DeepLedger
Menu

Connect an agent

QuickBooks MCP Server: Official, Self-Hosted and Hosted Options

Does QuickBooks have an MCP server? Compare Intuit's official server with a hosted connection, check Claude and ChatGPT compatibility, and verify your first task.

Published by DeepLedgerUpdated 13 min read

Yes, QuickBooks Online has an official MCP server from Intuit. It runs locally and gives a compatible AI client tools to work with your QuickBooks company. You can also maintain your own deployment or connect to a hosted service such as DeepLedger.

The practical choice is who will operate the server and how your AI client reaches it. Intuit's documented server uses a local stdio process. DeepLedger provides a remote URL, with QuickBooks authorization handled through its portal.

Choose Your Setup

Your situationStart hereWhat you need
You want to run Intuit's server on your machineOfficial local setupA compatible local MCP client, Intuit developer app and QuickBooks OAuth connection
Your team needs custom tools or deployment controlsYour own deploymentSomeone to maintain the server, credentials, permissions and client transport
You want a connection for a supported AI client without operating a serverDeepLedger hosted setupDeepLedger account, authorized QuickBooks company and compatible client access
You use QuickBooks DesktopDesktop connection optionsA Desktop-compatible integration; the Online routes here do not read company files

Before choosing, name the first job you need done: an aging report, an invoice, a journal entry or something else. Check that the server exposes that operation and the fields you need. An MCP connection by itself does not establish which accounting tasks are supported.

What Is a QuickBooks MCP Server?

The Model Context Protocol (MCP) is the interface between the AI application and the server. The server then talks to QuickBooks Online through its API. QuickBooks remains the place where the books are recorded.

For example, a report tool can retrieve a dated profit and loss report for the AI to explain. An invoice creation tool can write a new invoice. Those are different actions with different consequences; connecting a server does not mean every request is read-only.

The MCP architecture documentation explains this client/server relationship. For the accounting context, see our guide to MCP servers for accounting work.

QuickBooks MCP vs. QuickBooks API for AI Agents

The two are layers, not alternatives. The QuickBooks Online API is Intuit's programming interface: a developer registers an app, handles OAuth, and writes code for each request. A QuickBooks MCP server sits on top of that API and presents its operations as named tools with typed inputs, so an AI client can discover and call them without custom integration code for each one.

QuestionQuickBooks API directlyQuickBooks MCP server
Who writes the integration?Your developers, per operationThe server author; the AI client calls tools
How does the AI use it?Through code you write and maintainThrough tools it discovers at connection time
What handles Intuit OAuth?Your applicationThe server, local or hosted
Which limits apply?Intuit's API rate limits and scopesThe same limits, plus whatever the server restricts
Best fitA product or workflow you build and controlGiving an existing AI client access to the books

Because every QuickBooks MCP server for Online uses that API underneath, the MCP label does not add or remove any Intuit permission. It changes who does the integration work and how the AI client reaches the data. If your team already maintains a QuickBooks integration, the API route may remain the right one. If you want Claude, ChatGPT, or an agent framework to work with the books, an MCP server saves that work.

Your Three Options in 2026

Intuit also offers a first-party QuickBooks connector inside Claude, documented in Intuit's help article. It is a built-in connector rather than an MCP server you install. Check its current availability and supported actions in your account. Our Claude connection guide compares it with the hosted route below.

1. Intuit's Official MCP Server (Local)

Intuit's QuickBooks Online MCP server repository includes record operations and financial reports. The documented installation runs as a local stdio subprocess: a compatible AI client launches the server and exchanges messages with it.

Setup requires an Intuit developer app, OAuth authorization and the target company's realm ID. The README covers sandbox versus production callbacks and token storage. It also documents separate switches for disabling create, update and delete tools.

This route suits someone who can install and maintain the software. Keep the OAuth credentials in the server configuration, outside the AI conversation.

2. Self-Hosting an Open-Source Server

If your team needs control over deployment or custom tools, it can operate its own server. For a remote client, provide a compatible remote transport or a supported private-server tunnel. A local stdio process is not itself a public endpoint.

Your team owns credential storage, authorization, updates, availability and logs. Multiple companies also require deliberate separation of credentials and access. Identify who will maintain the connection when a token refresh fails or an API changes.

3. A Hosted MCP Platform

A hosted provider operates the server at a remote URL and supplies a connection flow. Providers differ in their tools, authentication, company access and review controls.

DeepLedger is one hosted option for QuickBooks Online. Its company tools can list the companies you can access and select an active company. Confirm that company before requesting work, especially when using more than one AI client. Our multiple-company guide explains how the shared active company works.

