Skip to content

Maintenance status, and the gap between main and open community PRs #315

Description

@aspiers

Hi, and thanks for publishing this server. It's been very useful.

The last merge to main was on 2026-06-05, and there are now 77 open pull requests, many of them fixes for bugs reported here (validation errors being swallowed, [object Object] in output, update-bank-transaction failing with 400s, invalid manual journal lineAmountTypes, and so on). Could a maintainer say whether the project is still actively maintained, and whether there's a plan for working through the PR queue?

To make the question concrete, I tried to find out what it would take to get the fixes and features I needed out of the open PRs, and ended up building a combined branch. It shows how far main has fallen behind what the community has already written. It also shows the kind of review and integration work a maintainer would face, and would keep facing as new PRs arrive:

The branch is on my fork. I'm not proposing it as an alternative to this repo or volunteering as an unofficial maintainer; it's a reference for what's ready to land. Since it exists, others may find it useful in the meantime:

Even a short note from the maintainers either way would help people decide whether to wait, contribute, or fork.

What's in the branch, how it was checked, and caveats

Base

PRs included

Area PRs
Error handling / security #305, #214, #290
Auth #200 (XERO_TOKEN_FILE self-refreshing token), plus my locking fixes described in #200 (comment)
Manual journals #182, #181 (includes #180's code)
Bank transactions #190, #153
Output formatting #207, #231 (closed, reopen requested)
Reports #186 (includes #198's fix)
Credit notes / allocations #187, #194, #195, #291
Invoices / bills #216, #221, #293, #294, #296, #308, #110 + #289 (combined so date filters and where are ANDed together)
Listing #176 (pageSize on list tools)
New tools #191 (linked transactions), #298 (general ledger journals), #145 (history & notes), #109 (attachments; without its unrelated xero-client.ts changes), #127 (invoice PDF / online URL)

Left out after review: #295 (a partial line update can delete the other lines; see my comment there), #126 (package rename and stale client rewrite; see my comment there), and duplicates superseded by the PRs above (#180, #197, #215, #313, #204, #178, #198, #161, #201). AU payroll, quotes and remote-hosting PRs are out of scope for my use, so I didn't evaluate them.

How it was checked

  • An AI coding assistant reviewed each included PR's diff, and I read the results. The review looked at secret handling, network destinations, dependency and lockfile changes, and risks of corrupting accounting data. This is not a professional security audit.
  • I exercised the read tools against a live UK organisation in token-file mode. That included the token file refreshing itself, with three server processes refreshing at the same moment. Bearer-token mode was only tested live with the v20 upgrade on its own.
  • I have not exercised the write tools live.

Caveats

Using it

git clone -b best-of-breed https://github.com/aspiers/xero-mcp-server.git
cd xero-mcp-server
npm ci && npm run build

Then point your MCP client at node /path/to/xero-mcp-server/dist/index.js, with the same environment variables as the README. #200's README section covers the XERO_TOKEN_FILE mode.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions