How to get your QuickBooks API Key

Skip Intuit's 500-page docs and get your QuickBooks API keys in 7 steps - with every gotcha that'll waste your week spelled out.

Saurabh RaiSaurabh Rai

Saurabh Rai · Developer Relations Engineer, Apideck

8 min readView as .md
How to get your QuickBooks API Key

What’s QuickBooks?

QuickBooks is Intuit’s accounting software that owns the small business market because it’s cheaper than everything else, and your accountant already knows it. There’s QuickBooks Online (cloud) and QuickBooks Desktop. Most businesses use it until they hit about $10M revenue, then graduate to something that doesn’t crash during month-end close. You’re here because you need to sync data between QuickBooks and your app. Here’s how to get API access without reading Intuit’s 500-page documentation.

Note: QuickBooks doesn't use traditional API keys. Instead, it uses OAuth 2.0 authentication with Client ID and Client Secret credentials. This guide walks you through obtaining those credentials and setting up the OAuth flow.

Prerequisites

  • QuickBooks Online account (Desktop API is different hell entirely)

  • Intuit Developer account (free but annoying)

  • Know if you’re building for one company or many.

Step 1: Create an Intuit Developer Account

Go to https://developer.intuit.com and sign up. Use an email you’ll still have access to in 2 years when something breaks.

Step 2: Create Your App

My Hub → App dashboard, then the + card to create an app

Pick your scopes on the permissions page: com.intuit.quickbooks.accounting is what 90% of you want. Only add the payments scope if you process payments.

Name your app something memorable. You’ll have 50 test apps eventually.

Step 3: Get Your Credentials

Your app dashboard shows:

  • Client ID: Public identifier for your app
  • Client Secret: Turn on the “Show credentials” switch and copy it somewhere secure

Development vs Production:

  • Development: For testing, works with sandbox companies
  • Production: For real data, requires app assessment (yes, really)

Both have different keys. Don’t mix them up.

Step 4: Set OAuth Settings

In your app settings → Redirect URIs

Add your callback URLs (Development and Production are listed separately):

  • Development: http://localhost:8080/callback
  • Production: https://yourapp.com/auth/quickbooks/callback

Plain-HTTP localhost only works with development keys. Production needs HTTPS. No exceptions.

Step 5: Configure Scopes

Scopes live in two places: the app's Permissions page in the portal (set in Step 2, editable later), and the scope parameter of the authorization URL you send users to (https://appcenter.intuit.com/connect/oauth2), space-separated. Only request scopes you've enabled on the app.

Common ones you’ll need:

  • com.intuit.quickbooks.accounting: Read/write all accounting data
  • com.intuit.quickbooks.payment: Process payments
  • openid: Required for any of the user info scopes below (OpenID Connect)
  • email: User’s email address
  • profile: User’s given and family name
  • address: User’s physical address
  • phone: Nobody uses this

Pick the minimum. Users see these on consent screen and get paranoid. If you still have second thoughts on how to do this, we have this visual guide for you.

Step 6: Connect to a Company

For Development:

  1. Use the sandbox company Intuit created with your developer account (you can add up to 10)

  2. Use “Connect to QuickBooks” button with your sandbox

  3. Authorize the connection

  4. Get your authorization code and realmId from the redirect

  5. Exchange the code for tokens at https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer

For Production:

  1. Complete app assessment (more on this below)

  2. Same OAuth flow but with real companies

  3. Get authorization code

  4. Exchange for tokens

Step 7: Token Management

You get:

  • Access token: Dies in 60 minutes
  • Refresh token: Valid for 100 days, and the window resets every time you use it. Each refresh returns a new refresh token, so always store the latest one. Since November 2025, every refresh token also has a hard maximum of five years
  • Company ID (realmId): Need this for every API call

Miss the 100-day refresh window, or hit the five-year cap? User has to reauthorize. Your customers will love that.

The Production App Assessment Nightmare

Before touching real data, Intuit requires:

  1. Security questionnaire
  2. App description and use case
  3. Sometimes a demo call
  4. 1-2 week wait

Just answer their questions. Fighting it wastes more time.

Common Screwups to Avoid

  1. Sandbox vs Production Confusion: Different base URLs

  2. Token Refresh Amnesia: That 100-day limit is real. Day 101 = reauthorization. Set up automated refresh at day 50.

  3. Rate Limits:

    • 500 requests per minute per company

    • 10 requests per second per company and app

    • Batch has its own throttle: 40 batch requests per minute per company and app (use them, but they don't bypass the limits)

  4. Webhook Verification: If using webhooks, verify the intuit-signature header on every notification before trusting the payload. And check your parser: Intuit moved webhooks to the CloudEvents payload format, mandatory for all apps since July 31, 2026.

