Back to Browse

Qbo MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports.

About

MCP server for QuickBooks Online — accounts, customers, invoices, bills, and reports.

Security Report

4.2
Use Caution4.2High Risk

The QuickBooks Online MCP server is well-structured with appropriate authentication mechanisms and reasonable permission scope for its intended purpose. Token handling follows best practices with environment variables and credentials file support. Minor concerns around broad exception handling and lack of explicit input validation in some areas prevent a higher score, but no critical security vulnerabilities were identified. Supply chain analysis found 7 known vulnerabilities in dependencies (2 critical, 2 high severity).

3 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

QuickBooks Online OAuth2 client ID from the Intuit developer appOptional

Environment variable: QBO_CLIENT_ID

QuickBooks Online OAuth2 client secretRequired

Environment variable: QBO_CLIENT_SECRET

OAuth2 refresh token for the connected QuickBooks companyRequired

Environment variable: QBO_REFRESH_TOKEN

QuickBooks Online company (realm) IDOptional

Environment variable: QBO_REALM_ID

QuickBooks API environment: 'sandbox' or 'production'Optional

Environment variable: QBO_ENVIRONMENT

Transport mode for the server. Set to 'stdio' for local CLI use; the image defaults to 'http' for gateway hosting.Optional

Environment variable: MCP_TRANSPORT

Credential source: 'env' reads vars locally, 'gateway' expects header injection from the WYRE MCP Gateway.Optional

Environment variable: AUTH_MODE

Log verbosity: debug, info, warn, errorOptional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-wyre-ai-qbo-mcp": {
      "env": {
        "AUTH_MODE": "your-auth-mode-here",
        "LOG_LEVEL": "your-log-level-here",
        "QBO_REALM_ID": "your-qbo-realm-id-here",
        "MCP_TRANSPORT": "your-mcp-transport-here",
        "QBO_CLIENT_ID": "your-qbo-client-id-here",
        "QBO_ENVIRONMENT": "your-qbo-environment-here",
        "QBO_CLIENT_SECRET": "your-qbo-client-secret-here",
        "QBO_REFRESH_TOKEN": "your-qbo-refresh-token-here"
      },
      "args": [
        "-y",
        "@wyre-ai/qbo-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

QuickBooks Online MCP Server

Model Context Protocol (MCP) server for the QuickBooks Online Accounting API. Exposes 130+ tools across 22 QBO entities plus 10 financial reports for Claude and other MCP-compatible clients.

Features

  • Interactive invoice card (MCP Apps, SEP-1865): qbo_invoices_get renders as a read-only interactive card in MCP Apps hosts (Claude Desktop/web) — customer, status, dates, line items, totals — neutral by default, brandable via window.__BRAND__ injection or MCP_BRAND_* env vars. Non-App hosts see the same JSON payload (plus a _card field).

One-Click Deployment

Deploy to DO

Deploy to Cloudflare Workers

Note on registry auth: This server depends only on public npm packages, so the Cloudflare and DigitalOcean cloud builders install its dependencies anonymously — no token is required for one-click deploy. (If a future release adds a private @wyre-ai/* dependency, you would supply a GitHub PAT with read:packages as a build variable — NODE_AUTH_TOKEN for Cloudflare Workers, a build-time GITHUB_TOKEN secret for DigitalOcean.)

Installing the published package: The released package is published to the GitHub Packages npm registry, which requires authentication on every install (even for public packages). To install it, authenticate npm to npm.pkg.github.com with a GitHub PAT that has read:packages:

export NODE_AUTH_TOKEN=$(gh auth token)
npm install @wyre-ai/qbo-mcp

Quick Start

Prerequisites

  • Node.js >= 20
  • QuickBooks Online OAuth2 app credentials (requires an Intuit developer account)

Install and Build

npm install
npm run build

Run (stdio mode)

QBO_ACCESS_TOKEN=your-access-token QBO_REALM_ID=your-realm-id npm start

Run (HTTP mode)

MCP_TRANSPORT=http QBO_ACCESS_TOKEN=your-access-token QBO_REALM_ID=your-realm-id npm start

The server listens on http://0.0.0.0:8080/mcp by default.

Docker

docker build -t qbo-mcp .
docker run -p 8080:8080 \
  -e MCP_TRANSPORT=http \
  -e QBO_ACCESS_TOKEN=your-access-token \
  -e QBO_REALM_ID=your-realm-id \
  qbo-mcp

Environment Variables

VariableRequiredDefaultDescription
QBO_ACCESS_TOKENYes (env mode)QuickBooks Online OAuth2 access token
QBO_REALM_IDYes (env mode)QuickBooks Online company (realm) ID
QBO_ENVNoproductionAPI environment: production or sandbox
QBO_CREDENTIALS_FILENoPath to a dotenv-format file re-read on every request; its QBO_ACCESS_TOKEN / QBO_REALM_ID / QBO_ENV override the environment variables (see Token rotation)
MCP_TRANSPORTNostdioTransport type: stdio or http
MCP_HTTP_PORTNo8080HTTP server port
MCP_HTTP_HOSTNo0.0.0.0HTTP server bind address
AUTH_MODENoenvAuth mode: env or gateway
MCP_BRAND_NAMENoBrand name shown on the MCP Apps invoice card (card is neutral when unset)
MCP_BRAND_LOGO_URLNoLogo URL for the invoice card
MCP_BRAND_PRIMARY_COLORNo#2563ebInvoice card primary color
MCP_BRAND_ACCENT_COLORNo#e5e7ebInvoice card accent color
MCP_BRAND_BGNo#ffffffInvoice card background color
MCP_BRAND_TEXTNo#333333Invoice card text color

Authentication

The server does not handle the OAuth flow — it consumes a pre-obtained access token. Two modes:

env mode (default). Token comes from QBO_ACCESS_TOKEN (or from the file named by QBO_CREDENTIALS_FILE, which wins when both are set). Single tenant.

gateway mode. Token comes from per-request HTTP headers, isolated through AsyncLocalStorage so concurrent requests never share credentials. Set AUTH_MODE=gateway and send:

HeaderRequiredDescription
X-Qbo-Access-TokenYesOAuth2 access token
X-Qbo-Realm-IdYesCompany (realm) ID
X-Qbo-EnvironmentNoproduction or sandbox (defaults to production)

When QBO rejects the access token, the server returns an MCP error whose text begins with the literal prefix QBO_UNAUTHORIZED:. The intended contract is that the gateway detects this prefix, refreshes the OAuth token, and retries the request.

Token rotation (env mode)

QBO access tokens expire after ~60 minutes, so env-mode deployments typically rotate them with a cron job. A rotated token in a Docker env_file never reaches a running container: Docker injects env_file only at container creation, so docker restart keeps the old environment and the refresh loop silently becomes a no-op until calls start failing with QBO_UNAUTHORIZED / Token revoked (#63).

Set QBO_CREDENTIALS_FILE to skip environment reinjection entirely. The server re-reads the file on every request, so a rotation takes effect immediately — no restart or recreate at all:

# docker-compose.yml
services:
  qbo-mcp:
    image: ghcr.io/wyre-ai/qbo-mcp
    environment:
      MCP_TRANSPORT: http
      QBO_CREDENTIALS_FILE: /secrets/qbo.env
    volumes:
      - ./secrets:/secrets:ro   # mount the DIRECTORY, not the file

Your refresh job then just rewrites ./secrets/qbo.env (dotenv format: QBO_ACCESS_TOKEN=..., optionally QBO_REALM_ID=... and QBO_ENV=...) and is done — drop the docker restart from the script. Mount the containing directory rather than the file itself: tools like sed -i replace the file's inode, and a single-file bind mount would keep pointing at the old one. If the file is missing or unreadable, tool calls fail loudly instead of silently falling back to a stale environment token.

