QuickBooks MCP: Accounting Data in an AI Assistant

Intuit offers two ways to put QuickBooks in an AI assistant: a hosted QuickBooks connector in Claude (and a plugin in ChatGPT), and an open source local MCP server for developers. What each can read and change, why neither covers QuickBooks Desktop, how to run the local server read-only, and what a person should review.

7 min read

Yes, QuickBooks has MCP support from Intuit itself, in two forms. The first is a hosted QuickBooks connector that Intuit built for Claude, listed in Anthropic’s connector directory, with a matching QuickBooks plugin in ChatGPT; it reads reports and can create and send invoices, estimates and payment links. The second is Intuit’s open source QuickBooks Online MCP server, a local stdio server for developers with more than a hundred tools across 29 QuickBooks entities. Both work with QuickBooks Online; neither is built for QuickBooks Desktop. And both can change your books, so the useful setup is the smallest one: read-only where you can, and a person approving anything that sends, posts or deletes.

The controls an accounting practice already uses, such as segregation of duties and a person approving every posting, are covered in AI agents for accounting. This guide is about the QuickBooks connections themselves. Nothing here is tax or accounting advice.

Where Intuit’s MCP support stands

As of September 30, 2026, the dates Intuit has published are these:

  • April 23, 2026: Intuit announced its apps in Claude (opens in a new tab), including QuickBooks and Intuit Enterprise Suite, for profitability, cash flow and benchmarking analysis. Anthropic’s directory page lists the connector as added in March 2026, a month earlier than that announcement.
  • July 28, 2026: Intuit’s announcement (opens in a new tab) expanded the Claude connector and the ChatGPT plugin with sales invoicing, payroll questions and QuickBooks Capital lending benchmarks, “moving beyond read-only access to your data.” It lists payroll actions, such as running payroll, as coming later.
  • The local server is maintained in Intuit’s GitHub organization and describes itself as “a local MCP server” that runs as a stdio subprocess and authenticates to one QuickBooks Online company.

The QuickBooks connector in Claude

The directory listing (opens in a new tab) names Intuit QuickBooks as the maker, shows the connector URL as https://ai-inc.quickbooks.intuit.com/v1/mcp, and lists 74 tools. Grouped by what they do:

  • Reports: profit and loss, cash flow, balance sheet, accounts receivable aging, and sales by customer and by product, plus industry benchmarking.
  • Sales: create, update, duplicate, send and delete invoices and estimates; recurring invoices; invoice reminders; payment links.
  • Customers and products: search and create customers, search and create products and services.
  • Transactions: import transactions and check import status.
  • Payroll: mostly reads, such as employees, pay schedules and payslips, but the list also includes creating and updating employees.
  • Lending: loan details, estimated payments and peer offers from QuickBooks Capital.

According to Intuit’s help article for the connector, it works with an active QuickBooks Online or Intuit Enterprise Suite subscription, is available to US customers only for now, and can also build reports from CSV, PDF or pasted transactions for people without a subscription. You add it under Connectors in Claude and sign in with your Intuit account; you disconnect it in the same place. Intuit says destructive actions, such as deleting an invoice or estimate, require your confirmation first, and that your QuickBooks data is not used to train Claude. How directory connectors work in general is in Claude’s connectors explained; the ChatGPT side is in ChatGPT connectors and apps.

Notice what the confirmation covers: deletes. Sending an invoice or a payment link to a customer is not a delete, and it reaches a real person with a real amount on it. Treat sends as needing a person too, whatever the client asks by default.

Intuit’s open source QuickBooks Online MCP server

The quickbooks-online-mcp-server repository (opens in a new tab) is for developers and partners who want QuickBooks in Claude Code, Claude Desktop or another MCP client on their own machine. Its README lists 145 tools: create, read, update, delete and search for 29 entities, from customers, invoices, bills and vendors to journal entries, deposits, transfers and tax codes, plus 11 reports such as the balance sheet, trial balance, general ledger and aged payables.

Setup is gated by Intuit’s OAuth. You register an app on the Intuit Developer Portal, run a one-time browser handshake with npm run auth, and the server keeps a refresh token in its .env file, rotating it on each refresh. After that, the README says, the server runs without a browser “until the 100-day refresh window lapses.” Two practical notes from the README: sandbox apps accept a http://localhost redirect, but production apps reject it and need a public HTTPS callback for the first sign-in; and the quick start’s clone command shows a placeholder address, so clone Intuit’s repository instead.

