Create the accounting application credentials for QuickBooks
Detailed client guidance covering create the accounting application credentials for QuickBooks, including prerequisites, exact controls, verification evidence, failure boundaries and safe recovery steps for the shipped QuickBooks connector.
Audience: Administrators, finance staff and authorised integration operatorsPermission: IntegrationModule v1.0.0
Where to goQuickBooks Accounting Automation → Integration
Before you startConfirm the intended tenant, remote account or invoice context, and your Integration access. Keep credentials and tokens out of screenshots, tickets and exported evidence. If a previous write may have reached an external service, verify remote state before retrying.
What you’ll accomplish
Detailed client guidance covering create the accounting application credentials for QuickBooks, including prerequisites, exact controls, verification evidence, failure boundaries and safe recovery steps for the shipped QuickBooks connector. This article is intentionally scoped to the behaviour enforced or exposed by the supplied module and does not treat provider marketing features as implemented integration capabilities.
How the workflow fits together
The connector keeps native CRM records authoritative while mapping verified Customer, Invoice and Payment evidence in QuickBooks. Queue, exception, API, reconciliation and compliance records are separate evidence layers, so each material action should be verified at both the native and remote sides.
Follow these steps
Open QuickBooks Accounting Automation → Integration.
Confirm you are in the intended tenant and connected company and that your role has the required Integration access.
Check the application credentials and exact callback/redirect URI registered with the provider.
Start or repeat authorization only from the Integration page so state and tenant context are fresh.
After callback, confirm the resolved remote identity before any sync is enabled.
Run the built-in connection test and refresh reference data.
Fields and decisions to review
This guide’s focusDetailed client guidance covering create the accounting application credentials for QuickBooks, including prerequisites, exact controls, verification evidence, failure boundaries and safe recovery steps for the shipped QuickBooks connector.
CredentialsApplication credentials are entered only in the Integration area. Secret values and tokens are encrypted or deliberately not rendered back in plaintext.
AuthorizationConnection uses the provider OAuth authorization-code flow. The callback must match the registered application configuration and the returned state must match the active session request.
State windowOAuth state is short-lived; a stale browser tab, repeated callback or session mismatch can require starting connection again.
IdentityEvery accounting request is tied to the verified remote organisation/company/business identity, not merely to an access token.
DisconnectDisconnect removes active authorization state while preserving mappings, queues, reports, reconciliation history and audit evidence needed for review.
Provider identityThe connected company is identified by the OAuth realmId and verified with CompanyInfo. The shipped flow does not invent a second company picker after OAuth.
Remote request identityThe verified realmId is carried with accounting requests using company path segment semantics.
How to confirm it worked
Reopen the native record and the relevant integration history/register. Confirm the stored remote accounting identifier, exact amount/status, latest timestamps and the expected audit or reconciliation evidence. If the provider-side state cannot be independently verified, keep the task unresolved and use the controlled exception or troubleshooting flow.
Questions clients commonly ask
How is the connected company identified?The connected company is identified by the OAuth realmId and verified with CompanyInfo. The shipped flow does not invent a second company picker after OAuth.
What should I verify before I trust the result?Verify the native record, the mapped remote record, the stored remote identifier, the current status/amount and the audit or history evidence. A success message alone is not the accounting evidence.
Should I press the action again after a timeout?Not until you have checked the remote accounting service and the Exceptions/API evidence. A timeout can occur after the remote side accepted a non-idempotent write, so a blind retry can create a duplicate.
Does the connector replace the native CRM record?No. Native clients, invoices and payments remain the operational source records. The connector records mappings, remote evidence and controlled reconciliation around them.
What should I include in a support case?Include the native record ID, remote ID if known, date/time, action, exact visible error and request/audit identifier. Never send client secrets, access tokens, refresh tokens or authorization headers.
Technical basis for this guidance
This guide was checked against the supplied module code paths: controllers/Quickbooks_accounting_automation.php; models/Quickbooks_accounting_automation_model.php; libraries/Quickbooks_api_client.php; libraries/Quickbooks_reconciliation_service.php; libraries/Quickbooks_document_import_service.php; views/admin; install.php; docs/FEATURE_MATRIX.md. It documents shipped behaviour, validation, routes and evidence controls; it does not claim successful live provider network calls from offline inspection.
Controls, checks and common mistakes
Work in the intended tenant and remote accounting/business context.
Do not paste credentials, access tokens, refresh tokens or private keys into tickets or notes.
Do not bypass a missing mapping, validation error, permission gate, duplicate check or remote-verification requirement.
Do not repeat a non-idempotent write until you know whether the previous request reached the remote service.
Keep native record, remote evidence and audit/history state aligned before closing the task.
Provider and accounting boundaryAuthorization does not prove that the intended company is selected. Confirm realmId identity and test the connection before posting.