Sign in, then create or select your organization. Check the environment badge before every connection or access change.
In Settings, choose Intuit Sandbox. An owner or admin connects the intended test company from Companies and completes Intuit consent in the browser.
In Assistants, review the client guide and choose only the required companies and read operations. Review each permission before granting access.
Complete the client acceptance checklist below using synthetic sandbox records. Production and provider consent require separate human approval.
Connect or reconnect QuickBooks
If Connect is unavailable, confirm you are an owner or admin and the selected environment is configured. Ask the operator to check that environment’s Intuit setup and exact callback URL; never share client secrets.
For reconnect or revoked status, return to Companies and use the connection control for the intended company and environment. Complete a fresh Intuit consent flow; an assistant grant cannot repair Intuit authorization.
For refreshing status, wait for the current refresh to finish, then reload once. If the status persists, ask the operator to investigate before starting another authorization flow.
If callback or consent fails, check the signed-in OmniQB account and selected organization, then start again from Companies. Do not reuse callback URLs or paste authorization codes into support messages.
After reconnecting, review assistant company access again. An active connection alone does not prove that any assistant can read it.
Assistant setup and missing tools
ChatGPT and Claude require the hosted OAuth flow and signed-in client acceptance. Those acceptance steps remain pending. A manual bearer key is not a replacement for their hosted flow.
Cursor’s guide uses a dedicated manual grant resolved from a local environment variable. Grok’s guide targets the xAI API, not an established consumer grok.com connector. No client is claimed accepted end to end.
For 401, check whether the dedicated grant is expired or revoked and use the approved client authorization flow. For 403 or missing tools, have an owner or admin review company access, active environment and exact read permission; do not broaden all permissions to clear an error.
If a tool list is stale, have the client workspace administrator review and refresh the connector’s tools using the official client guide. A listed tool still requires server authorization for each call.
For initialization failures, use the approved HTTPS deployment’s /api/mcp endpoint. Ask the operator to check deployment readiness and redacted protocol logs. Never put a bearer value in a URL, chat, screenshot or source control.
Sandbox versus production
Sandbox uses Intuit test companies. Production can expose real financial data even when operations are read-only. The Settings switch selects an environment; it does not copy companies, tokens or grants.
Review the environment-change confirmation and its access consequences before proceeding. Connect and authorize each environment separately; verify the company identity before the first read.
A configured badge is not production acceptance. The operator must verify Intuit production setup, provider client consent, and the unresolved onward-AI-sharing policy before broader use.
Team roles and access
Owners and admins manage company connections and assistant grants. Members should ask an owner or admin for the specific access needed. Organization membership and assistant permissions are separate checks.
In Team, verify the intended organization and invitation recipient. Expired, used or revoked invitations need an administrator’s review; signing in with another account does not transfer membership.
Assistant access is default deny. Per-company overrides replace the default operation list. Review report permissions separately because a report may expose underlying financial data.
If access changes while you work, reload and select the organization again. Review any confirmation before changing roles, removing access, revoking grants or disconnecting a company.
Document and upload statuses
Reading an existing QuickBooks attachment or PDF is separate from staging a new file. A preview is not a posted document and does not change your books.
Reserved means storage is being prepared or its outcome is uncertain. Quarantined means the file is not cleared for proposal use; do not bypass scanning. Clean means the configured scanner cleared those bytes, not that Intuit received the file.
Cleanup means deletion is queued. Deleted records indicate confirmed deletion of the staged object; they do not prove deletion from backups or QuickBooks. Never describe queued cleanup as finished.
Expired or invalid handles require a fresh authorized staging attempt after the prior outcome is resolved. After an uncertain upload response, do not repeatedly retry with new request IDs; ask the operator to check cleanup.
Staging may be unavailable because storage, scanner, cleanup health, permissions or quotas are not ready. Current live upload execution remains disabled. Ask the operator to resolve the gate rather than uploading sensitive documents to troubleshoot.
