Yes, QuickBooks Online has an official MCP server from Intuit. It runs locally and gives a compatible AI client tools to work with your QuickBooks company. You can also maintain your own deployment or connect to a hosted service such as DeepLedger.
The practical choice is who will operate the server and how your AI client reaches it. Intuit's documented server uses a local stdio process. DeepLedger provides a remote URL, with QuickBooks authorization handled through its portal.
Choose Your Setup
| Your situation | Start here | What you need |
|---|---|---|
| You want to run Intuit's server on your machine | Official local setup | A compatible local MCP client, Intuit developer app and QuickBooks OAuth connection |
| Your team needs custom tools or deployment controls | Your own deployment | Someone to maintain the server, credentials, permissions and client transport |
| You want a connection for a supported AI client without operating a server | DeepLedger hosted setup | DeepLedger account, authorized QuickBooks company and compatible client access |
| You use QuickBooks Desktop | Desktop connection options | A Desktop-compatible integration; the Online routes here do not read company files |
Before choosing, name the first job you need done: an aging report, an invoice, a journal entry or something else. Check that the server exposes that operation and the fields you need. An MCP connection by itself does not establish which accounting tasks are supported.
What Is a QuickBooks MCP Server?
The Model Context Protocol (MCP) is the interface between the AI application and the server. The server then talks to QuickBooks Online through its API. QuickBooks remains the place where the books are recorded.
For example, a report tool can retrieve a dated profit and loss report for the AI to explain. An invoice creation tool can write a new invoice. Those are different actions with different consequences; connecting a server does not mean every request is read-only.
The MCP architecture documentation explains this client/server relationship. For the accounting context, see our guide to MCP servers for accounting work.
QuickBooks MCP vs. QuickBooks API for AI Agents
The two are layers, not alternatives. The QuickBooks Online API is Intuit's programming interface: a developer registers an app, handles OAuth, and writes code for each request. A QuickBooks MCP server sits on top of that API and presents its operations as named tools with typed inputs, so an AI client can discover and call them without custom integration code for each one.
| Question | QuickBooks API directly | QuickBooks MCP server |
|---|---|---|
| Who writes the integration? | Your developers, per operation | The server author; the AI client calls tools |
| How does the AI use it? | Through code you write and maintain | Through tools it discovers at connection time |
| What handles Intuit OAuth? | Your application | The server, local or hosted |
| Which limits apply? | Intuit's API rate limits and scopes | The same limits, plus whatever the server restricts |
| Best fit | A product or workflow you build and control | Giving an existing AI client access to the books |
Because every QuickBooks MCP server for Online uses that API underneath, the MCP label does not add or remove any Intuit permission. It changes who does the integration work and how the AI client reaches the data. If your team already maintains a QuickBooks integration, the API route may remain the right one. If you want Claude, ChatGPT, or an agent framework to work with the books, an MCP server saves that work.
Your Three Options in 2026
Intuit also offers a first-party QuickBooks connector inside Claude, documented in Intuit's help article. It is a built-in connector rather than an MCP server you install. Check its current availability and supported actions in your account. Our Claude connection guide compares it with the hosted route below.
1. Intuit's Official MCP Server (Local)
Intuit's QuickBooks Online MCP server repository includes record operations and financial reports. The documented installation runs as a local stdio subprocess: a compatible AI client launches the server and exchanges messages with it.
Setup requires an Intuit developer app, OAuth authorization and the target company's realm ID. The README covers sandbox versus production callbacks and token storage. It also documents separate switches for disabling create, update and delete tools.
This route suits someone who can install and maintain the software. Keep the OAuth credentials in the server configuration, outside the AI conversation.
2. Self-Hosting an Open-Source Server
If your team needs control over deployment or custom tools, it can operate its own server. For a remote client, provide a compatible remote transport or a supported private-server tunnel. A local stdio process is not itself a public endpoint.
Your team owns credential storage, authorization, updates, availability and logs. Multiple companies also require deliberate separation of credentials and access. Identify who will maintain the connection when a token refresh fails or an API changes.
3. A Hosted MCP Platform
A hosted provider operates the server at a remote URL and supplies a connection flow. Providers differ in their tools, authentication, company access and review controls.
DeepLedger is one hosted option for QuickBooks Online. Its company tools can list the companies you can access and select an active company. Confirm that company before requesting work, especially when using more than one AI client. Our multiple-company guide explains how the shared active company works.
