# Xero (oci · ghcr.io/wyre-ai/xero-mcp:v1.5.6)

MCP server for Xero accounting — contacts, invoices, payments, accounts, and financial reports.

- Trust score: 54/100 (low)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- oci · `ghcr.io/wyre-ai/xero-mcp:v1.5.6`: 54/100 (this document), [markdown](https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6.md), [page](https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6)

## Channel facts

- Registry: `oci`
- Package: `ghcr.io/wyre-ai/xero-mcp:v1.5.6`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 0/100
  - Malware scan not yet available for this package.
  - Known CVEs could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.
  - Install-script risk not yet assessed.
  - Dependency health could not be checked: this artifact ships no SBOM, so there is no dependency list to read. Publishing one would let us assess it.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (Apache-2.0).
  - Actively maintained (last published 25 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 85/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1435 tokens (~68/item across 21 items; 20 tools + 1 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 83/100
  - Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 20 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.
  - Supports UI / widget rendering.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the Xero MCP server?

Xero runs locally as a container image, launched with docker run --rm -i ghcr.io/wyre-ai/xero-mcp:v1.5.6. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add wyre-ai-xero-mcp -- docker run --rm -i ghcr.io/wyre-ai/xero-mcp:v1.5.6
```

### Cursor

```json
{
  "mcpServers": {
    "wyre-ai-xero-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-ai/xero-mcp:v1.5.6"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "wyre-ai-xero-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-ai/xero-mcp:v1.5.6"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add wyre-ai-xero-mcp -- docker run --rm -i ghcr.io/wyre-ai/xero-mcp:v1.5.6
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "wyre-ai-xero-mcp": {
      "type": "local",
      "command": [
        "docker",
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-ai/xero-mcp:v1.5.6"
      ],
      "enabled": true
    }
  }
}
```

### Hermes

```yaml
mcp_servers:
  wyre-ai-xero-mcp:
    command: "docker"
    args: ["run", "--rm", "-i", "ghcr.io/wyre-ai/xero-mcp:v1.5.6"]
```

### Netclaw

```json
{
  "McpServers": {
    "wyre-ai-xero-mcp": {
      "Transport": "stdio",
      "Command": "docker",
      "Arguments": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-ai/xero-mcp:v1.5.6"
      ]
    }
  }
}
```

### Other

```json
{
  "mcpServers": {
    "wyre-ai-xero-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "ghcr.io/wyre-ai/xero-mcp:v1.5.6"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 54, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 53, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 52, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 51, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 50, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 49, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 48, +1)

No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-04 (score 47, +1)

No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (20)

### `xero_navigate` (~152 tokens)

Discover available Xero tools by domain. Returns tool names and descriptions for the selected domain. All tools are callable at any time — this is a help/discovery aid, not a prerequisite.

Input parameters:

- `domain` (string, required): The domain to explore: - contacts: Contact management - list, get, create, and search contacts (customers and suppliers) - invoices: Invoice management - list, get, create invoices and update their s…

### `xero_status` (~16 tokens)

Show credentials status and available domains

### `xero_back` (~26 tokens)

Return to domain selection (no-op in flattened mode). All tools are always available.

### `xero_contacts_list` (~86 tokens)

List contacts in Xero with pagination. Optionally filter using a where clause. Returns contact details including name, email, and addresses.

Input parameters:

- `page` (number): Page number (1-based, default: 1). Each page returns up to 100 contacts.
- `where` (string): Optional Xero where clause filter (e.g., 'ContactStatus=="ACTIVE"')

### `xero_contacts_get` (~48 tokens)

Get detailed information about a specific contact by its ID. Returns full contact profile including addresses, phone numbers, and email.

Input parameters:

- `contactId` (string, required): The unique contact ID (UUID)

### `xero_contacts_create` (~145 tokens)

Create a new contact in Xero. Name is required; other fields are optional.

Input parameters:

- `AccountNumber` (string): Account number for the contact
- `EmailAddress` (string): Contact email address
- `FirstName` (string): Contact first name
- `IsCustomer` (boolean): Whether the contact is a customer
- `IsSupplier` (boolean): Whether the contact is a supplier
- `LastName` (string): Contact last name
- `Name` (string, required): Contact name (required)
- `Phone` (string): Contact phone number
- `TaxNumber` (string): Tax number (ABN in Australia, GST in NZ, VAT in UK)

### `xero_contacts_search` (~38 tokens)

Search contacts by name. Returns contacts whose name contains the search term.

Input parameters:

- `term` (string, required): Search term to match against contact names

### `xero_invoices_list` (~105 tokens)

List invoices in Xero with pagination. Optionally filter by status and type (ACCREC for sales, ACCPAY for bills).

Input parameters:

- `Status` (string): Filter by invoice status
- `Type` (string): Filter by invoice type: ACCREC (accounts receivable / sales invoices) or ACCPAY (accounts payable / bills)
- `page` (number): Page number (1-based, default: 1). Each page returns up to 100 invoices.

### `xero_invoices_get` (~50 tokens)

Get detailed information about a specific invoice by its ID. Returns full invoice details including line items, amounts, and payment status.

Input parameters:

- `invoiceId` (string, required): The unique invoice ID (UUID)

### `xero_invoices_create` (~157 tokens)

Create a new invoice in Xero. Requires type, contact, and at least one line item.

