QuickBooks Online API: Complete Developer Guide for 2026

The QuickBooks Online (QBO) API is the primary interface for programmatically interacting with Intuit’s cloud accounting platform.

Whether you’re building a SaaS integration, automating invoice workflows, or syncing financial data between systems, this API is the backbone of the QuickBooks ecosystem.

This guide covers everything a developer needs to go from zero to production with the QuickBooks Online API in 2026 authentication, endpoints, rate limits, webhooks, code examples, and the hard-won lessons that save you weeks of debugging.

If you’re evaluating whether to build a QuickBooks integration in-house or hire a team, this guide will give you the technical depth to make that decision confidently.

Does QuickBooks Online Have an API?

Yes. QuickBooks Online provides a REST-based Accounting API that developers can use to read and write accounting data such as:

  • Customers
  • Invoices
  • Payments
  • Bills
  • Vendors
  • Accounts
  • Journal entries
  • Items
  • Purchase transactions

The API uses OAuth 2.0 for authentication and is the primary API for applications integrating directly with QuickBooks Online accounting data.

QuickBooks Payments and QuickBooks Desktop use separate APIs and integration methods.

TL;DR Quick Start

  • What it is: A RESTful API for reading and writing accounting data in QuickBooks Online (invoices, customers, payments, journal entries, and more)
  • Auth: OAuth 2.0 (authorization code flow) — no API keys, no basic auth
  • Base URL: https://quickbooks.api.intuit.com/v3/company/{realmId}/
  • Sandbox URL: https://sandbox-quickbooks.api.intuit.com/v3/company/{realmId}/
  • SDKs and libraries: Intuit provides official SDKs and OAuth libraries, with additional community-supported libraries available for languages including Node.js, Python, and Ruby.
  • Rate limits: Up to 500 requests per minute per realmId, with a maximum of 10 concurrent requests per realmId. Batch requests have separate limits.
  • Fastest path to first call: Create an Intuit Developer account → create an app → use OAuth 2.0 Playground → make a GET request to /query?query=SELECT * FROM CompanyInfo

QuickBooks Online API Updates in 2026

QuickBooks Online developers should account for several API and developer-platform changes when building or maintaining integrations in 2026.

Minor Version 75 Is the Current Baseline

Since August 1, 2025, QuickBooks Online Accounting API requests using minor versions 1 through 74 are handled using minor version 75.

Applications should therefore:

  • Be compatible with minor version 75
  • Avoid relying on older response structures
  • Be designed to tolerate future schema additions

OAuth Refresh Tokens Now Have a Maximum Lifetime

QuickBooks OAuth refresh tokens should no longer be treated as indefinitely renewable credentials.

Intuit has introduced a maximum five-year lifetime for refresh tokens.

Developers should:

  • Store the latest refresh token returned during renewal
  • Track authorization expiration
  • Provide users with a reconnection process
  • Configure the Reconnect URL in the Intuit Developer Portal

QuickBooks Webhooks Now Use CloudEvents

QuickBooks Online webhook notifications have moved to the CloudEvents format.

Applications using the previous webhook payload structure should update their event-handling logic to support CloudEvents.

Reports API Responses Have Changed

QuickBooks has also modernized its Reports API infrastructure.

Applications processing financial reports should avoid relying on fixed row positions and account for changes involving:

  • Null values
  • Account hierarchy
  • Summarization
  • Response formatting
  • Supported reports

API Usage Includes Core and CorePlus Calls

Intuit’s App Partner Program categorizes API activity into Core and CorePlus usage

API ClassificationTypical Usage
CoreMany standard API operations
CorePlusMany retrieval and reporting operations

CorePlus usage is subject to monthly allowances based on the developer’s partner tier.

QuickBooks Online API Overview: How It Works

The QuickBooks Online API is a REST API that uses JSON for request and response payloads (XML is also supported but deprecated for most use cases).

Every API call targets a specific company (realm) identified by a realmId, and all requests require a valid OAuth 2.0 access token.

Architecture at a Glance

ComponentDetails
ProtocolHTTPS (TLS 1.2+)
Data FormatJSON (recommended) or XML
AuthenticationOAuth 2.0 (Authorization Code Grant)
Base URL (Production)https://quickbooks.api.intuit.com/v3/company/{realmId}/
Base URL (Sandbox)https://sandbox-quickbooks.api.intuit.com/v3/company/{realmId}/
VersioningMinor versions via minorversion query parameter (current: 75)
Response CodesStandard HTTP (200, 400, 401, 403, 404, 429, 500, 503)

Available SDKs

Intuit provides official SDKs that handle OAuth token management, request signing, and serialization:

LanguagePackage / RepositoryNotes
Node.jsnode-quickbooks (npm)Most popular community SDK; Intuit’s official SDK available via npm intuit-oauth
Pythonpython-quickbooks (PyPI)Well-maintained, supports all entity types
JavaQuickBooks-V3-Java-SDKOfficial Intuit SDK, Maven-compatible
.NETQuickBooks-V3-DotNET-SDKOfficial Intuit SDK, NuGet package available
PHPQuickBooks-V3-PHP-SDKOfficial Intuit SDK, Composer-compatible
Rubyquickbooks-ruby (gem)Community-maintained, actively updated

What Is the Best API for QuickBooks Online?

For applications that need to read or write accounting data, the QuickBooks Online Accounting API is the primary API to use.

Use CaseRecommended API
Accounting dataQuickBooks Online Accounting API
Customers and vendorsQuickBooks Online Accounting API
Invoices and billsQuickBooks Online Accounting API
Journal entriesQuickBooks Online Accounting API
Accounting reportsQuickBooks Online Accounting API
Payment processingQuickBooks Payments API
QuickBooks DesktopDesktop SDK / Web Connector

If your application needs customers, invoices, payments, bills, journal entries, accounts, or financial reports from QuickBooks Online, the Accounting API is generally the appropriate starting point.

QuickBooks Online API Official Documentation & Developer Resources

Intuit provides several official resources for developers building with the QuickBooks Online API.

ResourceBest Used For
QuickBooks Online API DocumentationUnderstanding APIs, entities, and supported operations
API ExplorerReviewing fields, endpoints, requests, and responses
OAuth 2.0 DocumentationAuthentication and token management
QuickBooks SandboxTesting integrations with sample company data
Postman CollectionsTesting API requests before implementation
Intuit Developer PortalManaging apps, credentials, webhooks, and production settings

This guide complements the official Intuit documentation by explaining how authentication, endpoints, synchronization, rate limits, webhooks, and production considerations work together in a real-world QuickBooks integration.

How to Authenticate with QuickBooks Online API Using OAuth 2.0

The QuickBooks Online API uses OAuth 2.0 Authorization Code flow exclusively. There are no API keys or basic auth options. Here’s how the flow works:

Step 1: Register Your App

Go to the Intuit Developer Portal (developer.intuit.com), create an account, and register a new app. You’ll receive:

  • Client ID (also called Consumer Key)
  • Client Secret (also called Consumer Secret)

Configure your redirect URI this is where Intuit sends the authorization code after the user grants access.

Before going live, developers should also understand the full app setup process inside the Intuit Developer Portal.

Step 2: Authorization Request

Redirect the user to Intuit’s authorization endpoint:

https://appcenter.intuit.com/connect/oauth2?
  client_id=YOUR_CLIENT_ID
  &redirect_uri=YOUR_REDIRECT_URI
  &response_type=code
  &scope=com.intuit.quickbooks.accounting
  &state=YOUR_CSRF_TOKEN

Scopes available:

  • com.intuit.quickbooks.accounting Full access to accounting data
  • com.intuit.quickbooks.payment Access to payment processing
  • openid profile email User identity information

Step 3: Exchange Authorization Code for Tokens

After the user authorizes, Intuit redirects to your redirect URI with an authorization_code. Exchange it for tokens:

// Node.js — Token Exchange
const axios = require("axios");

const tokenResponse = await axios.post(
  "https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer",
  new URLSearchParams({
    grant_type: "authorization_code",
    code: authorizationCode,
    redirect_uri: YOUR_REDIRECT_URI,
  }),
  {
    headers: {
      Authorization: `Basic ${Buffer.from(
        `${CLIENT_ID}:${CLIENT_SECRET}`
      ).toString("base64")}`,
      "Content-Type": "application/x-www-form-urlencoded",
    },
  }
);

const { access_token, refresh_token, expires_in } = tokenResponse.data;
// access_token expires in 1 hour (3600s)
// Refresh tokens use rolling renewal and now have a maximum five-year lifetime. Always store the latest refresh token returned by Intuit.

Step 4: Make Authenticated API Calls

Include the access token as a Bearer token in every request:

const response = await axios.get(
  `https://quickbooks.api.intuit.com/v3/company/${realmId}/companyinfo/${realmId}`,
  {
    headers: {
      Authorization: `Bearer ${access_token}`,
      Accept: "application/json",
    },
  }
);

QuickBooks OAuth Token Lifecycle

QuickBooks Online uses short-lived access tokens together with refresh tokens.

Access Token

  • Valid for approximately 60 minutes
  • Used for authenticated QuickBooks API requests
  • Must be renewed when it expires

Refresh Token

Refresh tokens use a rolling renewal model.

Applications should always securely store the latest refresh token returned during renewal.

Intuit has also introduced a maximum five-year lifetime for refresh tokens.

A production integration should therefore:

  • Store the newest refresh token after every successful renewal
  • Track authorization expiration
  • Refresh access tokens before API calls fail
  • Provide users with a clear reconnect flow
  • Configure the Reconnect URL in the Intuit Developer Portal

If authorization expires completely, the user must reconnect their QuickBooks company through the OAuth authorization flow.

QuickBooks Online API Endpoints for Invoices, Customers, Payments & Bills

Every endpoint follows the pattern: GET|POST /v3/company/{realmId}/{entity}. Here are the most-used endpoints:

EntityCreateReadUpdateDeleteQuery
InvoicePOST /invoiceGET /invoice/{id}POST /invoicePOST /invoice?operation=deleteGET /query?query=SELECT * FROM Invoice
CustomerPOST /customerGET /customer/{id}POST /customer— (deactivate only)GET /query?query=SELECT * FROM Customer
PaymentPOST /paymentGET /payment/{id}POST /paymentPOST /payment?operation=deleteGET /query?query=SELECT * FROM Payment
BillPOST /billGET /bill/{id}POST /billPOST /bill?operation=deleteGET /query?query=SELECT * FROM Bill
Bill PaymentPOST /billpaymentGET /billpayment/{id}POST /billpaymentPOST /billpayment?operation=deleteGET /query?query=SELECT * FROM BillPayment
Journal EntryPOST /journalentryGET /journalentry/{id}POST /journalentryPOST /journalentry?operation=deleteGET /query?query=SELECT * FROM JournalEntry
AccountPOST /accountGET /account/{id}POST /account— (deactivate only)GET /query?query=SELECT * FROM Account
VendorPOST /vendorGET /vendor/{id}POST /vendor— (deactivate only)GET /query?query=SELECT * FROM Vendor
ItemPOST /itemGET /item/{id}POST /item— (deactivate only)GET /query?query=SELECT * FROM Item
Purchase OrderPOST /purchaseorderGET /purchaseorder/{id}POST /purchaseorderPOST /purchaseorder?operation=deleteGET /query?query=SELECT * FROM PurchaseOrder

Important notes on CRUD operations:

  • Update = Full object replacement. You must send the complete entity object including the SyncToken (optimistic locking). Partial updates are not supported.
  • Delete is only available on transaction entities (invoices, payments, bills). Name-list entities (customers, vendors, items, accounts) can only be deactivated by setting Active: false.

Query language uses a SQL-like syntax. Example: SELECT * FROM Invoice WHERE TotalAmt > ‘1000’ ORDERBY MetaData.CreateTime DESC MAXRESULTS 100

QuickBooks Query API, Pagination and Change Data Capture

QuickBooks Online provides different methods for retrieving and synchronizing accounting data.

Query API

The QuickBooks Query API provides SQL-like syntax for retrieving records based on specific conditions.

Example:

SELECT * FROM Invoice WHERE Balance > '0'

Pagination

For larger datasets, use:

  • STARTPOSITION
  • MAXRESULTS

This prevents the application from attempting to retrieve all available records in a single request.

Change Data Capture

Change Data Capture, or CDC, can retrieve supported records that changed after a specified point in time.

CDC is particularly useful for incremental synchronization.

Recommended Production Sync Flow

Initial full data sync
↓
Pagination
↓
Store records locally
↓
CDC for incremental changes
↓
Webhooks for change notifications

This approach reduces repeated full-data requests and gives the integration better control over synchronization volume.

QuickBooks Online API Rate Limits in 2026

Limit TypeCurrent Limit
Standard API requests500 requests/minute per realmId
Concurrent requests10 concurrent requests per realmId
Batch requests40 batch requests/minute per realmId
Operations per batchUp to 30 operations

What Happens When the Limit Is Exceeded?

When API limits are exceeded, QuickBooks may return HTTP 429.

Production applications should use:

  • Request queuing
  • Exponential backoff
  • Retry handling
  • API request monitoring

Handling 429 (Too Many Requests) Errors

When you hit rate limits, the API returns a 429 status. Implement exponential backoff with jitter:

async function apiCallWithRetry(fn, maxRetries = 5) {
  for (let attempt = 0; attempt < maxRetries; attempt++) {
    try {
      return await fn();
    } catch (error) {
      if (error.response?.status === 429 && attempt < maxRetries - 1) {
        const baseDelay = Math.pow(2, attempt) * 1000;
        const jitter = Math.random() * 1000;
        await new Promise((r) => setTimeout(r, baseDelay + jitter));
        continue;
      }
      throw error;
    }
  }
}

Pro tips for staying under limits:

  • Use batch operations where possible (up to 30 entities per batch)
  • Use Change Data Capture (CDC) instead of polling individual entities: GET /cdc?entities=Invoice,Customer&changedSince=2026-01-01T00:00:00Z
  • Cache frequently-read reference data (Chart of Accounts, Items, Tax Codes) locally
  • Implement request queuing with rate limiting in your application layer

Common QuickBooks Online API Error Codes

QuickBooks integrations should handle API errors based on the HTTP status code and the returned fault information.

Error CodeMeaningRecommended Action
400Invalid request or business validation errorReview request body and fault details
401Authentication failureCheck or refresh the access token
403Permission deniedVerify application and user permissions
404Resource not foundVerify endpoint and entity ID
429Rate limit exceededRetry using exponential backoff
500Internal server errorRetry after a delay
503Service temporarily unavailableRetry after a delay

Production integrations should also log:

  • Request ID
  • realmId
  • Endpoint
  • Error response
  • Retry status
  • Timestamp

This makes production troubleshooting considerably easier.

Building for Higher QuickBooks API Volumes?

Rate limits, batching, retries, and synchronization architecture become more important as transaction volumes grow.

Satva can review your QuickBooks API architecture and help design a data-sync approach that works reliably at production scale.

Discuss Your QBO Architecture

Common QuickBooks Online API Issues Developers Should Avoid

We’ve built dozens of QuickBooks integrations at Satva Solutions. Here are the top gotchas that trip up developers:

1. SyncToken Conflicts

Every entity has a SyncToken that increments on each update. If you send a stale SyncToken, the API returns a 400 error. Always fetch the latest entity before updating.

2. No Partial Updates

Unlike modern APIs (e.g., PATCH support), the QBO API requires you to send the entire entity object on every update. Missing fields will be set to null.

This is the single most common source of data loss in QBO integrations. (Fix common QuickBooks Online Accounting API errors, 2026)

These limitations are not just theoretical. Missing fields and unsupported objects often require practical workarounds in real-world QuickBooks integrations.

3. Sparse Updates Misconception

Intuit documents a sparse=true parameter, but it has significant limitations.

It works inconsistently across entity types, and relying on it is risky. Our recommendation: always send the full object.

4. Currency and Locale Issues

Multi-currency companies require extra handling. You must specify CurrencyRef on transactions, and exchange rates are not automatically applied.

If you’re building for international users, plan for this complexity upfront.

5. Sandbox vs. Production Gaps

The sandbox environment doesn’t perfectly mirror production behavior. Certain edge cases (webhooks, specific error codes, rate limiting behavior) may differ.

Always perform thorough testing in production with a test company.

Already Running Into QuickBooks API Integration Issues?

Satva can review your existing QuickBooks integration, OAuth flow, data-sync logic, error handling, and API usage to identify what needs to be fixed before it becomes a production problem.

Review Your QuickBooks Integration

How to Test QuickBooks Online API in Sandbox

Setting Up Your Sandbox

  • Log into the Intuit Developer Portal at developer.intuit.com
  • Navigate to your app’s Dashboard
  • Click “Sandbox” in the left menu — Intuit provides pre-populated sandbox companies with sample data
  • Use sandbox credentials (Client ID + Secret from the “Development” keys section)
  • Point API calls to: https://sandbox-quickbooks.api.intuit.com/v3/company/{realmId}/

Sandbox Test Data

Sandbox companies come pre-loaded with sample customers, invoices, items, and accounts. You can also:

  • Create additional test data via API calls
  • Reset sandbox data from the developer portal
  • Use the API Explorer in the developer portal for interactive testing

Testing Best Practices

  • Write integration tests against sandbox before deploying to production
  • Test error handling: intentionally send malformed requests, expired tokens, and duplicate entities
  • Verify webhook delivery using tools like ngrok or webhook.site for local development
  • Test with multi-currency sandbox companies if your integration handles international clients

Teams planning wider accounting integrations should also compare QuickBooks with other accounting APIs before finalizing the architecture

QuickBooks Online API Webhooks and CloudEvents

QuickBooks Online webhooks notify your application when data changes, eliminating the need for constant polling.

Available Webhook Events

Webhooks fire on Create, Update, and Delete operations for these entities:

Account, Bill, BillPayment, Budget, Class, CreditMemo, Currency

Customer, Department, Deposit, Employee, Estimate, Invoice

Item, JournalEntry, Payment, Purchase, PurchaseOrder

RefundReceipt, SalesReceipt, TimeActivity, Transfer, Vendor, VendorCredit

Webhook Setup

  • In the Intuit Developer Portal, navigate to Webhooks in your app settings
  • Enter your endpoint URL (must be HTTPS)
  • Select the entities you want to subscribe to
  • Intuit generates a verifier token for signature validation

Webhook Payload Format in 2026

QuickBooks Online webhook notifications now use the CloudEvents format.

The previous:

eventNotifications → dataChangeEvent → entities

structure should no longer be used as the primary implementation example.

Important CloudEvents fields include:

FieldPurpose
specversionCloudEvents specification version
typeIdentifies the QuickBooks entity and event
timeTimestamp of the event
intuitentityidID of the affected QuickBooks record
intuitaccountidQuickBooks company associated with the event

Webhook notifications should be treated as change signals.

When your application requires the complete accounting record:

  • Receive the webhook event.
  • Identify the affected entity.
  • Identify the QuickBooks company.
  • Retrieve the latest record through the QuickBooks Online API.
  • Update the local application data.

