This page is the user-facing edge of a server-side OAuth architecture. Tokens should never live in browser localStorage.
Connection setup
Connection status
Disconnected
Realm ID
—
Scopes
Accounting · Payments · OpenID
Last token refresh
—
Implementation notes
Use a backend callback route, encrypted token storage, CSRF state validation, and a job queue for initial backfill. Do not connect QBO directly from static HTML.
OAuth launcher
Wire this button to your backend authorization endpoint.