Terminal
git clone https://github.com/intuit/quickbooks-online-mcp-server.git
cd quickbooks-online-mcp-server
npm install
npm run build
cp .env.example .env    # add your client ID, secret and realm ID
npm run auth            # one-time browser sign-in

Running it read-only

The server has three switches. QUICKBOOKS_DISABLE_WRITE removes the create tools, QUICKBOOKS_DISABLE_UPDATE the update tools and QUICKBOOKS_DISABLE_DELETE the delete tools; the get_ and search_ tools are always available. With all three set, the agent can read and report but cannot change a thing, which is the right start for real company data:

Claude Desktop config (claude_desktop_config.json)
{
  "mcpServers": {
    "quickbooks": {
      "command": "node",
      "args": ["/path/to/quickbooks-online-mcp-server/dist/index.js"],
      "env": {
        "QUICKBOOKS_CLIENT_ID": "your_client_id",
        "QUICKBOOKS_CLIENT_SECRET": "your_client_secret",
        "QUICKBOOKS_REFRESH_TOKEN": "your_refresh_token",
        "QUICKBOOKS_REALM_ID": "your_realm_id",
        "QUICKBOOKS_ENVIRONMENT": "sandbox",
        "QUICKBOOKS_DISABLE_WRITE": "true",
        "QUICKBOOKS_DISABLE_UPDATE": "true",
        "QUICKBOOKS_DISABLE_DELETE": "true"
      }
    }
  }
}

Start against a sandbox company, as the README recommends, and switch QUICKBOOKS_ENVIRONMENT to production only when you know what the tools return. The client secret and refresh token in that file and in .env open your books; keep both out of version control and off shared machines. In Claude Code the same server is added as a stdio command, as the Claude Code MCP docs (opens in a new tab) show, with the variables passed by --env.

MCP for QuickBooks Desktop

There is no Intuit MCP server for QuickBooks Desktop. The Claude connector asks for QuickBooks Online or Intuit Enterprise Suite, and the open source server authenticates to a QuickBooks Online company. If you run Desktop, the connector’s no-subscription path is the Intuit-supported option: export a report or a transaction list and upload it for analysis, knowing the assistant is working from a file rather than your live books. Third-party Desktop integrations exist; judge them as you would any service that will hold your company file, with the checks in MCP security risks.

Scopes, sign-in and what a person reviews

Whichever route you use, the assistant acts with the access of the Intuit sign-in or developer app behind it. Four decisions keep that manageable:

  • Who signs in. Connect with a QuickBooks user whose access fits the job, not the company admin, where your subscription allows separate users.
  • Which tools are on. For the local server, the three disable flags. For the hosted connector, your client’s tool approval settings; leave send, delete and payroll tools on ask.
  • What gets reviewed. Every invoice, estimate or payment link before it goes to a customer; every imported transaction before it posts; every payroll or employee change; anything that states a tax position.
  • Where the data goes. Report output enters your AI client’s conversation and its model provider’s systems under that client’s terms. Keep Social Security numbers, bank account numbers and payroll detail out of prompts you do not need them in.

If you prepare returns or hold clients’ tax information, the FTC Safeguards Rule and IRS Publication 4557 already apply, and an AI connection is one more access path your written security plan has to cover; AI agents for accounting explains those rules. Payment links overlap with payment processors, covered in Stripe MCP.

A board for what waits on a person

An assistant that can read QuickBooks produces a steady queue of things for a person to decide: 12 invoices drafted and ready to send, three deposits it could not match, a vendor whose details changed. With fenbs connected at https://fenbs.ai/api/mcp, the assistant files each as a task with a priority from 1 to 10 and a link or a QuickBooks reference in the note, never an account number, and a person works them through To Do, Next Up, In Progress and Completed. Put standing rules such as “the assistant never sends an invoice” on the Decisions and rules page, which every connected AI assistant reads first. History records who filed and moved each task, alongside QuickBooks’s own record of what changed in the books. fenbs has no due dates, so filing and payroll deadlines stay in the calendar you already use.

Related

The approval step itself: AI agent approval workflows. Receipts and reminders for an owner-run business: AI agents for small businesses. Who may do what on the board: roles and permissions for humans and AI agents. Connecting it: the MCP docs.

Questions people ask.

Does QuickBooks have an MCP server?

Yes. Intuit built a hosted QuickBooks connector for Claude and a plugin for ChatGPT, and publishes an open source QuickBooks Online MCP server that developers run locally. Both work with QuickBooks Online.

Is there an MCP server for QuickBooks Desktop?

Not from Intuit. Its connector requires QuickBooks Online or Intuit Enterprise Suite, and its open source server authenticates to a QuickBooks Online company. Desktop users can export reports and upload them for analysis instead.

Can the QuickBooks MCP server be read-only?

The open source server can. Set QUICKBOOKS_DISABLE_WRITE, QUICKBOOKS_DISABLE_UPDATE and QUICKBOOKS_DISABLE_DELETE to true, and only the get and search tools remain. The hosted Claude connector includes write tools, so rely on your client’s tool approval settings there.

Is my QuickBooks data used to train AI models?

Intuit says QuickBooks data shared through the Claude connector is not used to train Claude and that data stays within Intuit systems and is not used to train foundation models. Check your AI client’s own data terms as well.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.