{"name":"io.github.Servosity/xero-mcp","slug":"servosity-xero-mcp","title":"Xero MCP","description":"Every Xero Accounting read plus a local SQLite ledger  -  aging, reconciliation, and GL tie-out","url":"https://mcp.market/server/servosity-xero-mcp","rating":null,"grade":"B","score":75,"certified":false,"status":"active","category":"data","tags":["data","finance"],"presence":{"score":31,"stars":41,"forks":9,"downloads_week":null,"last_push_at":"2026-09-18T21:32:08.000Z","license":"NOASSERTION"},"uptime":null,"claimed":false,"transport":"mcpb","callable_via_gateway":false,"default_price_micros":0,"repository":"https://github.com/servosity/msp-skills","website":null,"version":"0.1.5","remotes":[],"packages":[{"registryType":"mcpb","identifier":"https://github.com/Servosity/msp-skills/releases/download/xero-v0.1.5/xero-mcp.mcpb","version":"0.1.5","fileSha256":"0e779174512fc83d6cd39b74bea541d476b71e4e4aad1602ef5905e87de8ec27","transport":{"type":"stdio"},"environmentVariables":[{"description":"Set the XERO_ACCESS_TOKEN credential for the Xero MCP server.","isRequired":true,"isSecret":true,"name":"XERO_ACCESS_TOKEN"},{"description":"Authorization endpoint the login flow opens. Change it only if Xero moves the endpoint.","default":"https://login.xero.com/identity/connect/authorize","name":"XERO_AUTHORIZATION_URL"},{"description":"Base URL for the Xero API. Leave the prefilled default unless your account uses a different regional or self-hosted host.","default":"https://api.xero.com/api.xro/2.0","name":"XERO_BASE_URL"},{"description":"Client ID of your Xero app (developer.xero.com > My Apps). Set it with the client secret to run the OAuth2 flow; leave blank if you paste an access token instead.","isSecret":true,"name":"XERO_CLIENT_ID"},{"description":"Client secret paired with XERO_CLIENT_ID.","isSecret":true,"name":"XERO_CLIENT_SECRET"},{"description":"Optional. Sets XERO_OAUTH2 for the Xero MCP server.","isSecret":true,"name":"XERO_OAUTH2"},{"description":"The Xero organisation ('tenant') GUID sent as the Xero-Tenant-Id header. Every call requires it; `connections list` returns the tenants your token can reach.","isRequired":true,"name":"XERO_TENANT_ID"},{"description":"Token endpoint the client-credentials exchange posts to. Leave the prefilled default unless your tenant uses a different token endpoint.","default":"https://identity.xero.com/connect/token","name":"XERO_TOKEN_URL"},{"description":"Set to 1 to keep credentials off disk. The token cache becomes a no-op, so the connector mints a fresh token each run instead of writing one to config.toml. Leave blank for the default cached behaviour.","name":"XERO_NO_CONFIG_WRITE"}]}],"tools":[],"scan":{"score":75,"grade":"B","scanned_at":"2026-09-19T19:04:44.544Z","report":{"scannerVersion":"0.1.4","scannedAt":"2026-09-19T19:04:44.472Z","components":{"code":{"score":-1,"max":25,"notes":["package could not be scanned"]},"reliability":{"score":-1,"max":20,"notes":["no gateway calls yet and no remote to probe"]},"poisoning":{"score":-1,"max":15,"notes":["tools not inspected (local package is not executed); not counted"]},"auth":{"score":6,"max":15,"notes":["static API keys via environment variables"]},"maintenance":{"score":15,"max":15,"notes":["last push 1 days ago"]},"identity":{"score":9,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"packages":[],"repo":{"found":true,"owner":"servosity","repo":"msp-skills","archived":false,"pushedAt":"2026-09-18T21:32:08Z","stars":41,"forks":9,"openIssues":6,"ownerType":"Organization","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/3374481?v=4","ownerCreatedAt":"2013-01-24T22:07:17Z","license":"NOASSERTION"},"icon":{"url":"https://raw.githubusercontent.com/servosity/msp-skills/main/docs/assets/social/xero/xero-512x512.png","source":"registry","width":512,"height":512},"presence":{"stars":41,"forks":9,"downloadsWeek":null,"license":"NOASSERTION","lastPushAt":"2026-09-18T21:32:08.000Z","score":31}}}},"grade_history":[],"reviews":[]}