QuickBooks Connection Setup
This page is the user-facing edge of a server-side OAuth architecture. Tokens should never live in browser localStorage.
Connection status
Disconnected
Realm ID
—
Scopes
Accounting · Payments · OpenID
Last token refresh
—
Use a backend callback route, encrypted token storage, CSRF state validation, and a job queue for initial backfill. Do not connect QBO directly from static HTML.
OAuth launcher
Wire this button to your backend authorization endpoint.
Security checklist
Non-negotiable for production.
Server-side token encryptionrequired
Refresh token rotationrequired
Per-entity realm mappingneeded
Reconnect / revoke controlsneeded