You log into QuickBooks Online, generate an access token, and paste it into the third-party app you want to connect

QuickBooks Online does not let you hand over your password to other applications. Instead, it uses a system called OAuth, which creates a limited-access token that you can revoke at any time. The app you are connecting never sees your actual QuickBooks password. You authorize the connection once, and the app can then read or write the data you permitted it to access.

The process takes about five minutes and happens in two places: inside QuickBooks Online, where you approve the connection, and inside the third-party app, where you paste the token or complete the authorization flow. The exact steps depend on which app you are connecting, but the underlying mechanism is the same.

Key Takeaways

  • QuickBooks Online uses OAuth tokens instead of passwords, so third-party apps never see your login credentials.
  • You start the connection from inside the third-party app, which will redirect you to QuickBooks Online to approve access.
  • You can revoke access to any connected app at any time from the QuickBooks Online settings menu.
  • The app will ask you to choose which QuickBooks company file to connect and what data it can read or write.

Starting the connection from the third-party app

Most apps that work with QuickBooks Online have a settings or integrations page where you can add a new connection. Look for a button that says "Connect QuickBooks" or "Link QuickBooks Account" or "Authorize QuickBooks Online". Click it.

The app will open a new window or redirect your browser to QuickBooks Online's authorization page. You will see a screen that says something like "This app is requesting access to your QuickBooks data" and lists what the app wants to do — for example, "Read and write to your chart of accounts" or "Read your customer list". Read this list carefully. If the app is asking for more access than it needs, you can refuse and try a different app.

If you are not already logged into QuickBooks Online, you will be asked to log in now. Use the email and password for your QuickBooks Online account.

Choosing which company file and what data to share

After you log in, QuickBooks will ask you to choose which company file the app should connect to. If you have only one company file, it will be selected already. If you have multiple files, choose the one you want the app to access. You cannot connect a single app to multiple company files at once — you would need to repeat this process for each file.

Next, you will see a list of permissions. These vary by app. A payroll app might ask to read employees and write to payroll expenses. A bookkeeping app might ask to read all accounts and write to journal entries. A tax app might ask to read transactions but not write anything. You cannot customize these permissions — the app either gets the full set it is asking for, or you refuse the connection.

Click "Authorize" or "Allow" to proceed. QuickBooks will generate a token and send it back to the third-party app.

What happens after you authorize

The third-party app now has a token that lets it access your QuickBooks data according to the permissions you granted. You should see a confirmation message in the app saying the connection is active. Some apps will when ready start syncing data; others will wait until you tell them to.

The token does not expire on its own. It stays active until you revoke it. You do not need to re-authorize every time you use the app.

Revoking access if you stop using the app

If you want to disconnect an app, you do not delete it from your phone or computer. You revoke its token inside QuickBooks Online. Log into QuickBooks Online, go to Settings (the gear icon in the top right), then select "Apps and Integrations" or "Connected Apps". You will see a list of every app that has access to your QuickBooks data. Find the one you want to disconnect and click "Disconnect" or "Revoke". The app will when ready lose access to your QuickBooks data.

Revoking access does not delete any data the app already wrote to QuickBooks. If the app created transactions or accounts, those remain in your file. You would need to delete them manually if you want them gone.

Troubleshooting a failed connection

If the connection fails or gets stuck on the authorization screen, the most common cause is that you are logged into QuickBooks Online with a different email address than the one you expected. Log out completely, clear your browser cookies, and try again. Make sure you are using the email address that owns the QuickBooks Online account.

If the app says it cannot find your company file, check that you chose the correct file during authorization. Some apps also require that your QuickBooks subscription include certain features — for example, some accounting apps need QuickBooks Plus or higher. Check the app's documentation to see what subscription level it needs.

If you see an error message about "insufficient permissions", the app is trying to do something your user role in QuickBooks does not allow. Ask your QuickBooks administrator to give your user account the necessary permissions, then try connecting again.

What data the app can actually see

The permissions you grant determine what the app can read and write. An app with "read-only" access to your chart of accounts can see every account but cannot create new ones or change existing ones. An app with "write" access can create transactions, but only if you also granted it "read" access to the accounts it needs to write to.

Apps cannot see your password, your bank login credentials, or any data you did not explicitly grant them access to. If you have multiple company files, an app connected to one file cannot see the others. The token is specific to that file and that app.

Frequently Asked Questions

Can I use the same app with multiple QuickBooks company files?

You would need to authorize the app separately for each file. Log into QuickBooks Online with the first company file, go through the authorization process, then switch to the second company file and repeat. Each connection gets its own token.

What if I forget which apps I have connected?

Go to Settings in QuickBooks Online, then "Apps and Integrations" or "Connected Apps". You will see every app that currently has access to your data, along with when it was authorized and what permissions it has.

Does the app see my bank account login information?

No. The app only sees what QuickBooks lets it see through the token. Your bank login credentials are stored only in QuickBooks and are never shared with third-party apps, even if the app is designed to pull bank transactions.

Can I change what permissions an app has after I authorize it?

No. If you want to change permissions, you must revoke the connection and authorize it again. When you re-authorize, you will see the permission list again and can choose to allow or refuse the connection based on the new permissions the app is requesting.

What happens to the app's data if I revoke access?

The app loses the ability to read or write to QuickBooks going forward, but any data it already wrote to your QuickBooks file stays there. If you want that data removed, you need to delete it manually from QuickBooks.