Changes to Xero Accounting API Scopes

Earlier this year Xero introduced a change to the authentication scopes for new Xero OAuth Apps that were created on or after March 2, 2026. They are replacing the previous broad scopes with more granular scopes to give you more control and security.
Xero OAuth Apps created on or after March 2, 2026 have been assigned the new granular scopes – existing apps will need to update to granular scopes before September 2027, so there’s plenty of time to make the change. We’ve added a new support article with the details and making the changes should only take a few minutes (remember to re-authenticate after making the change to get the new access token with the new granular scopes).
If you’re using fmAccounting Link (Xero Edition) v2.35 or later you are already working with the granular scopes so no change is necessary here.
Xero have also made an update this week (29 June 2026) related to Authorisation. Xero are aligning authorisation on several endpoints with the roles and permissions described on Xero Central. No code changes are required. However, if a connection was authorised by a user without the required permissions, affected calls will fail with an authorisation error (403 error code), and that user will need their roles and permissions updated within Xero. For example the BankAccountAdmin permission will be required for any calls that create or update contact bank account details, whether via the Contacts endpoint or through document endpoints such as Invoices and CreditNotes.

Leave a Reply
Want to join the discussion?Feel free to contribute!