Supported resources
- Organisations
- Contacts
- Invoices
- Bills
- Bank transactions (read)
- Reports (profit and loss, balance sheet, aged receivables)
Authentication
OAuth 2.0 with Xero. The connection is held by Kroy; AI clients never receive Xero tokens.
Supported actions
| Capability | Type | Default |
xero.contacts.read Read contacts | read | Policy |
xero.invoices.read Read invoices | read | Policy |
xero.bills.read Read bills | read | Policy |
xero.reports.read Read reports | read | Policy |
xero.invoices.draft_create Create draft invoice | write | Policy |
xero.invoices.approve Approve invoice | write | Human approval |
Events
xero.invoice.createdxero.invoice.paid
Overview
Xero stays the authoritative record. Kroy connects to it so that authorised AI — Claude, ChatGPT and others — can use Xero data and actions without each AI holding its own Xero access.
Permissions
Each Xero action is a Kroy capability. Kroy decides every request against the person, the agent, the delegation between them and the organisation’s policies. Actions that change financial records can require human approval.
Industries
Accountancy practices can map staff to the client organisations they work on, so an AI acting for a manager sees that manager’s clients only.
Security
Kroy holds the Xero connection. Revoking an AI’s access to Kroy removes its access to Xero at the same moment. Every request is recorded.
Limitations
- Payroll is excluded by default and is not planned for the first release.
- Bank details cannot be changed through Kroy.
- Actions are subject to Xero’s own API rate limits.