Hermes Agent can work with your QuickBooks Online books through DeepLedger's hosted MCP server. Hermes is the open-source agent from Nous Research that runs in your terminal, a desktop app, or a messaging gateway. You add DeepLedger once, and Hermes discovers the accounting tools. Begin with a report you can check against QuickBooks before you let it record anything.
| Connection setting | Value |
|---|---|
| Server URL | https://mcp.deepledger.ai/mcp |
| Transport | Streamable HTTP |
| Authentication | OAuth (browser sign-in) or Authorization: Bearer <DeepLedger API key> |
| Hermes config file | ~/.hermes/config.yaml, under mcp_servers |
What you can do after connecting
Through DeepLedger, you can ask your AI agent to:
- Record purchases: bills, expenses, bill payments, and vendor credits.
- Manage sales records: estimates, invoices, customer payments, sales receipts, customer credits, and refund receipts.
- Record other transactions: bank deposits, transfers between accounts, and journal entries.
- Run reports: profit and loss, balance sheet, cash flow, accounts receivable and payable aging, general ledger, and trial balance.
- Prepare month-end close: track close checks, flag issues, assemble financial statements, and propose adjusting entries in DeepLedger's Close Sheet. You review the work and sign off in the portal.
- Work through tasks: raise questions, request missing documents, hand work between you and the AI agent, and track resolution in DeepLedger's Tasks.
- Find supporting information: look up customers, vendors, accounts, transactions, connected bank-feed entries, and uploaded documents.
Before you start
- A DeepLedger account with access to the QuickBooks Online company you plan to use.
- That company connected under Settings → Companies, with Intuit authorization completed by someone permitted to connect it.
- Hermes Agent installed and set up with a model provider. Run
hermes updateif your install is older than the September 2026 releases; this guide was checked against v2026.9.24. - For the API-key route only: owner or admin access in DeepLedger to create a key.
Hermes sends tool results to the model provider you configured. Before connecting real client books, confirm that provider is approved for financial data. Use a demo company while you set this up.
Choose how Hermes signs in
| OAuth | API key | |
|---|---|---|
| Best for | Hermes on your own computer, or the Hermes desktop app | A gateway (Telegram, Slack and similar) or a server with no browser |
| Secret stored | Token in ~/.hermes/mcp-tokens/deepledger.json | Key in ~/.hermes/.env |
| Revoke | hermes mcp remove deepledger | Revoke in DeepLedger Settings → API keys |
Either way, the connection acts as the DeepLedger user who authorized it and reaches every company that person can access. Neither is read-only.
Step 1: Add DeepLedger to Hermes
With OAuth
hermes mcp add deepledger --url https://mcp.deepledger.ai/mcp --auth oauth
Hermes opens your browser. Sign in with your DeepLedger account and approve access. DeepLedger supports OAuth discovery and dynamic client registration, so you don't need an Intuit developer app, a client ID or a pasted token.
With an API key
In DeepLedger, open Settings → API keys, select Create API key, name it for this machine and set an expiration. The key starts with dl_live_ and is shown once.
hermes mcp add deepledger --url https://mcp.deepledger.ai/mcp --auth header
Answer yes when Hermes asks whether the server requires authentication, then paste the key at the API key / Bearer token prompt. Hermes saves it to ~/.hermes/.env as MCP_DEEPLEDGER_API_KEY and writes only a reference to it in config.yaml. Don't paste the key into a chat with the agent.
Step 2: Start with a small set of tools
After it connects, Hermes lists DeepLedger's tools and asks:
Enable all N tools? [Y/n/select]:
Type select and keep only these four for your first session:
qbCompanyProfile: lists and switches companiesqbReports: financial reportsqbFetchTransactions: transaction lookupsgetGuide: DeepLedger's working guides
Hermes records your choice as tools.include. You can change it later with hermes mcp configure deepledger.
Step 3: Require approval before writes
Open ~/.hermes/config.yaml. The DeepLedger entry should look like one of these. Add the trust: untrusted line yourself:
mcp_servers:
deepledger:
url: "https://mcp.deepledger.ai/mcp"
auth: oauth
trust: untrusted
tools:
include: [qbCompanyProfile, qbReports, qbFetchTransactions, getGuide]
mcp_servers:
deepledger:
url: "https://mcp.deepledger.ai/mcp"
headers:
Authorization: "Bearer ${MCP_DEEPLEDGER_API_KEY}"
trust: untrusted
tools:
include: [qbCompanyProfile, qbReports, qbFetchTransactions, getGuide]
With trust: untrusted, Hermes asks before it runs any DeepLedger tool that the server does not mark read-only. DeepLedger marks qbReports, qbFetchTransactions and getGuide as read-only. Every other tool asks first, including qbCompanyProfile, because switching companies changes which books later calls use. Without the line, Hermes treats the server as fully trusted and calls write tools without asking.
Run /reload-mcp in an open session, or start a new one.
Step 4: Check the connection
hermes mcp test deepledger
hermes mcp list
In a session, ask "Tell me which DeepLedger tools are available right now." Hermes names them with a server prefix, such as mcp_deepledger_qbReports.
