Ledgitify requests the minimum permissions it needs to build your budget reports, and every one
of them is read-only. Ledgitify never creates, edits, voids, or deletes anything in your Xero
organisation.
Ledgitify makes no changes in Xero. There is no scenario in which connecting Ledgitify alters
your accounts, invoices, contacts, or journals. It only reads.
Identity permissions
Accounting permissions (all read-only)
What Ledgitify does not request
- No write access of any kind. There is no
.write scope in the list above.
- No payroll access by default. Payroll is a future feature and is only requested once
separately approved, so payroll data is not accessed unless you explicitly enable it.
How your access is stored and protected
- Ledgitify stores a Xero access token, never your Xero password.
- Tokens are refreshed automatically before they expire (Xero access tokens last 60 minutes).
- If you disconnect, or revoke access from within Xero, Ledgitify detects it, stops syncing, and
clears the stored token. See Disconnecting Xero.