Tenants and Connection Lifecycle - Xero
Xero OAuth tenant discovery and explicit connection revocation. Generated from Xero's official OpenAPI repository at immutable commit e952d0bda3628facbf7afc5990ad6a0e7e77bd1e; the exact xero-identity.yaml bytes are SHA-256 pinned. Every tenant-scoped call exposes the required Xero-tenant-id as an explicit approval-bound header argument; OAuth credentials, Authorization, and API authority are never caller inputs. Reads are uncached; all mutations are grant-off and require approval every run. JSON responses preserve unsafe integer literals as exact strings. No work-entity Source is declared because the official response contracts do not guarantee both a mandatory stable identity and a mandatory version field for an honest task, note, or project projection.
What this pack installs
- xero-identity Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.