You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Maintenance status, and the gap between main and open community PRs #315
Hi, and thanks for publishing this server. It's been very useful.
The last merge to main was on 2026-06-05, and there are now 77 open pull requests, many of them fixes for bugs reported here (validation errors being swallowed, [object Object] in output, update-bank-transaction failing with 400s, invalid manual journal lineAmountTypes, and so on). Could a maintainer say whether the project is still actively maintained, and whether there's a plan for working through the PR queue?
To make the question concrete, I tried to find out what it would take to get the fixes and features I needed out of the open PRs, and ended up building a combined branch. It shows how far main has fallen behind what the community has already written. It also shows the kind of review and integration work a maintainer would face, and would keep facing as new PRs arrive:
Duplicates: 7 groups of PRs doing the same thing (e.g. four separate [object Object] fixes, three P&L fixes, two attachment implementations that register the same tool name), each needing one PR picked.
Dependencies:xero-node is seven major versions behind (13 → 20). The upgrade (chore: upgrade xero-node to v20 #314) inserts new positional parameters, which breaks call sites in main and in three of the PRs until adjusted. tsc catches this, but the compiled JavaScript misbehaves without any error.
Result: the combined build has 79 tools against 51 on main, and passes npm ci, tsc, lint and 92 unit tests.
The branch is on my fork. I'm not proposing it as an alternative to this repo or volunteering as an unofficial maintainer; it's a reference for what's ready to land. Since it exists, others may find it useful in the meantime:
#191 (linked transactions), #298 (general ledger journals), #145 (history & notes), #109 (attachments; without its unrelated xero-client.ts changes), #127 (invoice PDF / online URL)
Left out after review: #295 (a partial line update can delete the other lines; see my comment there), #126 (package rename and stale client rewrite; see my comment there), and duplicates superseded by the PRs above (#180, #197, #215, #313, #204, #178, #198, #161, #201). AU payroll, quotes and remote-hosting PRs are out of scope for my use, so I didn't evaluate them.
How it was checked
An AI coding assistant reviewed each included PR's diff, and I read the results. The review looked at secret handling, network destinations, dependency and lockfile changes, and risks of corrupting accounting data. This is not a professional security audit.
I exercised the read tools against a live UK organisation in token-file mode. That included the token file refreshing itself, with three server processes refreshing at the same moment. Bearer-token mode was only tested live with the v20 upgrade on its own.
I have not exercised the write tools live.
Caveats
Several included tools make consequential writes with no confirmation step:
With XERO_TOKEN_FILE, set XERO_TENANT_ID. Otherwise writes go to the first connected organisation.
package.json still says @xeroapi/xero-mcp-server. Please don't publish it under that name.
Using it
git clone -b best-of-breed https://github.com/aspiers/xero-mcp-server.git
cd xero-mcp-server
npm ci && npm run build
Then point your MCP client at node /path/to/xero-mcp-server/dist/index.js, with the same environment variables as the README. #200's README section covers the XERO_TOKEN_FILE mode.
Hi, and thanks for publishing this server. It's been very useful.
The last merge to
mainwas on 2026-06-05, and there are now 77 open pull requests, many of them fixes for bugs reported here (validation errors being swallowed,[object Object]in output,update-bank-transactionfailing with 400s, invalid manual journallineAmountTypes, and so on). Could a maintainer say whether the project is still actively maintained, and whether there's a plan for working through the PR queue?To make the question concrete, I tried to find out what it would take to get the fixes and features I needed out of the open PRs, and ended up building a combined branch. It shows how far
mainhas fallen behind what the community has already written. It also shows the kind of review and integration work a maintainer would face, and would keep facing as new PRs arrive:[object Object]fixes, three P&L fixes, two attachment implementations that register the same tool name), each needing one PR picked.xero-nodeis seven major versions behind (13 → 20). The upgrade (chore: upgrade xero-node to v20 #314) inserts new positional parameters, which breaks call sites inmainand in three of the PRs until adjusted.tsccatches this, but the compiled JavaScript misbehaves without any error.main, and passesnpm ci,tsc, lint and 92 unit tests.The branch is on my fork. I'm not proposing it as an alternative to this repo or volunteering as an unofficial maintainer; it's a reference for what's ready to land. Since it exists, others may find it useful in the meantime:
Even a short note from the maintainers either way would help people decide whether to wait, contribute, or fork.
What's in the branch, how it was checked, and caveats
Base
main+ chore: upgrade xero-node to v20 #314 (xero-node 13 → 20.0.0). v20 includes the upstream fix that redacts request headers, including the bearer token, from SDK error objects. It also inserts new optional positional parameters beforeoptionsin several API methods, so some PRs needed small compatibility fixes (see my comments on feat: add allocation tools (credit note / overpayment / prepayment) + list-overpayments/list-prepayments #187 and feat: add invoice currency code #296).PRs included
XERO_TOKEN_FILEself-refreshing token), plus my locking fixes described in #200 (comment)whereare ANDed together)pageSizeon list tools)xero-client.tschanges), #127 (invoice PDF / online URL)Left out after review: #295 (a partial line update can delete the other lines; see my comment there), #126 (package rename and stale client rewrite; see my comment there), and duplicates superseded by the PRs above (#180, #197, #215, #313, #204, #178, #198, #161, #201). AU payroll, quotes and remote-hosting PRs are out of scope for my use, so I didn't evaluate them.
How it was checked
Caveats
Several included tools make consequential writes with no confirmation step:
Read the diffs before relying on them. A Xero lock date is a sensible safety net.
Some tools need scopes the default setup doesn't request:
accounting.attachments.read(Add attachment read functionality for invoices and manual journals #109) andaccounting.journals.read(feat: add general ledger journal tools (list, get) #298).With
XERO_TOKEN_FILE, setXERO_TENANT_ID. Otherwise writes go to the first connected organisation.package.jsonstill says@xeroapi/xero-mcp-server. Please don't publish it under that name.Using it
Then point your MCP client at
node /path/to/xero-mcp-server/dist/index.js, with the same environment variables as the README. #200's README section covers theXERO_TOKEN_FILEmode.