Official Xero skill
Interact with the Xero accounting API using the `xero` CLI tool. Manage contacts, invoices, quotes, credit notes, payments, bank transactions, items, manual...
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
0.0.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.0.6release · observed May 25, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17dq8hcd2z58frqmav5j4z6e986grtt:xero-command-line- Install using `clawhub skill install s17dq8hcd2z58frqmav5j4z6e986grtt:xero-command-line` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/xeroapi/xero-command-line before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-xeroapi-xero-command-line/snapshot"
Documentation
CLAWHUB
53,499 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: xero_command_line
description: Interact with the Xero accounting API using the `xero` CLI tool. Manage contacts, invoices, quotes, credit notes, payments, bank transactions, items, manual journals, tracking categories, currencies, tax rates, reports, and organisation details.
user-invocable: true
metadata:
openclaw:
source: "https://github.com/XeroAPI/xero-command-line"
homepage: "https://github.com/XeroAPI/xero-command-line#readme"
requires:
bins:
- xero
install: "npm install -g @xeroapi/xero-command-line"
keywords:
- accounting
- xero
- invoices
- bookkeeping
- finance
---
# xero CLI
You have access to the `xero` CLI — a command-line tool for the Xero accounting API using PKCE OAuth. Use it to read and write accounting data in the user's Xero organisation.
## Authentication & Setup
**Note for Agent:** If the user is not logged in, you must instruct them to run `xero login` in their terminal manually, as it requires a browser-based OAuth flow that you cannot complete. If login fails with `unauthorized_client` or scope-related errors — common for new Xero apps after the March 2026 scope migration, or when the app only grants read scopes — instruct them to re-login with `--scope` listing only the scopes enabled on their app (see [OAuth scopes](#oauth-scopes) below).
```bash
# Check if logged in / check organization details
xero org details
```
### Token storage (Linux / WSL / SSH)
Tokens are encrypted in `~/.config/xero-command-line/tokens.json`. By default the encryption key lives **only** in the OS keychain (on Linux: GNOME Keyring / Secret Service over D-Bus). A file copy is **not** written unless the user opts in.
**If the user is on WSL, SSH, or a headless VM** and sees an encryption-key error after a successful `xero login`:
1. **Prefer fixing the keychain:** `sudo apt install gnome-keyring libsecret-tools dbus-x11`, start `gnome-keyring-daemon`, then `xero login` again.
2. **Flaky keychain** (login OK, next command fails): `export XERO_KEYRING_FILE_BACKUP=1` before `xero login` — mirrors the key to `~/.config/xero-command-line/.encryption-key` (0600) for later reads. Opt-in; weaker than keychain-only.
3. **No keychain:** `export XERO_KEY_STORAGE=file` before `xero login`.
4. **Stronger file-based option:** `export XERO_TOKEN_PASSPHRASE='…'` (same value every session) — scrypt-derived key, not stored in plaintext.
Warn if `XERO_PROFILE`, `XERO_CLIENT_ID`, `XERO_KEY_STORAGE`, `XERO_KEYRING_FILE_BACKUP`, or `XERO_TOKEN_PASSPHRASE` are set — they change profile or how keys are stored. Check with `echo $XERO_PROFILE $XERO_CLIENT_ID $XERO_KEY_STORAGE $XERO_KEYRING_FILE_BACKUP`.
The CLI does **not** wipe `tokens.json` when decryption fails; instruct re-login only after the user confirms.
## IMPORTANT: Profile and identity verification
Before executing **any** commands (including read-only operations), you **must** verify which Xero organisation is active:
1_meta.json
{
"ownerId": "kn749n1k0dbn5c4nq6g1f9kn2x83mmvf",
"slug": "xero-command-line",
"version": "0.0.6",
"publishedAt": 1779675299482
}skill-card.md
## Description: Interact with the Xero accounting API using the `xero` CLI tool to manage contacts, invoices, quotes, credit notes, payments, bank transactions, items, manual journals, tracking categories, currencies, tax rates, reports, and organisation details. This skill is ready for commercial/non-commercial use. ## Publisher: [xeroapi](https://clawhub.ai/user/xeroapi) ### License/Terms of Use: MIT-0 ## Use Case: Developers and finance operations users can use this skill to guide an agent in running the Xero CLI for accounting workflows, including reading organisation data and preparing approved changes to financial records. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The CLI can access financial data in a Xero organisation. Mitigation: Use read-only scopes when possible and confirm the active organisation/profile before any command. Risk: Write commands can create or change accounting records. Mitigation: Review IDs and target records with read-only commands first, then require explicit user approval before each write. Risk: Token storage settings can weaken credential protection on Linux, WSL, SSH, or headless systems. Mitigation: Prefer OS keychain storage, treat file-based fallback and passphrase settings as sensitive, and review relevant environment variables before use. Risk: Global npm installation affects the user's local toolchain. Mitigation: Review the npm install command before running it and install only when the user intends to use the Xero CLI. ## Reference(s): - [Xero command line homepage](https://github.com/XeroAPI/xero-command-line#readme) - [Xero command line source](https://github.com/XeroAPI/xero-command-line) - [TOON format](https://github.com/toon-format/toon) - [ClawHub skill page](https://clawhub.ai/xeroapi/skills/xero-command-line) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown guidance with shell command examples and JSON payload snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [Guides agents to prefer TOON for parsing CLI read/list results, JSON when explicitly needed, and tables for user-facing summaries.] ## Skill Version(s): 0.0.6 (source: server release metadata, created 2026-05-25) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/xeroapi/skills/xero-command-line",
"sourceUrl": "https://clawhub.ai/xeroapi/skills/xero-command-line",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T16:04:13.291Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xeroapi-xero-command-line/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xeroapi-xero-command-line/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T16:04:13.291Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceUrl": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T16:04:13.291Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.0.6",
"href": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceUrl": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-25T02:14:59.482Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xeroapi-xero-command-line/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xeroapi-xero-command-line/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.0.6",
"description": "Version 0.0.6 - Added detailed documentation for Linux, WSL, and SSH token storage and related environment variables. - Warns users when XERO_PROFILE, XERO_CLIENT_ID, XERO_KEY_STORAGE, XERO_KEYRING_FILE_BACKUP, or XERO_TOKEN_PASSPHRASE are set, as these may impact security or profile selection. - Introduced the `--toon` output format option for commands, providing a compact, LLM-friendly encoding for improved efficiency when parsing results. - Revised recommendations for output formats: prefer `--toon` for agent processing, `--json` when explicitly needed, and table output for user-facing messages. - Clarified environment variable usage and added explicit checks and warnings to prevent accidental misconfiguration.",
"href": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceUrl": "https://clawhub.ai/xeroapi/xero-command-line",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-25T02:14:59.482Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
