Stitchflow
Xero logo

Xero SCIM guide

Connector Only

How to automate Xero user provisioning, and what it actually costs

Summary and recommendation

Xero, the major cloud accounting platform, provides no native SCIM provisioning support on any plan—despite over 10 years of customer requests for enterprise identity features. While Xero offers basic SAML SSO through third-party providers like miniOrange, this only handles authentication and leaves IT teams manually managing user accounts, permissions, and offboarding in a system that handles sensitive financial data.

This creates a significant security and compliance gap for organizations using Xero. Accounting platforms require strict access controls due to the sensitive nature of financial information, yet IT admins must rely on manual processes to provision new accountants and bookkeepers, update roles when employees change responsibilities, and ensure proper deactivation when staff leave. Without automated provisioning, there's no audit trail for user lifecycle events and substantial risk of orphaned accounts retaining access to financial systems.

The strategic alternative

Stitchflow provides SCIM-level provisioning through resilient browser automation for Xero without requiring any custom development work. Works regardless of your Xero plan and integrates with any IdP (Okta, Entra, Google Workspace, OneLogin). Flat pricing under $5K/year, regardless of team size.

Quick SCIM facts

SCIM available?No
SCIM tier requiredN/A
SSO required first?Yes
SSO available?Yes
SSO protocolSAML 2.0
DocumentationNot available

Supported identity providers

IdPSSOSCIMNotes
OktaSSO integration available but no SCIM provisioning. Xero lacks native SCIM support.
Microsoft Entra IDVia third-partyNo native Entra ID integration. Third-party solutions required for SSO.
Google WorkspaceVia third-partyNo native support
OneLoginVia third-partyNo native support

The cost of not automating

Without SCIM (or an alternative like Stitchflow), your IT team manages Xero accounts manually. Here's what that costs:

Source: Stitchflow aggregate data across apps with 2+ instances, normalized to 500 employees
Orphaned accounts (ex-employees with access)7
Unused licenses12
IT hours spent on manual management/year101 hours
Unused license cost/year$3,925
IT labor cost/year$6,088
Cost of compliance misses/year$1,741
Total annual financial impact$11,754

The Xero pricing problem

Xero gates SCIM provisioning behind premium plans, forcing significant cost increases for basic user management.

Tier comparison

PlanPriceSSOSCIM
Starter$15/month
Growing$42/month
Established$78/month

Pricing and provisioning options

PlanPriceSSOSCIM
Starter$15/month
Growing$42/month
Established$78/month

Third-party SSO options

miniOrange SSO gateway
~$2-4/user/month additional cost
AuthDigital
Custom pricing for Xero SSO bridge
Direct SAML integration
Not supported natively

What this means in practice

IT teams managing Xero access face a completely manual provisioning process:

User onboarding: Every new hire requires manual account creation in Xero, manual role assignment, and manual invitation emails. No automated provisioning from your IdP.

Access changes: Role changes, department moves, or permission updates require manual intervention in both your IdP and Xero separately.

Offboarding: Departing employees must be manually deactivated in Xero since there's no SCIM to automatically suspend access when they're disabled in your directory.

Audit compliance: No centralized logs or conditional access policies. You can't enforce geo-blocking, device compliance, or session controls on Xero access.

Additional constraints

Third-party dependency risk
SSO solutions like miniOrange create an additional failure point between your IdP and Xero
No sign-in telemetry
Zero visibility into who's accessing Xero, when, or from where
Cost complexity
Third-party SSO adds $24-48/user/year on top of Xero's base pricing
Limited conditional access
Can't enforce MFA policies, device compliance, or location restrictions
Feature request fatigue
The SSO feature has been "under consideration" for over a decade with no delivery timeline

Summary of challenges

  • Xero does not provide native SCIM at any price tier
  • Organizations must rely on third-party tools or manual provisioning
  • Our research shows teams manually provisioning this app spend significant hidden costs annually

What Xero actually offers for identity

No Native SSO or SCIM Support

After 10+ years of customer requests, Xero still provides no native identity management features:

FeatureSupported?
SAML SSO❌ No
OIDC SSO❌ No
SCIM provisioning❌ No
JIT provisioning❌ No
Conditional access❌ No
Sign-in logs❌ No

The reality: Despite being a major cloud accounting platform trusted by millions of businesses, Xero has no enterprise identity features whatsoever.

Third-Party SSO Workarounds

Some organizations use third-party solutions like miniOrange or AuthDigital to bridge the gap:

Cost
Additional $3-8/user/month on top of Xero subscription
Complexity
Requires separate vendor relationship and support
Limitations
No native audit logs, limited conditional access controls
Risk
Relies on external service for critical accounting system access

Okta Integration (Password Vaulting Only)

The official Okta Integration Network listing for Xero shows:

FeatureSupported?
SAML SSO❌ No
SWA (password vaulting)✓ Yes
Create users❌ No
Update users❌ No
Deactivate users❌ No

Translation: The Okta "integration" only stores and auto-fills passwords—not true federated authentication or any provisioning capabilities.

The Enterprise Gap

For a platform handling sensitive financial data, Xero's lack of identity controls creates significant security and compliance challenges:

No centralized user lifecycle management
No conditional access based on location or device
Manual password management across all users
No audit trail for authentication events
Terminated employees retain access until manually disabled

What IT admins are saying

Community sentiment on Xero's enterprise identity features is overwhelmingly frustrated after 10+ years of unfulfilled requests:

  • No native SAML SSO support despite being a major cloud accounting platform
  • Complete absence of SCIM provisioning capabilities
  • No centralized authentication telemetry or conditional access controls
  • Forced reliance on expensive third-party SSO solutions like miniOrange

Feature requested for over 10 years

Multiple community posts on Xero Product Ideas

No native conditional access or geo-blocking

IT admin feedback on enterprise security gaps

Login enable Windows Azure Active Directory Single Sign-On... This has been on the wish list for years

Xero Product Ideas forum thread with hundreds of votes

The recurring theme

Xero remains stubbornly behind on enterprise identity features that competitors implemented years ago, forcing IT teams to either manage accounts manually or pay for third-party workarounds just to get basic SSO functionality.

The decision

Your SituationRecommendation
Small finance team (<10 users) with stable staffManual management acceptable, focus on strong passwords
Growing business (10-50 users) needing accounting access controlsUse Stitchflow: automation essential for financial data security
Enterprise with compliance requirements (SOX, audit trails)Use Stitchflow: automation essential for compliance documentation
Multi-entity organizations with complex accounting structuresUse Stitchflow: automation strongly recommended for scale
Companies requiring SSO integration with existing identity systemsUse Stitchflow: Xero lacks native SSO despite 10+ years of requests

The bottom line

Xero is a leading cloud accounting platform, but it's stuck in the identity stone age—no SCIM, no native SSO, despite a decade of enterprise requests. For organizations that need automated provisioning and modern identity controls for their financial data, Stitchflow bridges this critical gap.

Automate Xero without third-party complexity

Stitchflow delivers SCIM-level provisioning through resilient browser automation, backed by 24/7 human in the loop for Xero at <$5K/year, flat, regardless of team size.

Works alongside or instead of native SCIM
Syncs with your existing IdP (Okta, Entra ID, Google Workspace)
Automates onboarding and offboarding
SOC 2 Type II certified
24/7 human-in-the-loop monitoring
Book a Demo

Technical specifications

SCIM Version

Not specified

Supported Operations

Not specified

Supported Attributes

No native SAML SSO supportNo native SCIM supportNo sign-in logs or conditional accessSSO feature requested for 10+ yearsThird-party solutions required

Plan requirement

Not specified

Prerequisites

Not specified

Key limitations

  • No native SAML SSO support
  • No native SCIM support
  • No sign-in logs or conditional access
  • SSO feature requested for 10+ years
  • Third-party solutions required

Documentation not available.

Configuration for Okta

Integration type

Okta Integration Network (OIN) app

Prerequisite

SSO must be configured before enabling SCIM.

Where to enable

Okta Admin Console → Applications → Xero → Sign On

SSO integration available but no SCIM provisioning. Xero lacks native SCIM support.

Use Stitchflow for automated provisioning.

Unlock SCIM for
Xero

Xero doesn't offer SCIM. Get an enterprise-grade SCIM endpoint in your IdP, even without native support.

See how it works
Admin Console
Directory
Applications
Xero logo
Xero
via Stitchflow

Last updated: 2026-01-11

* Pricing and features sourced from public documentation.

Keep exploring

Related apps

Wave logo

Wave

No SCIM

Finance / Accounting

ProvisioningNot Supported
Manual Cost$11,754/yr

Wave Accounting, the free accounting platform designed for small businesses, does not support SCIM provisioning or native SSO on any plan. While third-party password managers like OneLogin and Okta can provide password-based authentication through vaulting, this isn't true SAML federation. Wave's architecture is fundamentally built for manual user management by small business owners, not enterprise identity integration. This creates significant challenges for organizations that have adopted Wave but need centralized user lifecycle management. Without SCIM support, IT teams must manually create, update, and deactivate user accounts in Wave, creating compliance gaps and administrative overhead. The lack of native SSO means users must maintain separate credentials, increasing security risks and password fatigue.

View full guide
Zoho Books logo

Zoho Books

SCIM Tax

Finance / Accounting

SCIM StatusIncluded
Manual Cost$11,754/yr

Zoho Books, the accounting software for small businesses, does not offer native SCIM provisioning. Instead, user provisioning must be managed through Zoho Directory or Zoho One at the enterprise level, creating a complex multi-step process where IT teams must first provision users to the broader Zoho ecosystem before they can access Books specifically. This architecture means you cannot directly provision users to Zoho Books alone—you're forced into Zoho's broader suite management approach, even if Books is your only Zoho application. For organizations that need precise control over accounting system access, this indirect provisioning model creates unnecessary complexity and potential security gaps. The lack of direct SCIM support becomes particularly problematic for finance teams where access control is critical. Without automated provisioning, IT teams must manually coordinate user access across multiple Zoho administrative interfaces, increasing the risk of orphaned accounts or improper permissions in your accounting system. When employees change roles or leave the company, the manual deprovisioning process creates compliance risks in a system that handles sensitive financial data.

View full guide
6sense logo

6sense

No SCIM

B2B Revenue Intelligence / ABM

ProvisioningNot Supported
Manual Cost$11,754/yr

6sense, the B2B revenue intelligence platform, has paused SCIM provisioning for new customers until Q4 2026. While existing customers with SCIM enabled can continue using it, new implementations are limited to JIT (Just-In-Time) provisioning through SAML SSO. This creates a significant gap for IT teams managing revenue intelligence access, as JIT only creates users on first login and provides minimal attribute mapping (email, first name, last name only). For an enterprise platform with typical pricing of $55,000-$130,000 annually, the absence of automated user lifecycle management is a substantial limitation. The lack of SCIM until Q4 2026 forces IT teams into manual provisioning workflows for a platform handling sensitive revenue data. While SAML SSO handles authentication, it doesn't address user lifecycle events like role changes, department transfers, or offboarding. This creates compliance risks in revenue teams where access to prospect data and sales intelligence must be tightly controlled. The nearly two-year wait for SCIM restoration means organizations implementing 6sense today face manual user management for the foreseeable future.

View full guide