QuickBooks + Kroy

Connect QuickBooks once. Use it safely with any AI.

  1. QuickBooks, where it already is.

    QuickBooks stays the authoritative record. Nothing moves, and nothing is copied that doesn’t need to be.

  2. QuickBooks connects to Kroy.

    OAuth 2. Kroy holds the connection.

  3. Your AI connects to Kroy.

    Claude, ChatGPT or another AI connects to Kroy — not to QuickBooks. It never receives QuickBooks credentials.

  4. Exactly what is allowed.

    Each QuickBooks action is a Kroy capability; create invoice waits for a person by default. QuickBooks Online only. QuickBooks Desktop is not in scope for this connector.

  5. A real request.

    Claude asks for read customers. Kroy checks the person, the agent and the policy, calls QuickBooks, and records the request.

QuickBooks
Kroy
Claude
Priya Client manager
AUDIT

QuickBooks capabilities

  • quickbooks.customers.read
  • quickbooks.invoices.read
  • quickbooks.bills.read
  • quickbooks.estimates.create
  • !quickbooks.invoices.create
  • QuickBooks Online only. QuickBooks De…
QuickBooks
Kroy
Claude
Priya Client manager
AUDIT

QuickBooks capabilities

  • quickbooks.customers.read
  • quickbooks.invoices.read
  • quickbooks.bills.read
  • quickbooks.estimates.create
  • !quickbooks.invoices.create
  • QuickBooks Online only. QuickBooks De…
QuickBooks connecting to Kroy, then to an authorised AI. QuickBooks, where it already is.. QuickBooks connects to Kroy.. Your AI connects to Kroy.. Exactly what is allowed.. A real request..

Supported resources

  • Company information
  • Customers
  • Suppliers
  • Invoices
  • Bills
  • Estimates
  • Payments (read)
  • Reports (profit and loss, balance sheet, aged receivables, aged payables)

Authentication

OAuth 2.0 with Intuit, authorised by a QuickBooks Online administrator. The connection is held by Kroy; AI clients never receive QuickBooks tokens.

Supported actions

CapabilityTypeDefault
quickbooks.customers.read
Read customers
readPolicy
quickbooks.invoices.read
Read invoices
readPolicy
quickbooks.bills.read
Read bills
readPolicy
quickbooks.reports.read
Read reports
readPolicy
quickbooks.estimates.create
Create estimate
writePolicy
quickbooks.invoices.create
Create invoice
writeHuman approval
quickbooks.invoices.send
Send invoice to customer
writeHuman approval
quickbooks.bills.create
Record bill
writeHuman approval

Events

quickbooks.invoice.createdquickbooks.payment.received

Overview

QuickBooks stays the authoritative record. Kroy connects to QuickBooks Online once, so that authorised AI — Claude, ChatGPT and others — can use QuickBooks data and actions without each AI tool holding its own access to the books.

A finance manager can ask “Which customers are more than sixty days overdue, and what do they owe?” The AI calls Kroy. Kroy checks who is asking, which agent is asking for them and what they may see, reads the aged receivables report, and returns only the rows that person is entitled to.

Permissions

Each QuickBooks action is a Kroy capability. Kroy decides every request against the person, the agent, the delegation between them, the organisation’s policies and any approval requirement.

By default, AI may read and prepare. It may create estimates. Creating invoices, sending anything to a customer and recording bills all require a person to approve first. An organisation can tighten these defaults further, for example by allowing a particular Skill to read reports but nothing else.

Drafts before books

Changes to financial records are hard to reverse cleanly. The safe pattern is that AI prepares the work — a reconciliation note, a proposed invoice, a list of miscoded transactions — and a person decides what goes into QuickBooks. Kroy records both the proposal and the decision.

Industries

Accountancy practices that look after several QuickBooks companies can map each member of staff to the clients they work on. An AI acting for a manager then sees that manager’s clients only, and nothing from the rest of the practice.

Small and medium-sized businesses using QuickBooks for their own books can let the finance team use AI for month-end questions while keeping payroll and banking out of reach.

Security

Kroy holds the QuickBooks connection. AI clients receive the results of authorised requests, never the tokens. Revoking an AI’s access to Kroy removes its access to QuickBooks at the same moment, and every request — permitted or refused — is recorded in the audit trail.

Limitations

  • QuickBooks Online only. QuickBooks Desktop is not in scope for this connector.
  • Payroll is excluded by default.
  • Bank details and bank feed settings cannot be changed through Kroy.
  • Kroy cannot see or do more than the QuickBooks connection it holds is allowed to.
  • Actions are subject to Intuit’s own API rate limits.