If you'd rather keep plain env_file injection, the rotation script must recreate the container — docker compose up -d --force-recreate — a docker restart is never enough.

Sandbox Testing

Set QBO_ENV=sandbox (env mode) or X-Qbo-Environment: sandbox (gateway mode) to target Intuit's sandbox API at https://sandbox-quickbooks.api.intuit.com instead of production. Unrecognized values fail loudly (no silent fallback to production).

Available Tools

Tools are organized by domain. Call qbo_navigate with a domain name (e.g. customers, vendors, bills) to discover the tools in that domain. All tools are always callable — navigation is a discovery aid, not a prerequisite.

Entities (config-driven, 116 tools across 22 entities)

Each entity exposes some subset of list, get, create, update, search. Transactional entities support startDate/endDate filtering on the list operation. Updates are sparse and require the current SyncToken from a prior get.

Sales workflow

  • qbo_customers_* — list, get, create, search
  • qbo_invoices_* — list (Paid/Unpaid/Overdue status filter), get, create, send
  • qbo_estimates_* — list, get, create, update
  • qbo_sales_receipts_* — list, get, create, update
  • qbo_credit_memos_* — list, get, create, update
  • qbo_refund_receipts_* — list, get, create, update
  • qbo_payments_* — list, get, create

Purchase workflow

  • qbo_vendors_* — list, get, create, update, search
  • qbo_bills_* — list, get, create, update, search
  • qbo_bill_payments_* — list, get, create, update
  • qbo_vendor_credits_* — list, get, create, update
  • qbo_purchases_* — list, get, create, update (point-of-sale expenses)
  • qbo_purchase_orders_* — list, get, create, update

Bank & money movement

  • qbo_deposits_* — list, get, create, update
  • qbo_transfers_* — list, get, create, update
  • qbo_journal_entries_* — list, get, create, update (balanced debit/credit)

Products & accounts

  • qbo_items_* — list, get, create, update, search (products and services)
  • qbo_accounts_* — list, get, create, update, search (chart of accounts)

Classification & terms

  • qbo_classes_* — list, get, create, update, search
  • qbo_departments_* — list, get, create, update, search
  • qbo_terms_* — list, get, create, update, search (Net 30, etc.)
  • qbo_payment_methods_* — list, get, create, update, search

Tax & company

  • qbo_tax_codes_* — list, get, search (read-only)
  • qbo_tax_rates_* — list, get, search (read-only)
  • qbo_company_info_* — list, get (read-only singleton)

People & time

  • qbo_employees_* — list, get, create, update, search
  • qbo_time_activities_* — list, get, create, update (billable time)

Attachments

  • qbo_attachables_* — list, get, create, update (metadata only; file upload uses a separate QBO endpoint)

Reports (10 tools)

  • qbo_reports_profit_and_loss
  • qbo_reports_balance_sheet
  • qbo_reports_cash_flow
  • qbo_reports_trial_balance
  • qbo_reports_general_ledger
  • qbo_reports_aged_receivables
  • qbo_reports_aged_payables
  • qbo_reports_customer_sales
  • qbo_reports_customer_balance
  • qbo_reports_vendor_expenses

Legacy expense tools (backwards compatibility)

qbo_expenses_list_purchases, qbo_expenses_get_purchase, qbo_expenses_list_bills, qbo_expenses_get_bill remain available. New work should use the dedicated qbo_purchases_* and qbo_bills_* tool families, which add create/update/search.

Testing

npm test                   # unit suite — fast, no credentials needed
npm run test:integration   # hits a real QBO sandbox; skipped without creds

The integration suite calls one read tool per entity tier (customers, vendors, accounts, items, journal entries, company info) against Intuit's sandbox API. It only runs when both QBO_SANDBOX_ACCESS_TOKEN and QBO_SANDBOX_REALM_ID are present in the environment. CI wires these from the matching repo secrets and skips the job (with a clear notice) when they're absent — so dependabot/fork PRs don't fail.

License

Apache-2.0

Reviews

No reviews yet

Be the first to review this server!