The Comparison at a Glance
| Question | Intuit's documented local setup | Your own deployment | Hosted provider |
|---|---|---|---|
| Who operates it? | You | Your team | The provider |
| How does the AI connect? | A client launches a stdio process | The transport you implement | A supported remote endpoint |
| What do you configure? | Developer app, OAuth and local credentials | Server, credentials and access controls | Provider account and client connection |
| Can web AI clients use it? | Not directly over stdio | If you provide compatible remote access | Check client and account requirements |
| How are companies separated? | A configured company connection | Your implementation | Check the provider's access model |
| What about approvals and logs? | Inspect the implementation | Your responsibility | Verify the actual behavior |
Why Local vs. Remote Matters for Your AI Client
A local stdio client can be a desktop application, a command-line tool or a custom agent host. A remote HTTP client connects over a network instead of launching that subprocess.
Claude's custom web connectors need a reachable remote server. ChatGPT supports remote MCP connections and also documents a Secure MCP Tunnel for private servers. A tunnel adds its own setup and permissions. For DeepLedger's hosted route, use the public HTTPS endpoint below.
There are two connections to distinguish: the AI application's access to the MCP server, and the server's access to QuickBooks. The MCP authorization specification covers the former. A QuickBooks OAuth connection does not, by itself, establish what the AI client is allowed to do.
Setting Up a Hosted QuickBooks MCP Server
Start by creating a DeepLedger account or signing in to your existing account, then connect the intended QuickBooks Online company. In Settings → Company and QBO Connect → Companies, find the intended company, select Connect QB and complete Intuit's authorization flow. You need access to the company in DeepLedger and permission to connect it in QuickBooks.
Then add the remote endpoint to your AI assistant:
https://mcp.deepledger.ai/mcp
In Claude: the current individual Pro/Max instructions use Customize → Connectors → + → Add custom connector. Enter the URL, add the connector, and connect to authorize it. On Team or Enterprise, an owner must add the custom connector before members can connect. See Anthropic's current custom-connector instructions for your plan.
In ChatGPT: OpenAI's current instructions say to enable Developer mode in Settings → Security and login, then use the plus button on the Plugins page to create a developer-mode app for the remote server. Complete authorization and select the app in the conversation's Developer mode tools. Check OpenAI's developer-mode guide for eligibility and controls available to your account.
Menu labels and workspace policies can change. If the custom-connection option is missing, check those official instructions and your workspace permissions before changing server settings. Do not paste credentials into the chat.
Once connected, make a small read request:
Use DeepLedger to show the active QuickBooks company name and home currency. Do not create or change any QuickBooks records. If no company is selected, list the companies I can access and ask me which to use.
Confirm the returned company before continuing. DeepLedger's normal company switching affects later calls across your connected AI clients; a credential fixed to one company cannot switch.
For more context, see our connection walkthrough and guides for ChatGPT, Claude Code, Copilot Studio, CrewAI, LangChain, and Gemini Spark. Use the current client documentation above if menu labels differ.
Check the Connection With a Real Task
Start with requests whose results you can compare with QuickBooks:
- Explain a report: "Retrieve the profit and loss report for April 1 through June 30, 2026, on the accrual basis. Compare it with January 1 through March 31 on the same basis. Show the company and reporting currency."
- Prepare a review list: "Find posted transactions in uncategorized accounts for August 2026. Show dates, amounts and existing categories, and identify missing evidence. Do not change any records."
- Review receivables: "Retrieve accounts receivable aging detail as of September 30, 2026. Separate overdue invoices from credits and unapplied payments. Do not change records or send messages."
All three require suitable report or transaction tools. For a write, specify the company, source document, date and intended action. DeepLedger can also post multi-line journal entries: the AI journal-entry walkthrough follows an approved accrual schedule through posting and verification. The Grok overdue-invoice guide takes the receivables request through payment checks and follow-up drafts.
For bank cleanup, distinguish downloaded bank-feed items from posted entries using our uncategorized-transactions guide. Our workflow overview covers the wider review process; tool access alone does not establish that a close or reconciliation is complete. For what AI can and cannot do with the books themselves, see what an AI general ledger actually means.
Verify a report before expanding the workflow
We checked DeepLedger's qbCompanyProfile and qbReports tools against our designated Demo company on September 20, 2026. An accrual P&L for August 1–31 returned USD 3,400.00 income, USD 183.50 cost of goods sold and USD 926.50 net income. The matching P&L Detail report tied to those totals. These are demo figures, not customer results or a profitability claim.
The worked P&L analysis shows the full comparison, supporting entries and the zero-baseline problem the AI must handle. Use the same checks on your own company: identity, currency, dates, accounting basis and detail totals. A successful connection alone does not prove the answer is correct.
Is It Safe to Give an AI Access to Your Books?
Evaluate the actual connection, not the MCP label:
- Access: Who operates the server, which company can it reach, and how can you revoke access?
- Actions: Which tools can write, and what requires approval? A prompt asking for read-only work is not a substitute for disabling write tools when your client or server supports that.