Input parameters:

- `ContactID` (string, required): The contact ID to create the invoice for (required)
- `Date` (string): Invoice date in YYYY-MM-DD format
- `DueDate` (string): Due date in YYYY-MM-DD format
- `LineItems` (array, required): Array of line items (required). Each item needs Description, Quantity, UnitAmount, and AccountCode.
- `Reference` (string): Invoice reference/PO number
- `Status` (string): Initial invoice status (default: DRAFT)
- `Type` (string, required): Invoice type: ACCREC (sales invoice) or ACCPAY (bill) (required)

### `xero_invoices_update_status` (~60 tokens)

Update the status of an existing invoice. Can submit, authorise, or void an invoice.

Input parameters:

- `Status` (string, required): New status for the invoice (required)
- `invoiceId` (string, required): The invoice ID to update (required)

### `xero_payments_list` (~62 tokens)

List payments in Xero with pagination. Optionally filter by status.

Input parameters:

- `Status` (string): Filter by payment status
- `page` (number): Page number (1-based, default: 1). Each page returns up to 100 payments.

### `xero_payments_get` (~36 tokens)

Get detailed information about a specific payment by its ID.

Input parameters:

- `paymentId` (string, required): The unique payment ID (UUID)

### `xero_payments_create` (~100 tokens)

Create a new payment in Xero. Records a payment against an invoice.

Input parameters:

- `AccountID` (string, required): The bank account ID the payment is made from/to (required)
- `Amount` (number, required): Payment amount (required)
- `Date` (string, required): Payment date in YYYY-MM-DD format (required)
- `InvoiceID` (string, required): The invoice ID to apply the payment to (required)
- `Reference` (string): Payment reference

### `xero_accounts_list` (~115 tokens)

List chart of accounts in Xero. Optionally filter by account type or class.

Input parameters:

- `Class` (string): Filter by account class
- `Type` (string): Filter by account type (e.g., "BANK", "REVENUE", "EXPENSE", "CURRENT", "FIXED", "EQUITY", "CURRLIAB", "TERMLIAB", "DIRECTCOSTS", "OVERHEADS", "DEPRECIATN", "OTHERINCOME", "SALES")

### `xero_accounts_get` (~35 tokens)

Get detailed information about a specific account by its ID.

Input parameters:

- `accountId` (string, required): The unique account ID (UUID)

### `xero_reports_profit_and_loss` (~61 tokens)

Get a Profit and Loss (income statement) report for a date range.

Input parameters:

- `fromDate` (string, required): Start date in YYYY-MM-DD format (required)
- `toDate` (string, required): End date in YYYY-MM-DD format (required)

### `xero_reports_balance_sheet` (~38 tokens)

Get a Balance Sheet report as of a specific date.

Input parameters:

- `date` (string, required): Report date in YYYY-MM-DD format (required)

### `xero_reports_aged_receivables` (~45 tokens)

Get an Aged Receivables report showing outstanding customer invoices by age.

Input parameters:

- `date` (string, required): Report date in YYYY-MM-DD format (required)

### `xero_reports_aged_payables` (~43 tokens)

Get an Aged Payables report showing outstanding supplier bills by age.

Input parameters:

- `date` (string, required): Report date in YYYY-MM-DD format (required)

## Diagnostics

Captured diagnostic sections: Provenance. The full working is on the page: https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6#diagnostics

## Score history

- 2026-09-20: 54
- 2026-09-19: 54
- 2026-09-18: 53
- 2026-09-17: 53
- 2026-09-16: 52
- 2026-09-15: 52
- 2026-09-14: 51
- 2026-09-13: 51
- 2026-09-12: 50
- 2026-09-11: 50
- 2026-09-10: 49
- 2026-09-09: 49
- 2026-09-08: 48
- 2026-09-07: 48
- 2026-09-06: 47
- 2026-09-05: 47
- 2026-09-04: 47
- 2026-09-03: 46
- 2026-09-02: 42
- 2026-09-01: 42
- 2026-08-31: 42
- 2026-08-30: 42
- 2026-08-29: 42
- 2026-08-28: 42
- 2026-08-27: 42
- 2026-08-26: 42

## Common questions

### What is the Xero MCP server?

Xero is an MCP server listed in the public MCP registry as io.github.WYRE-AI/xero-mcp. MCP server for Xero accounting, contacts, invoices, payments, accounts, and financial reports. This page covers its container image (ghcr.io/wyre-ai/xero-mcp:v1.5.6).

### Is the Xero MCP server safe to use?

Xero scores 54 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Xero MCP server expose?

Xero exposes 20 tools: xero_navigate, xero_status, xero_back, xero_contacts_list, xero_contacts_get, and 15 more. Their descriptions and schemas cost roughly 1,418 tokens of context every time the server is loaded.

### Is the Xero MCP server still maintained?

Xero is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Xero MCP server under?

Xero declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- Repository: https://github.com/WYRE-AI/xero-mcp
- Changelog RSS feed: https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6.xml
- Changelog JSON feed: https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6.json
- HTML version of this page: https://verifymcp.io/servers/wyre-ai-xero-mcp/ghcr-io-wyre-ai-xero-mcp-v1-5-6
