What’s QuickBooks?
QuickBooks is Intuit’s accounting software that owns the small business market because it’s cheaper than everything else, and your accountant already knows it. There’s QuickBooks Online (cloud) and QuickBooks Desktop. Most businesses use it until they hit about $10M revenue, then graduate to something that doesn’t crash during month-end close. You’re here because you need to sync data between QuickBooks and your app. Here’s how to get API access without reading Intuit’s 500-page documentation.
Note: QuickBooks doesn't use traditional API keys. Instead, it uses OAuth 2.0 authentication with Client ID and Client Secret credentials. This guide walks you through obtaining those credentials and setting up the OAuth flow.
Prerequisites
-
QuickBooks Online account (Desktop API is different hell entirely)
-
Intuit Developer account (free but annoying)
-
Know if you’re building for one company or many.
Step 1: Create an Intuit Developer Account
Go to https://developer.intuit.com and sign up. Use an email you’ll still have access to in 2 years when something breaks.
Step 2: Create Your App
My Hub → App dashboard, then the + card to create an app
Pick your scopes on the permissions page: com.intuit.quickbooks.accounting is what 90% of you want. Only add the payments scope if you process payments.
Name your app something memorable. You’ll have 50 test apps eventually.
Step 3: Get Your Credentials
Your app dashboard shows:
- Client ID: Public identifier for your app
- Client Secret: Turn on the “Show credentials” switch and copy it somewhere secure
Development vs Production:
- Development: For testing, works with sandbox companies
- Production: For real data, requires app assessment (yes, really)
Both have different keys. Don’t mix them up.
Step 4: Set OAuth Settings
In your app settings → Redirect URIs
Add your callback URLs (Development and Production are listed separately):
- Development:
http://localhost:8080/callback - Production:
https://yourapp.com/auth/quickbooks/callback
Plain-HTTP localhost only works with development keys. Production needs HTTPS. No exceptions.
Step 5: Configure Scopes
Scopes live in two places: the app's Permissions page in the portal (set in Step 2, editable later), and the scope parameter of the authorization URL you send users to (https://appcenter.intuit.com/connect/oauth2), space-separated. Only request scopes you've enabled on the app.
Common ones you’ll need:
- com.intuit.quickbooks.accounting: Read/write all accounting data
- com.intuit.quickbooks.payment: Process payments
- openid: Required for any of the user info scopes below (OpenID Connect)
- email: User’s email address
- profile: User’s given and family name
- address: User’s physical address
- phone: Nobody uses this
Pick the minimum. Users see these on consent screen and get paranoid. If you still have second thoughts on how to do this, we have this visual guide for you.
Step 6: Connect to a Company
For Development:
-
Use the sandbox company Intuit created with your developer account (you can add up to 10)
-
Use “Connect to QuickBooks” button with your sandbox
-
Authorize the connection
-
Get your authorization code and realmId from the redirect
-
Exchange the code for tokens at
https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer
For Production:
-
Complete app assessment (more on this below)
-
Same OAuth flow but with real companies
-
Get authorization code
-
Exchange for tokens
Step 7: Token Management
You get:
- Access token: Dies in 60 minutes
- Refresh token: Valid for 100 days, and the window resets every time you use it. Each refresh returns a new refresh token, so always store the latest one. Since November 2025, every refresh token also has a hard maximum of five years
- Company ID (realmId): Need this for every API call
Miss the 100-day refresh window, or hit the five-year cap? User has to reauthorize. Your customers will love that.
The Production App Assessment Nightmare
Before touching real data, Intuit requires:
- Security questionnaire
- App description and use case
- Sometimes a demo call
- 1-2 week wait
Just answer their questions. Fighting it wastes more time.
Common Screwups to Avoid
-
Sandbox vs Production Confusion: Different base URLs
-
Production: https://quickbooks.api.intuit.com
-
Token Refresh Amnesia: That 100-day limit is real. Day 101 = reauthorization. Set up automated refresh at day 50.
