LedgerFix

Accounting software error codes, explained with the fix first — QuickBooks, Sage 50, Xero.

Xero Error Codes 400, 401, 403, 404 and 500, Decoded

Last updated: September 28, 2026

Share:X / TwitterFacebookLinkedInWhatsAppEmail

Xero's error style is different from QuickBooks' numbered codes: Xero surfaces the standard HTTP status codes — the same numbers the web itself runs on — plus validation messages like "account must be valid." Once you read the number as a category, these errors become surprisingly orderly. Here is each code in the family, what it means in Xero specifically, and what you can actually do about it.

400 — Bad request (usually your data)

The request itself was malformed. In day-to-day Xero this is almost always validation: an import row with a bad date format, a bank rule pointing at an archived account, a transaction with an amount field Xero cannot parse. The screen or import report usually names the field.

What to do: fix the named field or row and resubmit. For imports, correct the row in the file (or the mapping) rather than retrying the whole file — Xero's import reports identify the exact rows that failed with their reasons.

Authentication failed: expired login session, or — the common modern case — a bank-feed or integration consent that has lapsed. Apps connected via the Xero API show 401s when their token expires without refresh.

What to do: sign in again; for bank connections, re-authorize the feed from the Banking area; for third-party add-ons, reconnect the app from Settings → Connections. A 401 that persists with correct credentials is a support matter, but it is rare.

403 — Forbidden (permissions, not password)

You are authenticated but not allowed the action — a standard user without the adviser role trying a settings change, or an employee-level login touching payroll.

What to do: an organization adviser grants the role (Settings → Users), or the action is performed by someone who holds it. 403 is policy, not malfunction: nothing is broken.

404 — Not found

The record the request referenced does not exist (deleted invoice, removed contact, wrong URL in a bookmark or integration). Integrations hit 404s when a Xero record they cached has been deleted on the other side.

What to do: find the record afresh (search the contact/invoice) rather than following the stale link; for integrations, resync so they re-fetch current record IDs. A 404 on Xero's own pages after an update usually means a stale bookmark — navigate from the dashboard instead.

500 (and 502/503/504) — Xero's side

A server fault. 500 is a general failure; 502/504 typically appear as gateway timeouts under load or during incidents.

What to do: wait, then retry. Check the Xero status page for an incident before doing anything else. If an action 500s repeatedly while the status page is green, capture the exact steps and contact Xero support — but do not rebuild data on the suspicion that 500s imply corruption; they do not.

The one-click triage table

Code Whose fault First move
400 Yours (the data) Fix the named field/row
401 Credentials/consent Re-login or re-authorize the connection
403 Permissions Ask an adviser to grant the role
404 Stale reference Find the record afresh; resync integrations
500–504 Xero's Retry after checking status.xero.com

That table is 90% of Xero error handling: read the number, apply the category's move, escalate only what survives it.

Meanings follow Xero's help-center documentation of HTTP status errors and standard HTTP semantics. This page is general information, not Xero support.

Frequently asked questions

What do Xero error codes 400 to 500 mean?

Xero reuses the standard HTTP status codes: 400 means the request was malformed (often a bad import file or form entry), 401 an authentication problem, 403 your user lacks permission for that action, 404 the record was not found, and 500 a fault on Xero's side. Reading the number as a category is the whole trick.

Which Xero errors are mine to fix?

400, 401, 403 and 404: something in your request, login or permissions is wrong, and a correction on your side fixes them. 500-family errors are Xero server faults — retry later, check the Xero status page, and only then contact support.

What is the 'account must be valid' Xero error?

A validation error (shown with a 400) where a transaction references an account that is inactive, archived or of the wrong type — commonly in imports and bank rules. Fix the referenced account in Settings → Chart of accounts, or correct the row, then retry.

Why does Xero 401 happen with a connected bank?

The bank-feed authorization token has expired or been revoked. Re-authenticate the bank connection from the Banking menu — the 401 clears the moment the fresh consent is stored.

Do 500 errors mean my data is at risk?

No. A 500 means the server refused or failed to complete the request; nothing about it implies data loss. Retry the action after checking the Xero status page for an incident.

Keep reading