature your app silently cannot perform.
- No per-end-user Xero login. Each connection represents a single Xero account shared across every project linked to it. If the product you had in mind is a portal where each of your clients signs into their own Xero, this connector is the wrong tool and no amount of prompting changes that.
If authorisation is revoked on the Xero side, the connection has to be reconnected inside Lovable before any call succeeds again. Deleting a connection is permanent, removes the credentials from every linked project, and breaks whatever depended on it.
Setup: Three Traps Before You Write a Prompt
The connector does not give you a Lovable-hosted Xero app. You register your own, which means you inherit Xero's developer account, Xero's quotas and Xero's bill. Setup is short, and three specific things break it.
Trap one: the redirect URI has to be exact
In the Xero developer portal, create a Web app and set the OAuth 2.0 redirect URI to exactly this value:
https://api.lovable.dev/workspaces/connectors/standard/oauth/callback
Lovable shows the same string in a Redirect URI card with a copy button. A mismatch produces an "Invalid redirect_uri" failure at the Xero authorisation screen, not a helpful message inside Lovable. Then copy the client ID, a 32-character code, and generate a client secret.
Trap two: the March 2026 scope cut-off
This is the trap almost nobody writes about. Lovable's documentation states that Xero apps created after March 2026 support only granular scopes, and that Xero rejects the entire authorisation if Lovable requests a scope that is not enabled on the app. The error reads "Requested wrong apps scopes".
So the order matters. Enable every scope on the Xero app's Configuration page first, then select the matching scopes in Lovable. Doing it the other way round fails the whole handshake rather than degrading gracefully. The date lines up with Xero's wider developer platform change, which also took effect on 2 March 2026.
Trap three: the defaults are not the scopes you need
Four scopes are always included and cannot be removed. Several more are on by default. The rest are off, and two of the off-by-default ones matter for finance work. This is the table, read from the connector documentation on 10 October 2026:
For a receivables dashboard the defaults are enough. For anything that reconciles to a trial balance, or that needs to show the PDF attached to an invoice, you are turning scopes on in two places before it will work.
Who can create the connection, and the Enterprise surprise
App plus chat connectors are available by default on Free, Pro and Business. On Enterprise they are effectively switched off until an admin intervenes: the "Who can create connections and clients" control defaults to No one, and someone has to change it under Connectors, Admin settings, App plus chat connectors.
That is worth saying out loud because it reverses the usual assumption. Enterprise is not a superset of Business here, the same way it is not a superset on credit grants, a point covered in the Enterprise versus Business comparison. A new connection is also private to whoever created it until it is shared by email or offered to the whole workspace.
Xero Developer Pricing: The Bill Nobody Mentions
Lovable's documentation contains one sentence that every guide to this connector skips: "All API requests made through this connector run through your own Xero app and count toward Xero's rate limits. Billing and quota are handled directly by Xero, not Lovable."
Xero retired its revenue-share model and moved to flat developer plans on 2 March 2026. Prices are quoted in Australian dollars and exclude tax. Read from developer.xero.com/pricing on 10 October 2026, with approximate US dollars at the AUD to USD rate of 0.698 on the same day:
Three details decide whether this is free or not:
- Ingress is unlimited on every plan. Writing data into Xero does not consume the allowance. Only egress, meaning data you pull out, is metered, and the organisation endpoint is excluded because so many apps use it as a keep-alive.
- Overage is $2.40 AUD per gigabyte, roughly $1.67, on Core, Plus and Advanced. Allowances reset on the first of the calendar month in UTC and need a payment method on file.
- A connection is a connected Xero organisation. One company's own dashboard uses one. Starter covers five, free, forever, and a Starter app must add payment details before it can take a sixth, which moves it to Core.
There is a second cap that bites earlier than the price does. Each Xero organisation or practice can connect a maximum of five uncertified apps. Certified apps are unlimited. A bookkeeping practice that builds several internal tools on one client's books will hit that ceiling long before it hits a fee.