- Evidence: Can you inspect the request, result and resulting QuickBooks record? Ask what the logs include rather than assuming every read and write is retained.
- Data handling: Check both providers' terms and settings for retention and training. Returning data as conversation context does not settle either question.
Keep accounting judgment and final review with someone who understands the books. Our article on accounting audit trails discusses questions to ask; the providers' current terms and actual controls govern your connection.
What About QuickBooks Desktop?
The Intuit repository above and DeepLedger's connection target QuickBooks Online. They do not connect directly to a QuickBooks Desktop company file.
Desktop has separate integration interfaces. Intuit documents the Desktop SDK and Web Connector route, which lets compatible web services exchange data with Desktop. Check the integration's supported edition and read/write actions. Evaluate Desktop-compatible options against the work you need done before considering a migration.
Our QuickBooks Desktop connection guide separates Claude's local MCP route from ChatGPT's web connection requirements and explains how to analyze an exported report. If you want a DeepLedger Desktop connection, join the Desktop waitlist; we are measuring demand before deciding whether to build it.
When a connection is not working
If tools load but your company or reports are unavailable, follow our QuickBooks MCP connection troubleshooting guide. It separates tool discovery, DeepLedger sign-in, company selection, Intuit authorization and report settings so you can repair the failing step.
Next step: verify one company and one report
In DeepLedger Settings → Company and QBO Connect, find the intended company under Companies. If it is not connected, choose Connect QB and have an authorized person complete Intuit sign-in. Start with a demo company when testing a new AI provider; do not send private business reports until your organization has approved that provider and its data settings.
With DeepLedger enabled in your AI client, ask:
Using DeepLedger, list the companies I can access and identify the active company. Ask me which company to use. After I choose, select it and confirm its name and company identifier. Do not create or change accounting records.
Company selection can persist across your connected AI clients. Confirm it again when changing sessions; a company-bound credential may not allow switching. See selecting the right QuickBooks company.
Then replace the bracketed name with that confirmed company:
Using DeepLedger for [confirmed company], retrieve the profit and loss for September 1 through September 30, 2026, on an accrual basis. Show the returned company name and identifier, exact dates, accounting basis, currency, income, expenses and net income. Do not create or change accounting records. If the company or report settings cannot be confirmed, stop and explain the missing information.
In QuickBooks Online → Reports → Profit and Loss, run the report for the same company, September 1–30, 2026, accrual basis, currency and filters. Compare income, expenses and net income, then investigate any differing account lines. A successful tool response includes report data and matching context; a “connected” badge or an AI summary alone is not verification. If totals differ, correct the context and rerun before relying on the result. Follow the P&L analysis and verification workflow.
A read-only prompt is not read-only permissions. The connection can expose write tools; review permissions and proposed actions. After the report agrees, choose a real task from the journal-entry review workflow or overdue-invoice workflow, adapting the client-specific steps to your AI app.
Frequently Asked Questions
What is a QuickBooks MCP server?
It is software that gives an AI application tools for accessing QuickBooks data through the Model Context Protocol. The server determines which reports, records and write actions are available. MCP itself does not supply bookkeeping rules.
Does QuickBooks have an official MCP server?
Yes. Intuit publishes an open-source QuickBooks Online MCP server. Its documented setup runs locally over stdio and requires an Intuit developer app, OAuth authorization and a QuickBooks company connection.
Is a QuickBooks MCP server the same as the QuickBooks API?
No. The QuickBooks Online API is Intuit's programming interface, and a developer writes code against it. A QuickBooks MCP server wraps API operations as tools that an AI client can discover and call directly. Every MCP server for QuickBooks Online still uses that API and Intuit's OAuth underneath, so API permissions and limits still apply.
What is the difference between a local and a hosted QuickBooks MCP server?
A local stdio server runs as a process launched by a compatible client. A hosted server is operated at a network endpoint. Hosting, authentication, available tools and company access are separate things to check.
Can one MCP server work with both Claude and ChatGPT?
A remote server can work with both when it supports each client's transport and authentication requirements and your account permits custom connections. Configure and authorize it separately in each assistant. A local stdio process is not directly reachable by their web connectors.
Is MCP safe for financial data?
MCP alone is not a security guarantee. Review the server operator, permissions, enabled write tools, approval behavior and logs. Check the AI provider's and connector provider's data terms and settings; MCP does not determine training or retention.
Does this setup work with QuickBooks Desktop?
No. Intuit's repository and DeepLedger's connection described here target QuickBooks Online. Desktop needs a compatible integration using its own interfaces, such as the Desktop SDK or Web Connector. Check support for your edition and required actions before choosing a service.
Ready to test a connection? Open DeepLedger and start with the company check above.