Xero
Connecting Xero lets Ploy see everyone who has access to your Xero organisation and the role they hold there. Once connected, Ploy scans your organisation's user list every hour and keeps identities and access records up to date.
The connection is strictly read-only. Ploy requests only Xero's accounting.settings.read scope (plus offline_access so the connection stays alive), and Xero's Accounting API offers no way to create, change or remove users — so Ploy cannot make any changes in your Xero organisation.
What Ploy syncs from Xero
Users — everyone with access to the connected Xero organisation, with their name and email address. Ploy creates or updates an identity for each of them.
Xero access — a confirmed access record for each user, with their Xero organisation role (for example Standard, Adviser or Read Only) shown as their access level and entitlement.
Removals — a user who has been removed from the organisation is marked as inactive, and their Xero access is revoked in Ploy on the next scan.
Xero's Accounting API does not expose MFA status, sign-in history or per-resource sharing, so Ploy cannot show those for Xero.
Prerequisites
A Xero login that can create apps in the Xero developer portal.
Access to the Xero organisation you want Ploy to scan — you will sign in to Xero and authorise it during setup.
Step 1 — Create a Xero app
Ploy connects to Xero through an OAuth app that you create in your own Xero developer account, so the credentials stay under your control.
Sign in to the Xero developer portal at developer.xero.com with your Xero login.
Create a new app, choosing the web app option.
When asked for a redirect URI, enter Ploy's callback URL:
https://api.joinploy.com/integrations/auth/xero/callbackOpen the new app's configuration page and copy the Client ID.
Generate a Client Secret and copy it straight away — Xero will not show it again.
Step 2 — Connect Xero in Ploy
In Ploy, go to Integrations and choose Xero.
Enter the Client ID from your app in the Xero developer portal.
Enter the Client Secret generated for the same Xero app, then continue.
Click Connect to Xero. Sign in to Xero and choose which organisations Ploy may read — Ploy only ever reads.
On the final page, use Select the Xero organisation to scan to pick the organisation Ploy should watch. Ploy scans one Xero organisation per connection — add another connection for another organisation.
Once you finish, Ploy verifies the connection by reading your Xero user list, and the first scan starts automatically. After that, Ploy re-scans every hour.
What Ploy can change in Xero
Nothing. Xero's Accounting API is read-only for users — there is no API to invite, edit, suspend or remove a user — so this integration detects access but takes no actions in Xero. User access changes still have to be made in Xero itself.
Troubleshooting
"Xero rejected this connection. Reconnect Xero and try again."
Xero no longer accepts the connection's credentials. This usually means the app's Client Secret was regenerated or the app was deleted, or Xero's access was revoked. Re-enter the Client ID and Client Secret and click Connect to Xero again.
"Ploy is missing the Xero permission it needs to read users. Reconnect Xero and approve the requested access."
The Xero user who authorised the connection does not have permission to read the organisation's users, or the requested access was not approved during sign-in. Reconnect with a Xero user who has access to the organisation and approve the requested access.
"No Xero organisation is selected. Choose your organisation, then test again."
The setup was not finished — no organisation was chosen on the final page. Open the connection, pick your organisation under Select the Xero organisation to scan, and test again.
"We couldn't read your Xero users. Reconnect Xero and try again."
Ploy could not fetch the user list for the selected organisation. Check that the connection's Xero user still has access to that organisation, then click Connect to Xero to re-authorise.
The Connect to Xero button is disabled
The button only becomes active once a Client ID has been saved on the first page. Go back, enter the Client ID and Client Secret from your Xero app, and save before connecting.
No organisations appear in the dropdown
The organisation list is fetched live from Xero and only shows organisations of type "organisation" that you authorised during the Connect to Xero step. If it is empty, click Connect to Xero again and make sure you select the organisation you want on Xero's consent screen.