The Rate Limits That Decide Your Dashboard's Design
Xero's limits are per tenant, meaning per connected organisation, and they are low enough to shape the architecture rather than sit in the background. Read from Xero's OAuth 2.0 API limits page on 10 October 2026:
Every response carries X-DayLimit-Remaining, X-MinLimit-Remaining and X-AppMinLimit-Remaining. Breaching a limit returns HTTP 429 with an X-Rate-Limit-Problem header naming which one, plus a Retry-After header in seconds on the minute and daily limits. Xero's own guidance is to pause calls to that tenant until the Retry-After window passes rather than retry blindly.
Pagination compounds this. Listing invoices does not return line items, so the detail comes back 100 records at a time on invoices, credit notes, contacts, bank transactions and manual journals. A ledger with 4,000 open invoices is 40 calls just to walk the list, before anything else your dashboard does. On Starter's 1,000 calls a day that is fine once an hour and painful on every page load.
The design conclusion is unglamorous and correct: cache on a schedule, do not call Xero on render. Pull the aged receivables report and the invoice list into your app's own database on a timer, serve the dashboard from that, and show the reader when the data was last refreshed. Lovable's Cloud database and scheduled jobs both exist for exactly this, and jobs consume Cloud credits per run.
Two limits that produce confusing failures
First, the Journals endpoint is a premium feature available from the Advanced tier, along with the Xero Practice Manager API and Bulk Connections, each needing a security assessment and use-case approval. An app that works perfectly against invoices will simply not get journals on a free plan.
Second, and this one catches invoicing apps rather than dashboards: a Xero organisation on the Early plan can approve only 20 accounts receivable invoices and 5 accounts payable bills a month. Exceed it through the API and Xero returns HTTP 400 with the message "You have reached the limit of invoices you can approve." The limit belongs to the customer's Xero subscription, not to your app, so it will look like your code broke. Anyone building the invoice app pattern on top of Xero should handle that error by name.
One more for practices: on Xero partner editions such as cashbook and ledger organisations, only practice staff can authorise an API connection. The managed client and cashbook client roles cannot.
A Worked Aged Receivables Dashboard
The documentation's own first example prompt is a receivables dashboard, so that is the build. The prompt that starts it, from the connector page:
Use Xero and build a dashboard that shows open invoices, overdue balances, and aged receivables by customer.
Lovable will link the project to the connection and scaffold the app. The part no prompt gets right on its own is the arithmetic, so here it is worked by hand on a small ledger, as at 30 September.
Bucketed by due date, which is the only correct basis for an aged report: current $18,500; one to 30 days $17,200; 31 to 60 days $7,250; 61 to 90 days $31,000; over 90 days nil. Total receivables $73,950, of which $55,450 is overdue. That is 75.0 percent of the ledger past due, and a single customer, C, is 56 percent of the overdue balance.
The ageing basis is a real choice, not a detail
Bucket by invoice date instead and the picture changes for no good reason. Invoice 1041 was issued on 14 September on 30-day terms. By due date it is current. By invoice date it is 16 days old and lands in the one to 30 bucket, inflating what looks overdue by $18,500. Xero's own aged receivables report ages by due date. If your app offers both, label the toggle, and put the basis in the chart subtitle rather than in a tooltip.
Days sales outstanding, and the number that moves on you
DSO is receivables divided by credit sales for the period, times days in the period. On September sales of $96,000:
$73,950 divided by $96,000, times 30 days, is 23.1 days.
Now use a trailing three-month average instead. July $71,000, August $88,000, September $96,000, average $85,000:
$73,950 divided by $85,000, times 30 days, is 26.1 days.
Same ledger, same day, three days apart, purely because of the sales base. Neither is wrong. What is wrong is a dashboard that prints "DSO 23.1" with no indication of which it used, because the finance lead reading it will compare it to a figure calculated the other way and conclude collections improved. Put the method in the field label. The same discipline applies to runway in an investor update portal, where the choice of burn base moved the answer by more than a month.