Validating Webhook Signatures

Always validate the webhook signature to ensure the payload is from Intuit:

const crypto = require("crypto");

function isValidWebhookSignature(payload, signature, verifierToken) {
  const hash = crypto
    .createHmac("sha256", verifierToken)
    .update(payload)
    .digest("base64");
  return hash === signature;
}

Important: Webhook payloads only contain entity IDs and operation types — not the full entity data. You must make a follow-up API call to fetch the updated entity.

QuickBooks Online API Best Practices for Production Integrations

Error Handling

  • Always check the Fault object in error responses for detailed error codes and messages
  • Implement retry logic for 429 (rate limit), 500 (server error), and 503 (service unavailable)
  • Do not retry 400 (bad request) or 401 (unauthorized) these require code or token fixes
  • Log all API errors with full request/response bodies for debugging

Pagination

The QBO query API supports STARTPOSITION and MAXRESULTS:

SELECT * FROM Invoice STARTPOSITION 1 MAXRESULTS 100
SELECT * FROM Invoice STARTPOSITION 101 MAXRESULTS 100

Maximum MAXRESULTS is 1000. For large datasets, implement pagination loops and consider using CDC for ongoing sync instead.

Minor Version Management

  • Always specify the minorversion parameter in your API calls: ?minorversion=75
  • Pin to a specific version in production don’t use “latest”
  • Test new minor versions in sandbox before upgrading production
  • Monitor Intuit’s changelog for breaking changes in new minor versions

Idempotency

  • The QBO API supports a Request-Id header for idempotent requests
  • Use a unique UUID for each create operation to prevent duplicates on retries
  • For production-grade systems, real-world validation, duplicate prevention, and error handling are just as important as API connectivity.

This is especially important for payment and invoice creation, where duplicates cause real financial issues

Security

  • Store OAuth tokens encrypted at rest (never in plain text or client-side storage)
  • Implement token refresh proactively (before expiry, not after failure)
  • Use HTTPS everywhere Intuit rejects non-TLS connections
  • Scope your OAuth permissions to only what your app needs

Need to Take Your QuickBooks Integration to Production?

Satva can help design and build the OAuth flow, data synchronization, webhooks, retry logic, and accounting workflows required for a production-ready QuickBooks Online integration.

Discuss Your QuickBooks Integration

QuickBooks Online API Code Examples for Developers

Creating an Invoice (Node.js)

const axios = require("axios");

async function createInvoice(realmId, accessToken) {
  const invoice = {
    Line: [
      {
        Amount: 150.0,
        DetailType: "SalesItemLineDetail",
        SalesItemLineDetail: {
          ItemRef: { value: "1", name: "Services" },
          Qty: 1,
          UnitPrice: 150.0,
        },
      },
    ],
    CustomerRef: { value: "1" },
    BillEmail: { Address: "customer@example.com" },
    DueDate: "2026-04-15",
  };

  const response = await axios.post(
    `https://quickbooks.api.intuit.com/v3/company/${realmId}/invoice?minorversion=75`,
    invoice,
    {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "Content-Type": "application/json",
        Accept: "application/json",
      },
    }
  );

  return response.data.Invoice;
}

Querying Customers (Python)

import requests

def get_active_customers(realm_id, access_token, max_results=100):
    base_url = f"https://quickbooks.api.intuit.com/v3/company/{realm_id}"
    query = f"SELECT * FROM Customer WHERE Active = true MAXRESULTS {max_results}"

    response = requests.get(
        f"{base_url}/query",
        params={"query": query, "minorversion": "75"},
        headers={
            "Authorization": f"Bearer {access_token}",
            "Accept": "application/json",
        },
    )

    response.raise_for_status()
    data = response.json()
    return data.get("QueryResponse", {}).get("Customer", [])


# Usage
customers = get_active_customers(realm_id, access_token)
for customer in customers:
    print(f"{customer['DisplayName']} - {customer['PrimaryEmailAddr']['Address']}")

