List Contacts (V2)
GET/api/xero/v2/contacts
Paginated list of Xero contacts with advanced filtering.
Any valid API token can call this endpoint — no specific scope required. Manage tokens.
Authentication: Requires Bearer token.
Sort options: id, Name, ContactID, created_at
Filterable columns: id (numeric), Name (text), ContactID (text), link_type (text — polymorphic FQN e.g. App\Models\Supplier)
Also includes computed fields: IsCustomer, IsSupplier (extracted from JSON object)
Request
Responses
- 200
- 401
- 403
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.