What it costs to build
Lovable publishes example prompt costs of 0.50, 0.90, 1.20 and 1.70 credits, rising with how much work the message does. Build mode is usage-based, so a dashboard of this size is a handful of credits plus whatever iteration you do, not a fixed quote. Pro and Business both include 5 daily build credits that do not roll over and are not capped monthly, so spreading the build across a week costs materially less than doing it in one sitting. The full credit arithmetic is in the Lovable pricing breakdown.
The Clause That Changes What You Can Build
Xero updated its Developer Platform Terms alongside the pricing change, effective for new developers from 4 December 2025 and for everyone else from 2 March 2026. One clause reshapes AI projects built on Xero data, and it is not in any of the pages ranking for this keyword.
Clause 7(b)(i) of the Xero Developer Platform Terms and Conditions reads: "API Data cannot be used to train, fine tune, adapt, or enhance any AI Models." The introduction states the same prohibition in longer form, covering "machine learning tools, large language models or predictive analytics tools". Xero's own FAQ says the update "prohibits the use of data obtained through Xero's APIs to train" and describes the purpose as bolstering user trust and data security.
Clause 7(b)(ii) adds that "API Data shall not be passed to another third party without consent from the associated user", and clause 29 separately bars selling user data or aggregating and supplying it to another app or third party.
What that means in practice
Read plainly, this does not stop you using AI to build an app on Xero data, and it does not stop an app from summarising a ledger for the person who owns it. What it does stop is a product whose value comes from accumulating customers' Xero data into a model. It also makes the question "where does this data go and does that provider train on it" a contractual issue rather than a preference.
Three things to settle before you ship anything that sends Xero data to a model:
- Know your provider's training default. Lovable excludes workspace content from AI training by default on Business and Enterprise, not on Free or Pro. That default is now doing compliance work, not just privacy work. The full picture, including sub-processors and where prompts are processed, is in the data safety breakdown for Lovable.
- Get consent for anything leaving the app. Clause 7(b)(ii) is explicit that passing API data to a third party needs the associated user's consent, and a model provider is a third party.
- Keep aggregate reporting inside the customer's own scope. Benchmarking one client's figures against a pool built from other clients' Xero data is the pattern clause 29 is written to prevent.
None of this is legal advice and MoneyFlock is not a law firm; it is a prompt to read the clause and ask your own adviser, because a developer-terms breach costs an app its platform access rather than a fine. Worth noting alongside it: Xero ships its own AI toolkit, including an MCP server, an agents toolkit and a prompt library, and separately has an in-product AI assistant covered in this explainer on Xero's own AI agent. The ban is on training with API data, not on AI touching Xero at all.
Publishing Company Books: The Business Gate
A receivables dashboard shows customer names, amounts owed and payment behaviour. It should not be on a public URL, and on the lower plans it has no choice.
On Free and Pro, publishing is always external and website access cannot be restricted. Anyone with the link opens the app. Internal publish, the workspace-only audience, starts on Business at $50 a month for 100 credits, read from the pricing page logged out on 10 October 2026. Business also brings a team workspace, role-based access, SSO and the security centre.
The credit ladders were unchanged at this reading, the twenty-ninth in this series. Pro runs from 100 credits at $25 a month to 10,000 at $2,250. Business runs from 100 at $50 to 10,000 at $4,300.
One trap to plan around: after a downgrade from Business, the stored restriction keeps being enforced but you can no longer publish changes, with the message "Publish to workspace requires a Business plan". The app stays private and stays frozen. Business and Enterprise can also invite named viewers from outside the workspace, and a workspace can restrict those invites to verified domains.
Ready to build it, start on the Business plan, because that is the plan where company financials can be published to your workspace only. If you would rather not run the setup yourself, TJ's Lovable Expert directory profile is the place to start a conversation.
What the Whole Stack Costs
Two bills, not one, and the second is the one people forget.
For the single-company case, which is most readers, the honest answer is $50 a month and no Xero fee at all, as long as you stay inside five connected organisations and 1,000 API calls per organisation per day. Caching on a schedule is what keeps you there.
