← All guides

Is it safe to connect an app to Xero? Permissions explained

Every tool that plugs into your accounting asks for access first, on a consent screen most people click past. It is worth reading. Here's what those permissions actually mean in Xero, Fergus and Google, how to check what you have already granted, and how to take it back.

What a permission scope is

When you connect an app, you are not handing over your password. You are granting a scope: a named slice of your account the app may reach, such as "read your invoices". The provider issues the app a token carrying only those scopes. Nothing outside them is available, however the app is built.

That is why the consent screen matters. It is the full list of what the app can do, and the only place you see it before you agree.

Read or write — the line that matters

Scopes come in two kinds, and the difference is the whole story.

  • Read lets the app look. A tool that reads your invoices can see who owes what. It cannot change a number.
  • Write lets the app change your records. Depending on the scope, that can mean editing an invoice, altering a contact, or recording a payment.

Most apps need far less write access than they ask for. A reporting dashboard should never need to edit an invoice. If a tool asks to write and cannot tell you which feature needs it, that is a fair question to put to them.

It is all or nothing

On Xero and Google alike, you cannot tick some permissions and refuse others. The app names the set it wants, and you either grant the lot or cancel. So the decision is not "which of these am I comfortable with" but "do I trust this company with all of it".

That makes the length of the list a real signal. An app asking for six narrow scopes is easier to judge than one asking for broad access to your whole ledger.

What to ask before you click Allow

  1. Does each permission match a feature you want? Read access to invoices for an invoice tool, yes. Access to your payroll, no.
  2. Can it write, and to what? Assume anything writable will be written to.
  3. Who is the company? A named business with a privacy policy and a support address beats an anonymous app.
  4. How do you disconnect? Check it is one click on the provider's side, not an email request.
  5. What happens to the data when you leave? Their policy should say how long it is kept.

How to check what you've already granted

Most businesses have connected more apps than they remember, and a trial from two years ago may still hold a live token. Both of these take a minute.

  • Xero: click your organisation name, then Settings → Connected apps. Every app with access is listed, and the menu beside each one has Disconnect.
  • Google: open your Google account's third-party access page, which lists every app and what it can reach, with a remove button.

Revoking is immediate and safe. It invalidates the token, so the app stops reading. It does not delete anything in your accounts, and you can always reconnect.

Do this yearly, and whenever you stop using a tool. An unused connection is the one nobody notices.

Xero: the permissions are narrower than they used to be

Xero has moved to fine-grained scopes, so a well-built app now asks for something specific like "read invoices" rather than blanket access to your transactions. Apps registered from March 2026 can only use the narrow ones.

In practice that means a modern Xero connection should show you a readable list. If a consent screen still asks for sweeping access, the app is either old or asking for more than it needs. Xero's own reference on how scopes work spells out what each one covers.

Fergus and other token-based tools

Not every system uses a consent screen. Fergus, the job-management software many New Zealand trades run on, is reached with an API token you generate in your own account settings and paste into the other tool.

That is worth understanding, because a token is blunter than a scope. There is no screen listing what the other tool may do, and a token generally carries the permissions of whoever created it. So the care moves to you: generate one only for a tool you trust, keep it out of email and shared documents, and revoke it in Fergus when you stop using the tool. If the tool offers a proper OAuth connection instead, prefer it.

Gary reads invoices from Xero today, so this is background rather than a step you need for us.

Google and Microsoft: watch the mail scopes

Signing in with Google or Microsoft is the mildest thing on this page. A sign-in asks only for your name and email address, to know who you are. It gives the app no access to your mail or files.

Permission to send mail as you, or to read your inbox or calendar, is a different matter. Those are sensitive scopes, and Google puts apps that request them through extra review. Grant them only where sending on your behalf is the point of the tool, and check the wording: "read, compose and send" is much broader than "send".

What Gary asks for

We ask for as little as the job needs, and every permission maps to a feature you can see.

Gary reads your invoices and customers, to know who to chase and what is owed; your payments, so a paid invoice stops being chased; your organisation's base currency, so amounts show correctly; and your bank balance from your Balance Sheet, so our fee is only ever charged once you have actually been paid.

Gary writes one thing, and only if you switch it on: a note on an invoice recording what happened on a call. It is off by default.

Gary never moves money, never takes or changes a payment, and never edits your customer records. Your contacts are read-only — a phone number you add in Gary stays with us and is never pushed back to Xero. Disconnect in Xero and Gary stops reading straight away.

Our privacy and data page covers the rest: what we store, how long we keep it, who controls it, and how to have it deleted. What Gary's built on names the services involved.

If you are still deciding whether you need a phone step at all, start with Xero invoice reminders and where email stops working.

Common questions

Is it safe to connect an app to Xero?

Connecting through Xero's official flow is safe in itself — you never share your password, and access is limited to the permissions listed on the consent screen. The risk is the company you are granting it to, not the mechanism. Read the list, prefer read-only where it will do, and disconnect anything you have stopped using.

Can an app see everything in my Xero?

Only what its scopes allow. An app granted invoice and contact read access cannot see your payroll or your bank feed. Xero's consent screen is the authoritative list, and Settings → Connected apps shows it again later.

Can a connected app change my accounts?

Only with a write scope, and only in the area that scope names. An app with read-only access cannot alter anything. If you are unsure what a tool was granted, disconnect it and reconnect, reading the screen this time.

How do I remove an app's access to my Xero?

Click your organisation name, go to Settings → Connected apps, then Disconnect beside the app. It takes effect immediately and changes nothing in your accounting records.

What does offline access mean on a consent screen?

It lets the app refresh its own access so it keeps working without you reconnecting every half hour. It adds no new permissions — it only stops the ones you granted from expiring. Any tool that syncs in the background needs it.

Should I connect an app with my own login or a shared one?

Use your own named login. Access tied to a shared account is impossible to audit and outlives whoever set it up. If the person who connected a tool leaves, review what they granted.

Let Gary make the calls

Gary connects to Xero, rings your overdue customers in a friendly voice during business hours, and tells you what it found. Setup takes about five minutes.

Get started