@mindstone/mcp-server-quickbooks
v0.4.2
Published
QuickBooks Online MCP server for Model Context Protocol hosts — invoices, bills, customers, vendors, accounts
Readme
@mindstone/mcp-server-quickbooks
QuickBooks Online MCP server for Model Context Protocol hosts. Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online through a standardised MCP interface.
Status
- Version: 0.4.2 · npm
- Auth: OAuth (
QUICKBOOKS_REFRESH_TOKEN) - Tools: 21 (customers, vendors, invoices, bills, estimates, reports)
- Surface: cloud-api
- Machine-readable:
STATUS.json
Production writes are enabled by default
Every QuickBooks-mutating tool
(create_quickbooks_invoice, create_quickbooks_bill,
create_quickbooks_customer, create_quickbooks_vendor,
create_quickbooks_estimate, send_quickbooks_invoice_email,
update_quickbooks_invoice, update_quickbooks_customer,
update_quickbooks_vendor) executes its write without any opt-in:
capability is enabled by default and the host's tool-approval layer is the
gate. Read-only tools (list_*, get_*, query_*, download_*,
configure_quickbooks) are unaffected.
Versions 0.3.0–0.4.0 gated these writes behind a QB_ALLOW_PROD_WRITES=1
environment variable. That gate has been removed; the variable is no longer
read and can be deleted from host configurations.
Requirements
- Node.js 20+
- npm
One-click install
After clicking the button, your host will prompt you to fill: QUICKBOOKS_CLIENT_ID, QUICKBOOKS_CLIENT_SECRET, QUICKBOOKS_REFRESH_TOKEN, QUICKBOOKS_REALM_ID, QUICKBOOKS_ENVIRONMENT.
{
"mcpServers": {
"QuickBooks Online": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-quickbooks"
],
"env": {
"QUICKBOOKS_CLIENT_ID": "",
"QUICKBOOKS_CLIENT_SECRET": "",
"QUICKBOOKS_REFRESH_TOKEN": "",
"QUICKBOOKS_REALM_ID": "",
"QUICKBOOKS_ENVIRONMENT": "production"
}
}
}
}Quick Start
Install & build
cd <path-to-repo>/connectors/quickbooks
npm install
npm run buildnpx (once published)
npx -y @mindstone/mcp-server-quickbooksLocal
node dist/index.jsConfiguration
Environment variables
QUICKBOOKS_CLIENT_ID— Intuit Developer app client IDQUICKBOOKS_CLIENT_SECRET— Intuit Developer app client secretQUICKBOOKS_REFRESH_TOKEN— OAuth 2.0 refresh tokenQUICKBOOKS_REALM_ID— QuickBooks company (realm) IDQUICKBOOKS_ENVIRONMENT—sandboxorproduction(default:production)MCP_HOST_BRIDGE_STATE— optional path to a host bridge state file used for credential managementMINDSTONE_REBEL_BRIDGE_STATE— backwards-compatible alias forMCP_HOST_BRIDGE_STATE
Host configuration examples
Claude Desktop / Cursor
{
"mcpServers": {
"QuickBooks": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-quickbooks"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}Local development (no npm publish needed)
{
"mcpServers": {
"QuickBooks": {
"command": "node",
"args": ["<path-to-repo>/connectors/quickbooks/dist/index.js"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}Tools (21)
Configuration
configure_quickbooks— Configure QuickBooks Online OAuth credentials
Query
query_quickbooks— Run a QuickBooks query using QuickBooks Query Languageget_quickbooks_entity— Get a single entity by type and ID
Reports
get_quickbooks_report— Run a financial report (ProfitAndLoss, BalanceSheet, CashFlow, AgedReceivables, AgedPayables)
Customers
list_quickbooks_customers— List customerscreate_quickbooks_customer— Create a new customerupdate_quickbooks_customer— Sparse-update a customer (deactivate withactive: false)
Vendors
list_quickbooks_vendors— List vendorscreate_quickbooks_vendor— Create a new vendorupdate_quickbooks_vendor— Sparse-update a vendor (deactivate withactive: false)
Invoices
list_quickbooks_invoices— List invoicescreate_quickbooks_invoice— Create a new invoiceupdate_quickbooks_invoice— Sparse-update invoice header fields (dueDate, memo, privateNote)send_quickbooks_invoice_email— Email an invoice to its customerdownload_quickbooks_invoice_pdf— Download an invoice as a PDF (saved to the system temp directory)
Estimates
list_quickbooks_estimates— List estimates (quotes)create_quickbooks_estimate— Create a new estimate
Bills
list_quickbooks_bills— List bills (accounts payable)create_quickbooks_bill— Create a new bill
Employees
list_quickbooks_employees— List employees
Accounts
list_quickbooks_accounts— List chart of accounts
Untrusted content envelopes
Text authored inside QuickBooks (customer/vendor display names, memos, line
descriptions, report cells) is attacker-influenceable, so the connector wraps
it in <untrusted-content source="quickbooks:…"> envelopes before returning
it to the model. Typed entity payloads are sanitized deny-by-default: every
string is enveloped — including strings inside arrays, which have no key
context — unless its key is a narrow structural predicate (IDs, SyncToken,
dates/timestamps, enums) and its value passes a shape guard. query_quickbooks,
get_quickbooks_entity, and reports envelope every string key and value
wholesale. Structural values such as Id, SyncToken, dates, and
amounts are left untouched so they stay usable as inputs to follow-up calls.
Licence
FSL-1.1-MIT — Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.
