@mindstone/mcp-server-quickbooks

QuickBooks Online MCP server for Model Context Protocol hosts. Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online through a standardised MCP interface.
Status
Production writes are enabled by default
Every QuickBooks-mutating tool
(create_quickbooks_invoice, create_quickbooks_bill,
create_quickbooks_customer, create_quickbooks_vendor,
create_quickbooks_estimate, send_quickbooks_invoice_email,
update_quickbooks_invoice, update_quickbooks_customer,
update_quickbooks_vendor) executes its write without any opt-in:
capability is enabled by default and the host's tool-approval layer is the
gate. Read-only tools (list_*, get_*, query_*, download_*,
configure_quickbooks) are unaffected.
Versions 0.3.0โ0.4.0 gated these writes behind a QB_ALLOW_PROD_WRITES=1
environment variable. That gate has been removed; the variable is no longer
read and can be deleted from host configurations.
Requirements
One-click install

After clicking the button, your host will prompt you to fill: QUICKBOOKS_CLIENT_ID, QUICKBOOKS_CLIENT_SECRET, QUICKBOOKS_REFRESH_TOKEN, QUICKBOOKS_REALM_ID, QUICKBOOKS_ENVIRONMENT.
Manual config for Claude Desktop / Claude Code / Goose / Continue.dev (QuickBooks Online)
{
"mcpServers": {
"QuickBooks Online": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-quickbooks"
],
"env": {
"QUICKBOOKS_CLIENT_ID": "",
"QUICKBOOKS_CLIENT_SECRET": "",
"QUICKBOOKS_REFRESH_TOKEN": "",
"QUICKBOOKS_REALM_ID": "",
"QUICKBOOKS_ENVIRONMENT": "production"
}
}
}
}
Quick Start
Install & build
cd <path-to-repo>/connectors/quickbooks
npm install
npm run build
npx (once published)
npx -y @mindstone/mcp-server-quickbooks
Local
Configuration
Environment variables
QUICKBOOKS_CLIENT_ID โ Intuit Developer app client ID
QUICKBOOKS_CLIENT_SECRET โ Intuit Developer app client secret
QUICKBOOKS_REFRESH_TOKEN โ OAuth 2.0 refresh token
QUICKBOOKS_REALM_ID โ QuickBooks company (realm) ID
QUICKBOOKS_ENVIRONMENT โ sandbox or production (default: production)
MCP_HOST_BRIDGE_STATE โ optional path to a host bridge state file used for credential management
MINDSTONE_REBEL_BRIDGE_STATE โ backwards-compatible alias for MCP_HOST_BRIDGE_STATE
Host configuration examples
Claude Desktop / Cursor
{
"mcpServers": {
"QuickBooks": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-quickbooks"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
Local development (no npm publish needed)
{
"mcpServers": {
"QuickBooks": {
"command": "node",
"args": ["<path-to-repo>/connectors/quickbooks/dist/index.js"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
Configuration
configure_quickbooks โ Configure QuickBooks Online OAuth credentials
Query
query_quickbooks โ Run a QuickBooks query using QuickBooks Query Language
get_quickbooks_entity โ Get a single entity by type and ID
Reports
get_quickbooks_report โ Run a financial report (ProfitAndLoss, BalanceSheet, CashFlow, AgedReceivables, AgedPayables)
Customers
list_quickbooks_customers โ List customers
create_quickbooks_customer โ Create a new customer
update_quickbooks_customer โ Sparse-update a customer (deactivate with active: false)
Vendors
list_quickbooks_vendors โ List vendors
create_quickbooks_vendor โ Create a new vendor
update_quickbooks_vendor โ Sparse-update a vendor (deactivate with active: false)
Invoices
list_quickbooks_invoices โ List invoices
create_quickbooks_invoice โ Create a new invoice
update_quickbooks_invoice โ Sparse-update invoice header fields (dueDate, memo, privateNote)
send_quickbooks_invoice_email โ Email an invoice to its customer
download_quickbooks_invoice_pdf โ Download an invoice as a PDF (saved to the system temp directory)
Estimates
list_quickbooks_estimates โ List estimates (quotes)
create_quickbooks_estimate โ Create a new estimate
Bills
list_quickbooks_bills โ List bills (accounts payable)
create_quickbooks_bill โ Create a new bill
Employees
list_quickbooks_employees โ List employees
Accounts
list_quickbooks_accounts โ List chart of accounts
Untrusted content envelopes
Text authored inside QuickBooks (customer/vendor display names, memos, line
descriptions, report cells) is attacker-influenceable, so the connector wraps
it in <untrusted-content source="quickbooks:โฆ"> envelopes before returning
it to the model. Typed entity payloads are sanitized deny-by-default: every
string is enveloped โ including strings inside arrays, which have no key
context โ unless its key is a narrow structural predicate (IDs, SyncToken,
dates/timestamps, enums) and its value passes a shape guard. query_quickbooks,
get_quickbooks_entity, and reports envelope every string key and value
wholesale. Structural values such as Id, SyncToken, dates, and
amounts are left untouched so they stay usable as inputs to follow-up calls.
Licence
FSL-1.1-MIT โ Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.