A green run is not a correct month
A sync can finish without error and still have created too few, too many or wrongly posted documents. The measure that matters is a set of counts for the same period: source orders, documents created, orders found already present and orders held with a reason. If created plus held plus already-existing does not equal the source count, something was dropped or duplicated, whatever the run log says.
- Ask your developer to report these counts for every run.
- Compare them with a count made in the accounting system itself.
Who owns what
Name an owner for each of three things: the connection to the accounting system, which a person with the right role must renew when it lapses; the sync code, which your developer or vendor maintains; and the approval of exceptions, which your finance owner decides. A connection with no named owner is easy to miss: Xero says an unused refresh token expires after 60 days, and without an owner nobody is assigned to notice.
Four questions for your developer
What happens when the accounting system rate-limits a run, and where is the record of orders that were skipped? How does the sync recognise an order it has already created, and what does it do when it cannot tell? When was the connection last renewed, and who is told before it lapses? What do held orders look like and who clears them? Vague answers to any of these are the work to do first.
- Xero returns a wait value when a limit is hit, and Intuit advises waiting 60 seconds after a 429.
- A retry that cannot tell whether the first attempt worked is how duplicates start.
Choose the right size of help
A single known fault is a bounded job, for example duplicate prevention (from £395) or pacing and a checkpoint (from £445). Several faults that interact are a project, from £2,950. Watching the sync afterwards is a standing monthly service, £345 a month, which never renews credentials itself. All prices are untested, confirmed after an enquiry, with payment after agreed checks pass and you sign off. Send invented examples and counts first, never credentials, bank details, invoices or customer records; real records are handled only after written agreement through a secure handoff.
Sources and limits
- Xero: OAuth 2.0 FAQ Checked 2026-10-11.
- Access tokens last 30 minutes and unused refresh tokens expire after 60 days, after which the user must authorise the app again.
- Each successful refresh returns a new refresh token that must be stored in place of the old one.
- If a refresh request gets no response, the previous refresh token can be retried for 30 minutes before the user must re-authorise.
- Xero: limits FAQ Checked 2026-10-11.
- At the time checked the FAQ states per-connected-organisation limits of 60 calls per minute, 5 concurrent calls and a daily limit (5,000 per 24 hours), plus 10,000 calls per minute across all organisations for an app.
- Going over a limit returns HTTP 429 with a Retry-After header giving seconds to wait; responses carry headers showing the remaining daily, minute and app-minute allowance.
- Xero suggests combining creates or updates in one request (about 50 items is practical under the 3.5MB size cap), paging (100 records at a time) and the If-Modified-Since header.
- Intuit: API call limits and throttles Checked 2026-10-11.
- The QuickBooks Online REST API allows 500 requests per minute per company and 10 requests per second per company and app, and returns HTTP 429, advising a wait of 60 seconds.
- Batch requests are suggested at up to 30 payloads, with throttling from 40 batch requests per minute per company and app; a query returns at most 1,000 entities.