
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
@mindstone/mcp-server-quickbooks
Advanced tools
QuickBooks Online MCP server for Model Context Protocol hosts — invoices, bills, customers, vendors, accounts
QuickBooks Online MCP server for Model Context Protocol hosts. Manage invoices, bills, customers, vendors, employees, and accounts in QuickBooks Online through a standardised MCP interface.
QUICKBOOKS_REFRESH_TOKEN)STATUS.jsonEvery QuickBooks-mutating tool
(create_quickbooks_invoice, create_quickbooks_bill,
create_quickbooks_customer, create_quickbooks_vendor,
create_quickbooks_estimate, send_quickbooks_invoice_email,
update_quickbooks_invoice, update_quickbooks_customer,
update_quickbooks_vendor) executes its write without any opt-in:
capability is enabled by default and the host's tool-approval layer is the
gate. Read-only tools (list_*, get_*, query_*, download_*,
configure_quickbooks) are unaffected.
Versions 0.3.0–0.4.0 gated these writes behind a QB_ALLOW_PROD_WRITES=1
environment variable. That gate has been removed; the variable is no longer
read and can be deleted from host configurations.
After clicking the button, your host will prompt you to fill: QUICKBOOKS_CLIENT_ID, QUICKBOOKS_CLIENT_SECRET, QUICKBOOKS_REFRESH_TOKEN, QUICKBOOKS_REALM_ID, QUICKBOOKS_ENVIRONMENT.
{
"mcpServers": {
"QuickBooks Online": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-quickbooks"
],
"env": {
"QUICKBOOKS_CLIENT_ID": "",
"QUICKBOOKS_CLIENT_SECRET": "",
"QUICKBOOKS_REFRESH_TOKEN": "",
"QUICKBOOKS_REALM_ID": "",
"QUICKBOOKS_ENVIRONMENT": "production"
}
}
}
}
cd <path-to-repo>/connectors/quickbooks
npm install
npm run build
npx -y @mindstone/mcp-server-quickbooks
node dist/index.js
QUICKBOOKS_CLIENT_ID — Intuit Developer app client IDQUICKBOOKS_CLIENT_SECRET — Intuit Developer app client secretQUICKBOOKS_REFRESH_TOKEN — OAuth 2.0 refresh tokenQUICKBOOKS_REALM_ID — QuickBooks company (realm) IDQUICKBOOKS_ENVIRONMENT — sandbox or production (default: production)MCP_HOST_BRIDGE_STATE — optional path to a host bridge state file used for credential managementMINDSTONE_REBEL_BRIDGE_STATE — backwards-compatible alias for MCP_HOST_BRIDGE_STATE{
"mcpServers": {
"QuickBooks": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-quickbooks"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
{
"mcpServers": {
"QuickBooks": {
"command": "node",
"args": ["<path-to-repo>/connectors/quickbooks/dist/index.js"],
"env": {
"QUICKBOOKS_CLIENT_ID": "your-client-id",
"QUICKBOOKS_CLIENT_SECRET": "your-client-secret",
"QUICKBOOKS_REFRESH_TOKEN": "your-refresh-token",
"QUICKBOOKS_REALM_ID": "your-realm-id"
}
}
}
}
configure_quickbooks — Configure QuickBooks Online OAuth credentialsquery_quickbooks — Run a QuickBooks query using QuickBooks Query Languageget_quickbooks_entity — Get a single entity by type and IDget_quickbooks_report — Run a financial report (ProfitAndLoss, BalanceSheet, CashFlow, AgedReceivables, AgedPayables)list_quickbooks_customers — List customerscreate_quickbooks_customer — Create a new customerupdate_quickbooks_customer — Sparse-update a customer (deactivate with active: false)list_quickbooks_vendors — List vendorscreate_quickbooks_vendor — Create a new vendorupdate_quickbooks_vendor — Sparse-update a vendor (deactivate with active: false)list_quickbooks_invoices — List invoicescreate_quickbooks_invoice — Create a new invoiceupdate_quickbooks_invoice — Sparse-update invoice header fields (dueDate, memo, privateNote)send_quickbooks_invoice_email — Email an invoice to its customerdownload_quickbooks_invoice_pdf — Download an invoice as a PDF (saved to the system temp directory)list_quickbooks_estimates — List estimates (quotes)create_quickbooks_estimate — Create a new estimatelist_quickbooks_bills — List bills (accounts payable)create_quickbooks_bill — Create a new billlist_quickbooks_employees — List employeeslist_quickbooks_accounts — List chart of accountsText authored inside QuickBooks (customer/vendor display names, memos, line
descriptions, report cells) is attacker-influenceable, so the connector wraps
it in <untrusted-content source="quickbooks:…"> envelopes before returning
it to the model. Typed entity payloads are sanitized deny-by-default: every
string is enveloped — including strings inside arrays, which have no key
context — unless its key is a narrow structural predicate (IDs, SyncToken,
dates/timestamps, enums) and its value passes a shape guard. query_quickbooks,
get_quickbooks_entity, and reports envelope every string key and value
wholesale. Structural values such as Id, SyncToken, dates, and
amounts are left untouched so they stay usable as inputs to follow-up calls.
FSL-1.1-MIT — Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.
FAQs
QuickBooks Online MCP server for Model Context Protocol hosts — invoices, bills, customers, vendors, accounts
We found that @mindstone/mcp-server-quickbooks demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.