Unavailable features and proposal previews
The Access catalog distinguishes available reads, proposal code with live execution disabled, and gated products. A catalog entry or passing synthetic test is not evidence of live provider acceptance.
Financial writes and payments are not enabled. Confirming a proposal preview does not post, send, charge, delete or update anything in QuickBooks.
Payments, Payroll and other restricted products need independently verified provider eligibility and integration work. Changing a team role or reconnecting cannot unlock them.
For a disabled operation, check the catalog explanation and ask your administrator whether it is supported. Do not substitute a broader grant or a production connection to bypass a gate.
Client acceptance checklist
Acceptance remains pending for ChatGPT, Claude, Cursor and Grok (xAI API). The same checks apply to each client; browser consent and provider grants are human steps.
Have the operator approve a reachable HTTPS test deployment and confirm the provider’s current plan and workspace requirements.
Use an explicitly approved sandbox company with synthetic records. Review organization, environment, companies and read permissions before completing consent or creating a dedicated manual grant.
Verify initialization, tool discovery and one permitted company-information read. Check that a denied company or operation remains inaccessible.
Verify cancellation, expiry and revocation stop access. Record client version, deployment revision, date and redacted results with the operator.
Keep production use pending until client acceptance and the Intuit onward-AI-sharing review are resolved. Synthetic protocol checks cannot establish provider acceptance.
Connect your assistant
Start with Intuit Sandbox. An owner or admin must connect a company and grant only the required company access and read operations. Google sign-in and the selected environment’s Intuit credentials must be configured by the operator. Client setup does not connect QuickBooks or create credentials.
This is the production domain’s endpoint; it is not proof of deployment readiness. For a separately approved test deployment use its origin followed by /api/mcp. Do not put a grant in the URL, a chat message, or source control.
ChatGPT — hosted OAuth acceptance pending
OmniQB’s hosted OAuth flow must be accepted and deployed before these steps can succeed. A manual bearer grant is not a substitute for this flow.
On ChatGPT web, have your workspace admin enable developer mode and authorize your account. Availability depends on plan and workspace policy.
Requires an accepted and deployed OmniQB OAuth flow plus an endpoint reachable from Anthropic’s infrastructure. Local browser reachability is insufficient.
Have your Claude workspace owner enable custom connectors if required by policy.
Open Customize → Connectors → + → Add custom connector.
Enter OmniQB and the MCP endpoint. Add it, then connect and complete OmniQB authorization once the hosted flow is available.
Enable the connector for a conversation, review exposed tools, and test only a permitted sandbox company.
Create a dedicated manual read-only grant below and save its one-time value in your local secret management setup as OMNIQB_GRANT. Make that environment variable available to Cursor.
Add this configuration to .cursor/mcp.json for a project or ~/.cursor/mcp.json for personal use.
Open Customize, enable OmniQB and inspect its available tools. Test a permitted sandbox company; if initialization fails, inspect MCP Logs and keep the integration disabled pending acceptance.
The official xAI API supports remote MCP. This guide does not establish a custom MCP connector in the consumer grok.com app.
Use an approved xAI API application and API credentials managed outside OmniQB. API usage may incur charges.
Create a dedicated OmniQB read-only grant. In your server-side xAI Responses API request, include this entry in tools, resolving the placeholder from your secret store.
Review allowed_tools and run a sandbox acceptance test before using financial data. OmniQB has not verified this client end to end.
Official documentation checked October 8, 2026. Revoke the dedicated grant in Assistants when access is no longer needed. Switching environments does not transfer grants, tokens or company data.
Prepare the affected screen, approximate time and timezone, sandbox or production, client name/version, and a redacted error code. Explain the expected result and steps to reproduce using synthetic data.
Do not include credentials, bearer grants, authorization codes, callback URLs, private upload handles, financial documents or customer data. Nothing is collected or sent from this help page.