Xero API Changes 2026: What UK Bookkeepers Using Dext, Receipt Bot and Third-Party Apps Need to Know

Share
Xero API Changes 2026: What UK Bookkeepers Using Dext, Receipt Bot and Third-Party Apps Need to Know

Xero API Changes 2026: What UK Bookkeepers Using Dext, Receipt Bot and Third-Party Apps Need to Know

If you use Dext, Receipt Bot, Hubdoc, AutoEntry or any other app that connects to Xero, something significant happened to the plumbing in March 2026 — and you may already be feeling it in your software bills. Xero overhauled the way third-party apps access its platform, introducing a new commercial pricing model, a new system of tighter API permissions, and an explicit ban on using Xero data to train AI. For bookkeepers and sole practitioners, none of this breaks anything overnight. But it does explain why some of your Xero-connected tools have quietly raised their prices, and it gives you a clearer picture of where the ecosystem is heading.

This article explains what changed, which tools are most affected, and what — if anything — you actually need to do about it. If you want to get ahead of things, the most practical move is still to make sure your receipt capture and data-entry workflow is as efficient as possible, so you are getting genuine value out of every app you pay for.

Reviewing your Xero app stack? Dext is still the benchmark for receipt capture — and the one most likely to hold its value as costs shift across the ecosystem.

Try Dext Free for 14 Days

What Actually Changed in March 2026

Three distinct changes came into effect on 2 March 2026. They are separate but related, and it is worth understanding each one clearly.

1. A new commercial pricing model: connections and data egress

Until March 2026, Xero charged third-party developers through a revenue-share arrangement: take 15% of whatever a developer earned through the Xero App Store. That model has been retired. In its place, Xero now charges developers based on two things: how many companies (connections) are linked to their app, and how much data the app downloads from Xero (data egress).

The new model has five tiers, with pricing in Australian dollars (Xero's home currency):

Tier Monthly fee (AUD) Max connections Included egress App Store listing
Starter Free 5 n/a (1,000 calls/tenant/day cap) No
Core ~$35 50 10 GB No
Plus ~$245 1,000 50 GB Optional (cert. required)
Advanced ~$1,445 10,000 250 GB Optional (cert. + security assessment)
Enterprise Price on application No limit Negotiated Required

Egress overage above each tier's included allowance is charged at AUD $2.40 per GB. Importantly, the Journals endpoint — used for bank reconciliation and journal retrieval — now requires the Advanced tier regardless of connection count. Any app that relies on pulling journal data to function will face a minimum monthly cost of around AUD $1,445, which at current exchange rates is roughly £720. That is not a rounding error on a small developer's costs.

One important exemption: apps built by an accountant or bookkeeper for use in their own practice or with a single client are excluded from the new commercial model. If you have built a bespoke Xero integration for your own use, this does not apply to you.

2. Granular scopes: tighter permissions for every connected app

Until March 2026, Xero used broad permission "scopes" when apps connected via OAuth. The main one — accounting.transactions — gave an app access to invoices, purchase orders, payments, prepayments, quotes and more in a single permission grant. From 2 March 2026, Xero replaced these with granular scopes, where each type of data requires a separate, explicit permission.

For example, accounting.transactions is now split into:

  • accounting.invoices — credit notes, invoices, purchase orders, quotes
  • accounting.payments — batch payments, overpayments, payments, prepayments
  • accounting.journals — journal entries (Advanced tier required)

Apps created before 2 March 2026 have until 13 September 2027 to migrate. Apps created after that date already use granular scopes by default. The migration has a practical implication for end users: when a developer updates their app to use granular scopes, existing users may need to re-authorise the connection — clicking through the OAuth flow again to grant the new specific permissions. If you see a prompt from Dext or another Xero-connected app asking you to re-connect or "update permissions", this is why.

3. The AI training ban

Xero has added an explicit prohibition in its developer terms: data obtained via the Xero API may not be used to train artificial intelligence or machine learning models. This applies to all developers from 2 March 2026 (and from 4 December 2025 for new developers). It is enforceable through the platform terms and could result in access being revoked for developers who breach it.

The reasoning Xero gives is privacy and trust: client accounting data should not be fed into general-purpose AI models without explicit consent. Critics, including Dext's Chief Product Officer Stephen Edginton, argued publicly that the ban raises deeper questions about data ownership — pointing out that software processes data but does not own it, and that the restriction could drive AI-native tools to build their own general ledgers rather than rely on Xero. It is an ongoing tension in the ecosystem, and worth watching.

What This Means for Dext, Receipt Bot and the Apps You Use

The most immediate consequence for UK bookkeepers is the one Lara Manton, a bookkeeper and director at LJM Bookkeeping, put plainly in a public comment on AccountingWEB: "I'm expecting that the majority of apps will have to pass on at least a portion of the price increase, which we then need to absorb or pass to our end clients."

That is already happening. AccountingWEB reported in January 2026 that at least three Xero-connected apps had already raised their prices on the back of the new commercial model. One developer told AccountingWEB that their annual API cost was set to jump from near zero to over $17,000 (AUD) overnight.

The apps most exposed are those with the deepest Xero integrations — the tools that pull large volumes of transaction data regularly. Dext, which processes millions of documents and pushes coded data back into Xero continuously, is firmly in this category. Receipt Bot and AutoEntry, which operate at similar volume for receipt capture, face the same structural cost increase. None of these vendors has publicly itemised exactly what their Xero API costs look like under the new model, but the direction is clear: the era of free or near-free Xero API access is over for commercial app developers.

Smaller or more specialist tools, particularly those with fewer than 50 client connections, can still operate on the Core tier at around $35 AUD/month and remain viable. But anything sitting in the hundreds or thousands of client connections is on Plus or Advanced — and facing a meaningfully different cost structure than it had 12 months ago.

For the best receipt capture tools on the market, the value proposition has not changed — but you should factor in that pricing across this category may drift upward over the next 12–18 months as developers digest their new cost structures.

What the AI Ban Means in Practice for Your Clients

For day-to-day bookkeeping work, the AI training ban changes nothing immediately visible. Your clients' VAT records are not being fed into a language model. What the ban does affect is product development at the app layer: vendors who had plans to improve AI categorisation or anomaly detection by training on aggregated Xero transaction data now cannot do so using data pulled via the API.

This matters because the AI features UK bookkeepers have been exploring — smart coding suggestions, automatic reconciliation, anomaly flagging — partly depend on training data. If vendors cannot use Xero data to improve those models, they either train on data from their own document-ingestion systems (which Dext, for instance, already holds independently of Xero), or they invest in building their own ledger infrastructure. Either route is viable but adds complexity and cost.

The practical upshot for now: Dext AI Assist and similar features within receipt capture tools are unaffected by this specific ban because they process documents before they reach Xero — the training data sits in the capture layer, not in the ledger. Tools that primarily function by pulling Xero data out and analysing it are the ones more constrained.

The XPM Changes (If You Use Xero Practice Manager)

Practices using Xero Practice Manager (XPM) should also be aware of a separate API overhaul. XPM 3.1 has landed — bringing JSON responses, UUIDs, field selection, and pagination — and the v3.0 API retires on 30 April 2027. A faster deprecation applies to three XPM endpoints (Leads, Purchase Orders, and Suppliers), which retired on 5 August 2026.

If your practice uses any tool that integrates with XPM — workflow software, job costing tools, time trackers — check whether the vendor has already migrated to XPM 3.1. If they are still on v3.0, they have until April 2027, but any tool still on the older version after August 2026 may already have gaps in Leads, Purchase Orders and Suppliers data.

What Bookkeepers Should Actually Do Now

For most UK bookkeepers and sole practitioners, the direct action required is close to zero — these are developer-facing changes, not configuration changes on your side. But there are a few sensible things to keep in mind:

  • Expect re-authorisation prompts. As apps migrate to granular scopes before the September 2027 deadline, you will periodically see prompts to re-connect or "update permissions" for Xero-integrated tools. This is expected and legitimate — follow the vendor's instructions when they appear.
  • Review your app stack once a year. With API costs now a real variable for developers, the economics of smaller apps in the Xero ecosystem may shift. Tools that were previously free or heavily subsidised may price differently. Do a quick review of the apps your practice relies on and whether the pricing still makes sense.
  • Audit inactive Xero connections. If you have disconnected a tool but never formally removed its Xero connection, you are contributing to that vendor's connection count — which affects their tier costs. This is minor from your perspective but good housekeeping: revoke connections for apps you no longer use via Xero's Connected Apps settings.
  • Ask your software vendors directly. If you rely on a niche or specialist Xero-connected tool and are concerned about its viability under the new model, ask the vendor how they are positioned. A credible vendor will have a clear answer; one that cannot explain their tier situation is worth monitoring carefully.

If you are considering switching or adding any Xero-connected tool this year, it is worth checking whether the vendor is HMRC-recognised for MTD purposes as well as certified in the Xero App Store. App Store listing now requires the Plus tier or above, so any certified App Store listing is at least paying $245 AUD/month to be there — a reasonable indicator that the vendor is serious and commercially stable.

The Bigger Picture: Is This Xero Closing the Ecosystem?

Whether Xero's API changes represent a strategic tightening of an open ecosystem or a reasonable move to fund platform sustainability depends on your perspective. Alastair Barlow, former CEO of accounting firm flinder, made the point that Xero's value was built on a network effect from its marketplace — and that changes which create friction for third-party developers risk undermining that.

The more pointed comparison is to Sage: once so embedded in the profession that no one imagined it could be displaced — until Xero did exactly that. Whether the API changes open a similar gap for a more open competitor is the question several accounting-tech observers are now asking. For the best Xero alternatives in 2026, the argument just got marginally more interesting.

For now, Xero remains the dominant ledger for UK small business and bookkeeping practices. Its 1 million+ UK subscribers and deep integration into HMRC's MTD infrastructure mean it is not going anywhere quickly. But the API changes are a reminder that platform lock-in cuts both ways — and that reviewing your app stack with fresh eyes at least once a year is time well spent.

Affiliate disclosure: Some links in this article are affiliate links. If you sign up through them, we may earn a commission at no extra cost to you. We only recommend tools we've genuinely assessed.

Read more