Running Hermes without a browser
DeepLedger does not support the device-code flow, so hermes mcp login deepledger --flow device will not work. On a remote host, pick one:
- Use an API key. This is the simplest choice for a gateway or a server.
- Forward the callback port. Set a fixed port under
oauth: { redirect_port: 27890 }in the server entry. Runssh -N -L 27890:127.0.0.1:27890 you@hostfrom your laptop, then open the sign-in link there. - Paste the redirect. If the browser can't reach the callback, Hermes offers to take the redirect URL at its prompt.
- Use the desktop app. It relays the OAuth callback from your machine to a remote backend automatically.
On a gateway, find out how approval requests reach you before you add write tools.
Next step: verify one company and one report
In DeepLedger Settings → Companies, find the company you want. If it isn't connected, select Connect to QuickBooks and have an authorized person complete Intuit sign-in. Start with a demo company when testing a new AI provider. Don't send private business reports until your organization has approved that provider and its data settings.
With DeepLedger enabled in Hermes, ask:
Using DeepLedger, list the companies I can access and identify the active company. Ask me which company to use. After I choose, select it and confirm its name and company identifier. Do not create or change accounting records.
Approve the company switch when Hermes asks. Company selection can carry over to your other connected AI clients. Confirm it again when you change sessions; a company-bound credential may not allow switching. See selecting the right QuickBooks company.
Then replace the bracketed name with that confirmed company:
Using DeepLedger for [confirmed company], retrieve the profit and loss for September 1 through September 30, 2026, on an accrual basis. Show the returned company name and identifier, exact dates, accounting basis, currency, income, expenses and net income. Do not create or change accounting records. If the company or report settings cannot be confirmed, stop and explain the missing information.
In QuickBooks Online → Reports → Profit and Loss, run the report for the same company, September 1–30, 2026, accrual basis, currency and filters. Compare income, expenses and net income, then look into any account lines that differ. A successful tool response includes report data and matching context; a “connected” status or an AI summary alone is not verification. If totals differ, correct the context and rerun before relying on the result. Follow the P&L analysis and verification workflow.
A read-only prompt is not read-only permissions. Once you widen tools.include, the connection can reach write tools. Keep trust: untrusted on and read each proposed action before you approve it. After the report agrees, choose a real task from the journal-entry review workflow or overdue-invoice workflow, and adapt the client-specific steps to Hermes.
Example prompts to try next
Add the tools a prompt needs to tools.include first, such as qbExpense, qbBill or customReports. Replace the bracketed details with your own company, dates and account names.
Record a paid expense
Using DeepLedger for [company], record a [currency and amount] software subscription paid to [vendor] on [date] from [bank or credit card account], categorized to [expense account]. Check for an existing transaction and show me the proposed entry before saving. After I confirm, record it and return the QuickBooks transaction reference.
Record an unpaid bill
Using DeepLedger for [company], prepare an unpaid bill from this attached vendor invoice. Check for duplicates, use the invoice number, date, due date, line amounts and taxes, and propose the expense categories. Ask me for missing details and show the bill for confirmation before recording it.
Run financial reports
Using DeepLedger for [company], get the profit and loss for [start date] through [end date] and the balance sheet as of [end date], using [cash or accrual] basis. Show the company, dates, currency and report totals, then summarize the main changes from the previous period.
Hermes memory and your books
Hermes keeps session history and its own long-term memory on the machine where it runs. Report figures and transaction details from DeepLedger can end up there. Protect that machine as you would any copy of client financial data. Ask Hermes not to save client figures to its memory unless you mean it to. DeepLedger keeps its own audit trail of every write, separate from Hermes.
Troubleshooting
- Server missing: check
hermes mcp listand confirm the entry doesn't sayenabled: false. After editingconfig.yaml, run/reload-mcpor start a new session. - 401 or 403: for OAuth, run
hermes mcp login deepledgerand sign in with the right DeepLedger account. For an API key, check thatMCP_DEEPLEDGER_API_KEYin~/.hermes/.envis complete and hasn't expired or been revoked.hermes logs --level debugshows the failing request. - A tool is missing: it's probably not in
tools.include. Add it withhermes mcp configure deepledger. - Every call asks for approval: that's expected for write tools under
trust: untrusted. Reports and transaction lookups shouldn't ask. If they do, update Hermes. - Wrong company or report: use the company check above, reconnect QuickBooks in DeepLedger if needed, and rerun with explicit dates and basis.
- Disconnect:
hermes mcp remove deepledgerremoves the server from Hermes. If you used an API key, revoke it in Settings → API keys. Neither step deletes accounting records or disconnects QuickBooks from DeepLedger.
Testing scope
Documentation and configuration last verified October 5, 2026. We checked this guide against the Hermes Agent documentation and the v2026.9.24 source for hermes mcp add, OAuth, tool filtering and the trust setting, and against DeepLedger's server implementation. We did not complete a new OAuth grant or retrieve a report from Hermes during this revision. The prompts are suggested checks, not test results. Before using business data, have the account owner complete sign-in and the demo-company report comparison above.
Return to AI platforms and integrations or resolve a connection error with the MCP troubleshooting guide.