-
Rate Limits:
-
500 requests per minute per company
-
10 requests per second per company and app
-
Batch has its own throttle: 40 batch requests per minute per company and app (use them, but they don't bypass the limits)
-
-
Webhook Verification: If using webhooks, verify the
intuit-signatureheader on every notification before trusting the payload. And check your parser: Intuit moved webhooks to the CloudEvents payload format, mandatory for all apps since July 31, 2026. -
Minor Version Hell: Since August 1, 2025, Intuit ignores minor versions 1 to 74 and treats every request as 75 or higher. Set
minorversion=75(or newer) as a query parameter so you know which schema you're coding against. -
Company ID Mix-ups: Each QuickBooks company has a unique ID. Using the wrong one = 401 errors.
API Limits That Will Annoy You
-
API response: 1000 records per query max, and the default is 100, so set
MAXRESULTSand page withSTARTPOSITION -
Batch operations: 30 items per request (Intuit's recommended maximum)
-
Timeouts: any request running longer than 120 seconds fails, so keep batches small
-
Cost: since July 2025, reads (CorePlus calls) are metered under Intuit's App Partner Program. The free Builder tier includes 500,000 per month and then blocks further reads until the reset. Writes stay free. Sandbox and OAuth calls don't count
The Disconnect Problem
QuickBooks forces reauthorization if:
- The refresh token goes unused for 100 days
- The refresh token hits its five-year maximum
- User revokes access in QuickBooks
- You change your app's scopes
Build reconnection flows now, not when customers are screaming.
What You Actually Need to Know
-
Accounting API: Create, read and update on invoices, customers, payments and the rest. Deletes differ: transactions (invoices, estimates, sales receipts) can be hard deleted, but list entities (customers, vendors, accounts) can only be made inactive by setting
Activeto false -
Reports API: Read-only financial reports (P&L, Balance Sheet, etc.)
-
Webhooks: Real-time notifications (when they work)
-
Batch API: Send multiple operations in one request (use this for bulk operations)
QuickBooks Desktop Note
Still need Desktop? Different API and no OAuth at all: it connects through the QuickBooks Web Connector, a Windows app set up with a .qwc file and a password, syncs only run while the Web Connector is open and the machine is awake, and Intuit wants it dead. Only use if forced at gunpoint. You can read our guide here about Quickbooks Desktop API.
Testing Without Going Insane
-
Use sandbox companies (free, up to 10, valid for two years)
-
Test with production-like data volumes
-
Test token refresh on day 99 (not day 100)
-
Test reconnection flows before launch
That’s it. You have QuickBooks API access. Stop reading forums and start building.
Managing QuickBooks API connectivity with Apideck's Vault
If you want to integrate with QuickBooks and other accounting systems, managing API connections can be challenging. You can use Apideck to connect to accounting applications. Apideck's Vault allows for:
- Secure credential storage with automatic token refresh - No need to build token management infrastructure or handle OAuth flows manually.
- Pre-built authentication UI - Embedded Vault components handle credential input and OAuth authorization without custom UI development.
- Centralized connection monitoring - Track connection states, validate credentials, and manage multiple accounting platforms from a single dashboard.
And here's how you can easily connect and manage permissions for your API Access.

Testing and production work differently through Apideck. For testing, Apideck provides its own QuickBooks credentials, so you can start testing without registering an Intuit app first. During OAuth, the consent screen shows "Apideck" as the requesting application.
For production, you use your own Intuit app. Follow Steps 1 to 5 above, add Apideck's redirect URI (https://unify.apideck.com/vault/callback) to your app, and paste your Client ID and Client Secret into the QuickBooks connector settings in your Apideck dashboard. Intuit's app assessment and any App Partner Program fees apply to whoever owns the Intuit app, so in production that's you. After that, Apideck runs the OAuth flow and refreshes tokens, and you call the Accounting API with x-apideck-service-id: quickbooks.
Feeling motivated? Got your API keys? Here's the next steps:
- Signup for Apideck
- Quickbooks documentation: https://developers.apideck.com/apis/accounting/quickbooks
- How to integrate with Quickbooks API: https://www.apideck.com/blog/how-to-integrate-with-quickbooks-api#setting-up-a-developer-account
Go build an amazing Quickbooks Integration
Ready to get started?
Scale your integration strategy and deliver the integrations your customers need in record time.