The Comparison at a Glance

QuestionIntuit's documented local setupYour own deploymentHosted provider
Who operates it?YouYour teamThe provider
How does the AI connect?A client launches a stdio processThe transport you implementA supported remote endpoint
What do you configure?Developer app, OAuth and local credentialsServer, credentials and access controlsProvider account and client connection
Can web AI clients use it?Not directly over stdioIf you provide compatible remote accessCheck client and account requirements
How are companies separated?A configured company connectionYour implementationCheck the provider's access model
What about approvals and logs?Inspect the implementationYour responsibilityVerify the actual behavior

Why Local vs. Remote Matters for Your AI Client

A local stdio client can be a desktop application, a command-line tool or a custom agent host. A remote HTTP client connects over a network instead of launching that subprocess.

Claude's custom web connectors need a reachable remote server. ChatGPT supports remote MCP connections and also documents a Secure MCP Tunnel for private servers. A tunnel adds its own setup and permissions. For DeepLedger's hosted route, use the public HTTPS endpoint below.

There are two connections to distinguish: the AI application's access to the MCP server, and the server's access to QuickBooks. The MCP authorization specification covers the former. A QuickBooks OAuth connection does not, by itself, establish what the AI client is allowed to do.

Setting Up a Hosted QuickBooks MCP Server

Start by creating a DeepLedger account or signing in to your existing account, then connect the intended QuickBooks Online company. In Settings → Company and QBO Connect → Companies, find the intended company, select Connect QB and complete Intuit's authorization flow. You need access to the company in DeepLedger and permission to connect it in QuickBooks.

Then add the remote endpoint to your AI assistant:

https://mcp.deepledger.ai/mcp

In Claude: the current individual Pro/Max instructions use Customize → Connectors → + → Add custom connector. Enter the URL, add the connector, and connect to authorize it. On Team or Enterprise, an owner must add the custom connector before members can connect. See Anthropic's current custom-connector instructions for your plan.

In ChatGPT: OpenAI's current instructions say to enable Developer mode in Settings → Security and login, then use the plus button on the Plugins page to create a developer-mode app for the remote server. Complete authorization and select the app in the conversation's Developer mode tools. Check OpenAI's developer-mode guide for eligibility and controls available to your account.

Menu labels and workspace policies can change. If the custom-connection option is missing, check those official instructions and your workspace permissions before changing server settings. Do not paste credentials into the chat.

Once connected, make a small read request:

Use DeepLedger to show the active QuickBooks company name and home currency. Do not create or change any QuickBooks records. If no company is selected, list the companies I can access and ask me which to use.

Confirm the returned company before continuing. DeepLedger's normal company switching affects later calls across your connected AI clients; a credential fixed to one company cannot switch.

For more context, see our connection walkthrough and guides for ChatGPT, Claude Code, Copilot Studio, CrewAI, LangChain, and Gemini Spark. Use the current client documentation above if menu labels differ.

Check the Connection With a Real Task

Start with requests whose results you can compare with QuickBooks:

  • Explain a report: "Retrieve the profit and loss report for April 1 through June 30, 2026, on the accrual basis. Compare it with January 1 through March 31 on the same basis. Show the company and reporting currency."
  • Prepare a review list: "Find posted transactions in uncategorized accounts for August 2026. Show dates, amounts and existing categories, and identify missing evidence. Do not change any records."
  • Review receivables: "Retrieve accounts receivable aging detail as of September 30, 2026. Separate overdue invoices from credits and unapplied payments. Do not change records or send messages."

All three require suitable report or transaction tools. For a write, specify the company, source document, date and intended action. DeepLedger can also post multi-line journal entries: the AI journal-entry walkthrough follows an approved accrual schedule through posting and verification. The Grok overdue-invoice guide takes the receivables request through payment checks and follow-up drafts.

For bank cleanup, distinguish downloaded bank-feed items from posted entries using our uncategorized-transactions guide. Our workflow overview covers the wider review process; tool access alone does not establish that a close or reconciliation is complete. For what AI can and cannot do with the books themselves, see what an AI general ledger actually means.

Verify a report before expanding the workflow

We checked DeepLedger's qbCompanyProfile and qbReports tools against our designated Demo company on September 20, 2026. An accrual P&L for August 1–31 returned USD 3,400.00 income, USD 183.50 cost of goods sold and USD 926.50 net income. The matching P&L Detail report tied to those totals. These are demo figures, not customer results or a profitability claim.

The worked P&L analysis shows the full comparison, supporting entries and the zero-baseline problem the AI must handle. Use the same checks on your own company: identity, currency, dates, accounting basis and detail totals. A successful connection alone does not prove the answer is correct.

Is It Safe to Give an AI Access to Your Books?

Evaluate the actual connection, not the MCP label:

  • Access: Who operates the server, which company can it reach, and how can you revoke access?
  • Actions: Which tools can write, and what requires approval? A prompt asking for read-only work is not a substitute for disabling write tools when your client or server supports that.
  • Evidence: Can you inspect the request, result and resulting QuickBooks record? Ask what the logs include rather than assuming every read and write is retained.
  • Data handling: Check both providers' terms and settings for retention and training. Returning data as conversation context does not settle either question.

Keep accounting judgment and final review with someone who understands the books. Our article on accounting audit trails discusses questions to ask; the providers' current terms and actual controls govern your connection.

What About QuickBooks Desktop?

The Intuit repository above and DeepLedger's connection target QuickBooks Online. They do not connect directly to a QuickBooks Desktop company file.

Desktop has separate integration interfaces. Intuit documents the Desktop SDK and Web Connector route, which lets compatible web services exchange data with Desktop. Check the integration's supported edition and read/write actions. Evaluate Desktop-compatible options against the work you need done before considering a migration.

Our QuickBooks Desktop connection guide separates Claude's local MCP route from ChatGPT's web connection requirements and explains how to analyze an exported report. If you want a DeepLedger Desktop connection, join the Desktop waitlist; we are measuring demand before deciding whether to build it.

When a connection is not working

If tools load but your company or reports are unavailable, follow our QuickBooks MCP connection troubleshooting guide. It separates tool discovery, DeepLedger sign-in, company selection, Intuit authorization and report settings so you can repair the failing step.

Next step: verify one company and one report

In DeepLedger Settings → Company and QBO Connect, find the intended company under Companies. If it is not connected, choose Connect QB and have an authorized person complete Intuit sign-in. Start with a demo company when testing a new AI provider; do not send private business reports until your organization has approved that provider and its data settings.

With DeepLedger enabled in your AI client, ask:

Using DeepLedger, list the companies I can access and identify the active company. Ask me which company to use. After I choose, select it and confirm its name and company identifier. Do not create or change accounting records.

Company selection can persist across your connected AI clients. Confirm it again when changing sessions; a company-bound credential may not allow switching. See selecting the right QuickBooks company.

Then replace the bracketed name with that confirmed company:

Using DeepLedger for [confirmed company], retrieve the profit and loss for September 1 through September 30, 2026, on an accrual basis. Show the returned company name and identifier, exact dates, accounting basis, currency, income, expenses and net income. Do not create or change accounting records. If the company or report settings cannot be confirmed, stop and explain the missing information.

In QuickBooks Online → Reports → Profit and Loss, run the report for the same company, September 1–30, 2026, accrual basis, currency and filters. Compare income, expenses and net income, then investigate any differing account lines. A successful tool response includes report data and matching context; a “connected” badge or an AI summary alone is not verification. If totals differ, correct the context and rerun before relying on the result. Follow the P&L analysis and verification workflow.

A read-only prompt is not read-only permissions. The connection can expose write tools; review permissions and proposed actions. After the report agrees, choose a real task from the journal-entry review workflow or overdue-invoice workflow, adapting the client-specific steps to your AI app.

Frequently Asked Questions

What is a QuickBooks MCP server?

It is software that gives an AI application tools for accessing QuickBooks data through the Model Context Protocol. The server determines which reports, records and write actions are available. MCP itself does not supply bookkeeping rules.

Does QuickBooks have an official MCP server?

Yes. Intuit publishes an open-source QuickBooks Online MCP server. Its documented setup runs locally over stdio and requires an Intuit developer app, OAuth authorization and a QuickBooks company connection.

Is a QuickBooks MCP server the same as the QuickBooks API?

No. The QuickBooks Online API is Intuit's programming interface, and a developer writes code against it. A QuickBooks MCP server wraps API operations as tools that an AI client can discover and call directly. Every MCP server for QuickBooks Online still uses that API and Intuit's OAuth underneath, so API permissions and limits still apply.

What is the difference between a local and a hosted QuickBooks MCP server?

A local stdio server runs as a process launched by a compatible client. A hosted server is operated at a network endpoint. Hosting, authentication, available tools and company access are separate things to check.

Can one MCP server work with both Claude and ChatGPT?

A remote server can work with both when it supports each client's transport and authentication requirements and your account permits custom connections. Configure and authorize it separately in each assistant. A local stdio process is not directly reachable by their web connectors.

Is MCP safe for financial data?

MCP alone is not a security guarantee. Review the server operator, permissions, enabled write tools, approval behavior and logs. Check the AI provider's and connector provider's data terms and settings; MCP does not determine training or retention.

Does this setup work with QuickBooks Desktop?

No. Intuit's repository and DeepLedger's connection described here target QuickBooks Online. Desktop needs a compatible integration using its own interfaces, such as the Desktop SDK or Web Connector. Check support for your edition and required actions before choosing a service.

Ready to test a connection? Open DeepLedger and start with the company check above.

Ready to get started?

Connect QuickBooks and try your first task with an AI agent.

Create an Account