QuickBooks for AI agents

QuickBooks is cloud accounting software for managing income, expenses, invoices, and financial reporting. Small businesses and their accountants use it as their core bookkeeping system. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Finance and accountingOAuth 2.0MCP + RESTquickbooks.intuit.com
AUDIT LOG · QUICKBOOKSPOLICY: acme-support
09:41:07 · claude · u_8f2read
quickbooks.list_cards
List Cards✓ allowed · 212ms
09:41:08 · claude · u_8f2read
quickbooks.get_bill
Get Bill✓ allowed · 164ms
09:41:09 · claude · u_8f2write
quickbooks.create_bill
Create Bill✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
quickbooks.delete_item
Delete Item✕ blocked · policy: deny
EVERY QUICKBOOKS CALL, ON THE RECORD
01 · USE CASES

What agents do in QuickBooks.

01

Create an invoice for a customer

Generate a new invoice with line items and send it for payment tracking.

02

Check a customer's balance read-only

Pull a customer balance report before following up on an outstanding payment.

03

Delete a bank account with approval

Remove a bank account from the books only after the accountant confirms it is closed.

02 · ACTIONS

114 QuickBooks actions, graded by risk.

Every QuickBooks action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

70

Look things up. Allowed by default.

  • quickbooks.get_bill
    Get Bill
  • quickbooks.get_item
    Get Item
  • quickbooks.get_term
    Get Term
  • quickbooks.list_cards
    List Cards
  • quickbooks.get_deposit
    Get Deposit
  • quickbooks.get_payment
    Get Payment
  • quickbooks.get_reports
    Get Reports
  • quickbooks.query_bills
    Query Bills
  • quickbooks.query_items
    Query Item Entities
  • quickbooks.get_estimate
    Get Estimate
  • quickbooks.get_purchase
    Get Purchase
  • quickbooks.get_tax_rate
    Get Tax Rate
  • quickbooks.get_transfer
    Get Transfer
  • quickbooks.list_invoices
    List Invoices
  • quickbooks.query_account
    Query Account Entities
  • quickbooks.query_vendors
    Query Vendor Entities
+ 54 MORE

write

39

Create and change things. Allow, or ask the user first.

  • quickbooks.create_bill
    Create Bill
  • quickbooks.create_item
    Create Item
  • quickbooks.update_term
    Update Term
  • quickbooks.create_class
    Create Class
  • quickbooks.create_vendor
    Create Vendor
  • quickbooks.create_account
    Create Account
  • quickbooks.create_deposit
    Create Deposit
  • quickbooks.create_invoice
    Create Invoice
  • quickbooks.create_payment
    Create Payment
  • quickbooks.create_customer
    Create Customer
  • quickbooks.create_employee
    Create Employee
  • quickbooks.create_estimate
    Create Estimate
  • quickbooks.create_purchase
    Create Purchase
  • quickbooks.update_transfer
    Update Transfer
  • quickbooks.send_credit_memo
    Send Credit Memo
  • quickbooks.create_tax_agency
    Create Tax Agency
+ 23 MORE

destructive

5

Delete, cancel or archive. Ask first, or deny outright.

  • quickbooks.delete_item
    Delete Item
  • quickbooks.delete_bank_account
    Delete Bank Account
  • quickbooks.get_refund_receipt
    Get Refund Receipt
  • quickbooks.create_refund_receipt
    Create Refund Receipt
  • quickbooks.get_refund_receipt_pdf
    Get Refund Receipt PDF
03 · HOW IT WORKS

QuickBooks in three steps.

  1. 01Your users connect QuickBooksThey sign in to QuickBooks on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Bill” can wait for the user, and “delete Item” can be denied outright.
  3. 03Any agent can actYour agent calls QuickBooks through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('quickbooks', {
  read: 'allow',
  write: 'ask',        // create_bill
  destructive: 'deny',  // delete_item
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How QuickBooks connects.

Users sign in to QuickBooks on Arc0 Connect and approve the scopes you request. Build with Arc0’s QuickBooks OAuth app, or bring your own so the QuickBooks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same QuickBooks connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use QuickBooks from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

QuickBooks and Arc0, answered.

Q01

Can I use QuickBooks with Claude, ChatGPT or Cursor?

Yes. Connect QuickBooks to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the QuickBooks actions you allow.

Q02

How do users connect QuickBooks?

Users sign in to QuickBooks on Arc0 Connect and approve the scopes you request. Build with Arc0’s QuickBooks OAuth app, or bring your own so the QuickBooks consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which QuickBooks actions can my agent take?

114 in total: 70 read, 39 write and 5 destructive, such as “create Bill”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in QuickBooks?

Yes. Actions like “delete Item” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call QuickBooks too?

Yes. The same QuickBooks connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug QuickBooks into your agent.

Your users connect QuickBooks once, under your brand. Your agent gets 114 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan