Repository navigation
Add read-only Xero Accounting adapter - #943
Conversation
|
👋 Welcome, @ryanduguid, and thanks for opening your first PR on AnythingMCP! A few quick pointers:
Someone from the core team will look at this within ~48h. If you don't hear back, please ping us in Discussions / Q&A. ⭐ While you wait — if you find AnythingMCP useful, a star helps others discover it. |
|
All contributors have signed the CLA ✍️ ✅ |
|
I have read the CLA Document and I hereby sign the CLA |
The tenant is chosen after authorisation, so it moves from the OAuth extraHeaders to each Accounting tool's headers, and the new tool reads https://api.xero.com/connections without it. A tool header that is only an empty variable now keeps its placeholder, so the call is refused with the variable's name instead of sending a blank header.
|
Done in bd2ae4d. Two changes were needed to make that work:
Tests: |
Summary / Goal
Add Xero Accounting to the adapter catalogue so an authorised organisation can read invoices, bills, contacts, accounts, Trial Balance and Profit and Loss through the existing REST engine.
Context
Refs #150 and October Challenge #846. @keysersoft
The
xeroslug was free before implementation. This follows the FreshBooks OAuth2 and existingextraHeaderspatterns. Current Xero scope documentation supplies the granular invoice and individual report read scopes.Changes
intl/xero.jsonwith nine GET tools: Organisation probe; invoice, contact and account list/get; Trial Balance; Profit and Loss.xero-tenant-id. Document required variables, a Postman route to discover the tenant before first installation, both callback URLs, rotating tokens, additive consent, pagination and 429 handling. Every tool includes examples.RUN_XERO_LIVE=1.catalog.tswith the script, add the Xero SVG logo and update the quoted catalogue counts in the eight files checked by the repository script.Constraints
All Accounting tools use GET under
https://api.xero.com/api.xro/2.0. Scopes grant only the specified accounting reads. Tenant discovery at/connectionsis documented separately because it sits outside that base URL. Required settings areXERO_CLIENT_ID,XERO_CLIENT_SECRETandXERO_TENANT_ID;XERO_REFRESH_TOKENis optional. No engine, dependency oree/changes, write tools, custom MCP server or issue claim.Type
Testing
The catalogue at
95fc33ca7e5fcontains 326 listed adapters, 17 keyless and 4,014 tools. Commit4bb8f6bb741ecorrects the README banner from 16 to 17 keyless connectors. Fresh count and adapter validation checks pass after this documentation correction.Local backend checks and the frontend production build ran on Linux with Node 26.10.0, npm 12.2.0 and generated Prisma 7.10.0, using locked dependencies. Catalogue checks ran on Windows. No live Xero credentials were used.
node scripts/regenerate-catalog.mjs95fc33ca7e5fnode scripts/validate-adapters.mjs --warnnode scripts/adapter-count.mjs --checknpm test -w packages/backend -- --maxWorkers=495fc33ca7e5fpackages/backendnpm run lintpackages/backendnpx tsc --noEmit -p tsconfig.jsonpackages/backendnpm run buildpackages/frontendnpm run buildbf8dee91ed85; not repeated after the upstream mergegit diff --checkEarlier upstream CI at
bf8dee91ed85passes backend and frontend lint/typecheck/build, the backend test suite, adapter validator and generator checks, script tests, runtime dependency checks, release/stuck-users tests, and Docker image build/boot. CodeQL, Playwright, the filesystem scan and the CLA passed atbf8dee91ed85. Hosted workflows on the repaired branch require maintainer approval; the current head has no fresh hosted CI result. The full backend suite and frontend build were not repeated for the one-line README correction.At
bf8dee91ed85, the Xero spec contributed 27 passing static, request-mapping and callback integration tests, plus one skipped live probe. Mocked calls cover every path, bearer and tenant headers, defaults, filters, report dates, false booleans, encoded identifiers and retained response envelopes. Both omitted and blank optional refresh tokens are tested through import, authorisation state, the callback/encrypted merge and authenticated healthcheck/probe requests. Existing OAuth tests cover Basic authentication and persistence of rotated refresh tokens. At that earlier revision, Aikido scanned five changed code/configuration/asset files with no findings. All 1,503 tracked TS/TSX/JSON/SVG files checked locally matched the Git snapshot after checks.Done-when / Checklist
catalog.tsis regenerated by script.ee/changes or secrets are included.Risks and unverified checks
Live Xero authorisation, granular-scope acceptance, rotating refresh and provider responses are unverified because no live credentials were supplied. Clean-room Cloud/self-host installation is also unverified. Tenant discovery requires an authorised session for the same app before installation; the instructions include a Postman Desktop procedure for a new app. Existing Xero consent can retain broader scopes; the instructions explain revoking and reauthorising to reduce permissions.
Trivy's Docker image vulnerability scan was skipped for this PR; GitHub marks its aggregate check neutral.
Related Issues
Refs #150. Part of #846.