Vibe coding your first app: a practical guide for accountants
We built a Xero file-readiness dashboard in Lovable in an afternoon. Here’s how, the moment it confidently got the bank reconciliation wrong, and what it takes before your team relies on an AI-built app.
Part of our AI in accounting coverage. See the full AI for accountants guide →
By Nathan Harper, founder of AhoyAhoy, The Firm’s development partner for accountants who want to build their own apps.
Every practice has a “wouldn’t it be great if…” list. A lodgement tracker that isn’t a spreadsheet only one person understands. A Div 7A calculator. One screen showing which client files are ready for year-end.
Until recently, that list stayed a list. Now there’s vibe coding: you describe the app in plain English, an AI tool like Lovable writes the code, and you keep steering until it works. No programming background needed.
Accountants are better placed for this than most. A good app brief is rules, inputs, outputs and exceptions, which is how you already think.
We built a real one to see what it takes. Here’s what worked, what broke, and where the line sits between a fun afternoon and something you’d trust with client data.
Working papers vs signed financials
One distinction decides almost everything else:
- A prototype is your working papers. Rough, for you, fine to throw away. Vibe coding is brilliant at this.
- A production app is the signed financials. Other people rely on it, it touches client data, and it has to keep working when nobody’s watching.
Most of the trouble people get into comes from treating the first like the second.
The build: “How ready is that file?”
We wanted one screen listing every client connected to Xero, each marked ready, needs attention or at risk.
The obvious measure is unreconciled bank lines. This is where Xero said no. Its API doesn’t share them, because they’re raw bank data covered by consumer data rights. The AI tool won’t warn you about this. It can write the code, but it can’t change what the platform allows.
So we used signals Xero does share:
- Suspense or clearing accounts that aren’t zero
- Draft invoices and bills older than 14 days
- Receivables and payables older than 120 days
- Lock dates behind the last month-end
Five steps in Lovable
1. Write the brief like a scope of work. Who uses it, what it shows, what drives each figure, what it must never do (change anything in Xero) and what “done” looks like. Ten minutes here saves hours later.
2. Connect Xero. Create a web app at developer.xero.com, paste Lovable’s redirect URI in exactly, and tick the same scopes in both places or the connection fails. Treat the client secret like a password. Budget 20 minutes; you only do it once.
3. Build on the Demo Company. Make your mistakes on data that belongs to nobody.
4. Start with one prompt, then change one thing at a time. Our first version threw a Xero error and still marked the Demo Company “At Risk”. Two prompts fixed it: paste the exact error back in, then “if a request fails, show ‘Couldn’t check’. Never calculate a status from incomplete data.”
5. Test it like an auditor. This is where it got interesting.
The dashboard said both bank accounts were up to date. Xero said 28 items to reconcile and a $13,472.70 difference.
Without the bank lines, the app had improvised: it used the date of the last reconciled transaction instead. The answer looked authoritative. It was wrong, and nothing flagged it. Now picture that dashboard rolled out to a team of 20.
Vibe-coded apps rarely fail loudly. They fail plausibly.
So tick and bash it. Check the figures against Xero for a few real files, ask the AI to explain each calculation in plain English, and make sure it catches the file you know is a mess. We removed the bank score altogether; the dashboard now says “check in Xero”. If a number can’t be verified, it doesn’t belong on the screen.
Before you roll it out
Security. “Read-only” is a rule in the code, not a lock on the door. Lovable’s Xero connection can still create and edit invoices, bills and contacts. One person’s login reaches every connected client file, and without a sign-in, anyone with the link sees everything.
Scale. Client files connect one at a time, and whoever connects them needs the right role in each. Xero also allows only two uncertified apps per organisation, so some clients can’t be connected at all. (Lovable told us new files would appear automatically. They don’t.)
Cost. Since March 2026, Xero charges developers by how many organisations an app connects to:
| Tier | Client files | AUD a month, ex GST | Catch |
|---|---|---|---|
| Starter | Up to 5 | Free | 1,000 API calls per file a day |
| Core | Up to 50 | $35 | 10 GB of data a month |
| Plus | Up to 1,000 | $245 | Xero app certification |
| Advanced | Up to 10,000 | $1,445 | Annual security assessment |
Past 50 client files you need certification, which is a real undertaking for an internal tool.
Maintenance. Xero’s API, tax rates and Lovable all change, and each change can quietly break something. When it breaks in March, who fixes it?
Your time. Shaye Thyer puts it well: put your tinkering on a timesheet at your own charge-out rate and look at the number. Sometimes an existing app does the job for a few hundred dollars a year.
Green, amber, red
- Green: go for it. Personal tools, calculators, anything on the Demo Company.
- Amber: slow down. Shared with your team or connected to a few real client files. Add a sign-in, test it like an auditor and name an owner.
- Red: get help. Client-facing, sensitive data, dozens of files, or something the practice will depend on. Get a proper review before anyone relies on it.
Where AhoyAhoy fits in
In one afternoon the AI didn’t know Xero keeps bank lines private, invented a workaround that looked right and wasn’t, and described its own connection model incorrectly. None of it announced itself. Each was caught by someone who knew Xero’s API.
That’s the role we play. We’re not here to replace your experiments, just to make sure they land somewhere useful:
- A sanity check before you build. Half an hour can save a weekend, or tell you a certified app already does it.
- A Production Readiness Review. A fixed-price review of your AI-built app across security, code quality, scalability, performance, maintainability and best practice, before your team relies on it.
- Taking it to production. Proper sign-in, secure tokens, many client files and Xero certification. Your prototype becomes the brief.
- Owning it long-term, so “who fixes this in March?” has an answer.
AhoyAhoy has been a certified Xero development partner since 2018, is ISO 27001 certified, and builds Xero and XPM integrations for practices every day.
Built something and want it checked? Book a Production Readiness Review, or tell us about your idea before you start.
Go build something
Pick one small, annoying problem. Write the brief like a scope of work, build it on the Demo Company, then test it like an auditor. Not ready for client data? A lodgement tracker, a Div 7A calculator or an onboarding checklist each makes a good first app. For more ideas, see what accountants are building with AI and how firm owners are vibe coding Karbon integrations.
Your first app won’t be perfect. It just needs to show you what’s possible, and what it would take to do it properly. The AI can write the code, but it takes an accountant to notice when a dashboard says “up to date” and Xero says 28 items.
Nathan Harper is the founder of AhoyAhoy, a certified Xero development partner and The Firm’s development partner for accountants building their own apps.
Vibe CodingAIXeroLovableApp DevelopmentSecurity