  5. Minor Version Hell: Since August 1, 2025, Intuit ignores minor versions 1 to 74 and treats every request as 75 or higher. Set minorversion=75 (or newer) as a query parameter so you know which schema you're coding against.

  6. Company ID Mix-ups: Each QuickBooks company has a unique ID. Using the wrong one = 401 errors.

API Limits That Will Annoy You

  • API response: 1000 records per query max, and the default is 100, so set MAXRESULTS and page with STARTPOSITION

  • Batch operations: 30 items per request (Intuit's recommended maximum)

  • Timeouts: any request running longer than 120 seconds fails, so keep batches small

  • Cost: since July 2025, reads (CorePlus calls) are metered under Intuit's App Partner Program. The free Builder tier includes 500,000 per month and then blocks further reads until the reset. Writes stay free. Sandbox and OAuth calls don't count

The Disconnect Problem

QuickBooks forces reauthorization if:

  • The refresh token goes unused for 100 days
  • The refresh token hits its five-year maximum
  • User revokes access in QuickBooks
  • You change your app's scopes

Build reconnection flows now, not when customers are screaming.

What You Actually Need to Know

  1. Accounting API: Create, read and update on invoices, customers, payments and the rest. Deletes differ: transactions (invoices, estimates, sales receipts) can be hard deleted, but list entities (customers, vendors, accounts) can only be made inactive by setting Active to false

  2. Reports API: Read-only financial reports (P&L, Balance Sheet, etc.)

  3. Webhooks: Real-time notifications (when they work)

  4. Batch API: Send multiple operations in one request (use this for bulk operations)

QuickBooks Desktop Note

Still need Desktop? Different API and no OAuth at all: it connects through the QuickBooks Web Connector, a Windows app set up with a .qwc file and a password, syncs only run while the Web Connector is open and the machine is awake, and Intuit wants it dead. Only use if forced at gunpoint. You can read our guide here about Quickbooks Desktop API.

Testing Without Going Insane

  1. Use sandbox companies (free, up to 10, valid for two years)

  2. Test with production-like data volumes

  3. Test token refresh on day 99 (not day 100)

  4. Test reconnection flows before launch

That’s it. You have QuickBooks API access. Stop reading forums and start building.

Managing QuickBooks API connectivity with Apideck's Vault

If you want to integrate with QuickBooks and other accounting systems, managing API connections can be challenging. You can use Apideck to connect to accounting applications. Apideck's Vault allows for:

  • Secure credential storage with automatic token refresh - No need to build token management infrastructure or handle OAuth flows manually.
  • Pre-built authentication UI - Embedded Vault components handle credential input and OAuth authorization without custom UI development.
  • Centralized connection monitoring - Track connection states, validate credentials, and manage multiple accounting platforms from a single dashboard.

And here's how you can easily connect and manage permissions for your API Access.

Screenshot 2025-11-14 at 18.48.17@2x

Testing and production work differently through Apideck. For testing, Apideck provides its own QuickBooks credentials, so you can start testing without registering an Intuit app first. During OAuth, the consent screen shows "Apideck" as the requesting application.

For production, you use your own Intuit app. Follow Steps 1 to 5 above, add Apideck's redirect URI (https://unify.apideck.com/vault/callback) to your app, and paste your Client ID and Client Secret into the QuickBooks connector settings in your Apideck dashboard. Intuit's app assessment and any App Partner Program fees apply to whoever owns the Intuit app, so in production that's you. After that, Apideck runs the OAuth flow and refreshes tokens, and you call the Accounting API with x-apideck-service-id: quickbooks.

Feeling motivated? Got your API keys? Here's the next steps:

  1. Signup for Apideck
  2. Quickbooks documentation: https://developers.apideck.com/apis/accounting/quickbooks
  3. How to integrate with Quickbooks API: https://www.apideck.com/blog/how-to-integrate-with-quickbooks-api#setting-up-a-developer-account

Go build an amazing Quickbooks Integration

Ready to get started?

Scale your integration strategy and deliver the integrations your customers need in record time.

Ready to get started?
Talk to an expert

Trusted by fast-moving product & engineering teams

Bonsai by Zoom
JobNimbus
Blue Zinc
Exact
Drata