手动断开Xero账户后,如何检测用户凭证有效性以实现心跳机制?
Great question—since Xero doesn’t offer a webhook or callback to notify you when a user manually disconnects their account via the Settings > General Settings > Connected Apps > Disconnect path you mentioned, the only reliable way to implement a heartbeat-style check is to use a lightweight API endpoint to validate the user’s credentials and connection status.
Here’s the best approach:
Use the GET /connections Endpoint
The GET /connections endpoint is perfect for this use case because it’s designed to return information about the active connections linked to your app. It’s a low-bandwidth request that doesn’t pull large datasets, making it ideal for periodic checks.
How it works:
- When you send a request to this endpoint with the user’s valid access token and tenant ID:
- A 200 OK response means the connection is still active (you’ll get a JSON array with connection details like tenant ID, creation date, etc.).
- A 401 Unauthorized response indicates the access token is invalid, expired, or the user has manually disconnected their account.
Example Request (curl):
curl -X GET https://api.xero.com/connections \ -H "Authorization: Bearer YOUR_USER_ACCESS_TOKEN" \ -H "Xero-tenant-id: YOUR_USER_TENANT_ID"
Handling the Response:
- On a 200 response: Confirm the connection is healthy, no action needed.
- On a 401 response: Mark the user’s Xero connection as disconnected in your system. You can then prompt the user to re-authorize their account if needed.
Key Considerations
- Rate Limits: Xero enforces rate limits (60 requests per minute, 1000 per day). A heartbeat check every 15–30 minutes is more than sufficient and won’t hit these limits.
- Token Refresh: Remember that Xero access tokens expire after 30 minutes. Make sure you’re using a fresh access token (obtained via the refresh token flow) for each heartbeat request—an expired token will return a 401, which you don’t want to confuse with a manual disconnection.
- Error Differentiation: While a 401 usually means disconnection or invalid credentials, you can check the response body for specific error codes to distinguish between expired tokens (which you can auto-refresh) and permanent disconnections (which require user action).
Summary
Since Xero doesn’t provide a callback for manual disconnections, the GET /connections endpoint is the most practical way to implement a heartbeat check. It’s lightweight, reliable, and gives you clear signals about whether the user’s account is still connected to your app.
内容的提问来源于stack exchange,提问作者Igor Rizhyi

