Xero Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Xero Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol (MCP) server for the Xero Accounting API. Enables Claude and other MCP-compatible clients to manage Xero contacts, invoices, payments, accounts, and reports.
Note on registry auth: This server depends only on public npm packages, so the Cloudflare and DigitalOcean cloud builders install its dependencies anonymously — no token is required for one-click deploy. (If a future release adds a private@wyre-technology/*dependency, you would supply a GitHub PAT withread:packagesas a build variable —NODE_AUTH_TOKENfor Cloudflare Workers, a build-timeGITHUB_TOKENsecret for DigitalOcean.)
>
Installing the published package: The released package is published to the GitHub Packages npm registry, which requires authentication on every install (even for public packages). To install it, authenticate npm tonpm.pkg.github.comwith a GitHub PAT that hasread:packages:
>
``bash export NODE_AUTH_TOKEN=$(gh auth token) npm install @wyre-technology/xero-mcp ``npm install
npm run buildXERO_ACCESS_TOKEN=your-access-token XERO_TENANT_ID=your-tenant-id npm startMCP_TRANSPORT=http XERO_ACCESS_TOKEN=your-access-token XERO_TENANT_ID=your-tenant-id npm startThe server listens on http://0.0.0.0:8080/mcp by default.
docker build -t xero-mcp .
docker run -p 8080:8080 \
-e MCP_TRANSPORT=http \
-e XERO_ACCESS_TOKEN=your-access-token \
-e XERO_TENANT_ID=your-tenant-id \
xero-mcp| Variable | Required | Default | Description |
|---|---|---|---|
XERO_ACCESS_TOKEN | Yes (env mode) | — | Xero OAuth2 access token |
XERO_TENANT_ID | Yes (env mode) | — | Xero tenant ID (organisation) |
MCP_TRANSPORT | No | stdio | Transport type: stdio or http |
MCP_HTTP_PORT | No | 8080 | HTTP server port |
MCP_HTTP_HOST | No | 0.0.0.0 | HTTP server bind address |
AUTH_MODE | No | env | Auth mode: env or gateway |
When AUTH_MODE=gateway, credentials are passed per-request via HTTP headers instead of environment variables:
X-Xero-Access-Token — OAuth2 access tokenX-Xero-Tenant-Id — Xero tenant IDThis allows a gateway/proxy to manage multi-tenant credentials.
Tools are organized into domains. Use xero_navigate to select a domain, then use the domain-specific tools.
xero_navigate — Select a domain (contacts, invoices, payments, accounts, reports)xero_back — Return to domain selectionxero_contacts_list — List contacts with pagination and optional filteringxero_contacts_get — Get detailed contact information by IDxero_contacts_create — Create a new contact (customer or supplier)xero_contacts_search — Search contacts by namexero_invoices_list — List invoices with optional status and type filtersxero_invoices_get — Get detailed invoice information by IDxero_invoices_create — Create a new invoice (sales or bill)xero_invoices_update_status — Update invoice status (submit, authorise, void)xero_payments_list — List payments with optional status filterxero_payments_get — Get detailed payment information by IDxero_payments_create — Record a payment against an invoicexero_accounts_list — List chart of accounts with optional type/class filterxero_accounts_get — Get detailed account information by IDxero_reports_profit_and_loss — Profit and Loss (income statement) for a date rangexero_reports_balance_sheet — Balance Sheet as of a specific datexero_reports_aged_receivables — Aged Receivables by contactxero_reports_aged_payables — Aged Payables by contactApache-2.0
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.