When Not to Use This Connector
- You need each end user to sign into their own Xero. Not supported. One connection equals one Xero account.
- You need journals, Xero Practice Manager data or bulk connections. Advanced tier, certification and a security assessment first.
- You need real-time events. The connector is request-driven. Xero webhooks exist, but not through this path.
- Your customer's Xero organisation is on the Early plan and your app creates invoices. Twenty approved sales invoices a month is a hard ceiling that your app will hit as an HTTP 400.
- Your product's value comes from training a model on accounting data. Clause 7(b)(i) closes that door.
- Your books live in a spreadsheet rather than Xero. Different connector, different article: the Excel connector route uses a live workbook as the backend instead.
For everything else, and especially for a single company that wants its receivables visible to the finance team without exporting to a spreadsheet every Monday, this is now a short build on a first-party connector rather than a week of OAuth plumbing. The wider verdict on the platform sits in the Lovable review for founders.
Frequently Asked Questions
Does Xero have API integration?
Yes. Xero exposes an accounting API over OAuth 2.0, and since 28 July 2026 Lovable has shipped a first-party connector that sits on top of it, so an app you build can reach contacts, invoices, bills, payments, bank transactions and the standard financial reports without you writing the OAuth flow yourself. You still register your own Xero app.
Is the Xero API free?
For small use, yes. Xero's Starter developer plan costs nothing and allows five connected organisations, with 1,000 API calls per day per organisation. It needs no app certification. You pay once you pass five connections or need more than 1,000 calls a day for a single organisation.
How much does Xero API usage cost?
From 2 March 2026, Core is $35 AUD a month for 50 connections and 10 GB of monthly egress, Plus is $245 AUD for 1,000 connections and 50 GB, and Advanced is $1,445 AUD for 10,000 connections and 250 GB. Egress beyond the allowance is $2.40 AUD per gigabyte. Prices exclude tax, and sending data into Xero is unlimited on every plan.
Can a Lovable app write to Xero, or is the connector read-only?
It writes. Lovable's documentation lists creating and updating sales invoices and bills, managing contacts and recording payments and bank transactions. The read-only part is narrower than people assume: Xero's own announcement says reports are always read-only, which covers the profit and loss, balance sheet and aged reports, not the transactional endpoints.
How can I automate Xero reports?
Have your app pull the report on a schedule rather than on demand. The aged receivables, profit and loss and balance sheet reports are all readable through the connector's default scopes. Store each pull in your app's own database with a timestamp, render the dashboard from that copy, and the 60-calls-per-minute and daily tenant limits stop being a factor.
How do I change my Xero dashboard?
Xero's built-in dashboard is configurable only within the limits Xero provides. Building alongside it is the point of this connector: a separate app, on your own URL, that reads the same organisation and lays the numbers out the way your team actually works, including views Xero does not offer such as a single collections queue ordered by overdue value.
References
- Lovable documentation: Connect your app to Xero, read 10 October 2026
- Lovable changelog, Xero connector entry dated 28 July 2026, read 10 October 2026
- Xero Developer blog: Introducing the Lovable Xero connector, Corey Leung, 29 July 2026
- Xero Developer: Pricing and policies, read 10 October 2026
- Xero Developer: OAuth 2.0 API limits, read 10 October 2026
- Xero Developer Platform Terms and Conditions, read 10 October 2026
- Xero Developer: Pricing and policy updates FAQs, read 10 October 2026
- Lovable pricing, read logged out 10 October 2026
- Lovable Connectors catalogue, read inside a live workspace on 10 October 2026
About the Author
TJ Alam is a certified Lovable Expert on the Website Builder track and the founder of Digi Flock Enterprises. He has built and shipped tjalam.com and cyberdance.in with Lovable. He writes the Lovable series for MoneyFlock and tests every plan gate, price and connector claim in the live product before publishing. You can find him on the Lovable Expert directory, or start a Lovable Business plan here.
MoneyFlock may earn a commission if you subscribe to a Lovable Business plan through links in this article, at no extra cost to you. TJ Alam is a certified Lovable Expert.