OAuth 2.0 Token Refresh

async function refreshAccessToken(refreshToken, clientId, clientSecret) {
  const response = await axios.post(
    "https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer",
    new URLSearchParams({
      grant_type: "refresh_token",
      refresh_token: refreshToken,
    }),
    {
      headers: {
        Authorization: `Basic ${Buffer.from(
          `${clientId}:${clientSecret}`
        ).toString("base64")}`,
        "Content-Type": "application/x-www-form-urlencoded",
      },
    }
  );

  const { access_token, refresh_token, expires_in } = response.data;
  // IMPORTANT: Store the NEW refresh_token — it rotates on each refresh
  // The old refresh_token is invalidated immediately
  return { access_token, refresh_token, expires_in };
}

QuickBooks Online API FAQs

Is the QuickBooks Online API Free in 2026?

QuickBooks API usage depends partly on the type of API call and the developer’s Intuit App Partner Program tier.

Intuit categorizes API usage into:

  • Core calls
  • CorePlus calls

Core calls include many standard operations, while CorePlus includes many retrieval and reporting operations.

The Builder tier:

  • Has no monthly partner-program fee
  • Includes a monthly CorePlus API credit allowance

Higher partner tiers provide larger usage allowances and may support additional usage according to Intuit’s current rate card.

Developers building high-volume QuickBooks integrations should review the latest Intuit App Partner Program pricing and API credit policies instead of assuming all API usage is unlimited.

What languages does the QuickBooks API support?

The QuickBooks Online API is language-agnostic since it’s a REST API. Intuit provides official SDKs for Java, .NET, PHP, Node.js, Python, and Ruby. You can also use any HTTP client in any programming language (Go, Rust, Swift, etc.) to interact with the API directly.

How do I get a QuickBooks API key?

QuickBooks doesn’t use traditional API keys. Instead, you register an app at developer.intuit.com to get OAuth 2.0 Client ID and Client Secret credentials. These are used in the OAuth 2.0 authorization flow to obtain access tokens. See our step-by-step guide to setting up an app on the Intuit Developer Portal.

What Are the QuickBooks Online API Rate Limits?

QuickBooks Online Accounting API production guidance allows:

  • Up to 500 requests per minute per realmId
  • Up to 10 concurrent requests per realmId
  • Up to 40 batch requests per minute per realmId
  • Up to 30 operations in one batch request

If a limit is exceeded, the API may return HTTP 429.

Production integrations should implement request queuing, retry handling, and exponential backoff.

Can I use the QuickBooks API with Desktop?

The QuickBooks Online API does not work with QuickBooks Desktop. Desktop uses a separate integration method via the QuickBooks Web Connector (QBWC) or the QuickBooks Desktop SDK, which uses XML-based messaging (qbXML). If you need to support both, you’ll need to build two separate integrations. Consider migrating Desktop clients to QuickBooks Online for API access.

How Do I Handle QuickBooks OAuth 2.0 Token Expiration?

QuickBooks access tokens are valid for approximately one hour.

When the access token expires:

  • Use the refresh token to request a new access token.
  • Save the latest refresh token returned by Intuit.
  • Update the token expiration information.
  • Retry the API request if required.

Refresh tokens now also have a maximum lifetime.

Applications should therefore provide users with a reconnection path rather than assuming an actively refreshed QuickBooks authorization will remain valid indefinitely.

Can the QuickBooks Online API Access Bank Feed Transactions?

The QuickBooks Online Accounting API can access supported accounting transactions after they are recorded in QuickBooks.

However, developers should not assume that raw bank-feed activity waiting in the “For Review” area is available through the standard Accounting API in the same way as posted accounting transactions.

If an application requires direct access to raw bank-account transaction feeds, it may need a separate banking-data integration in addition to the QuickBooks Online API.

Need Help Building Your QuickBooks Integration?

Satva Solutions has built 50+ QuickBooks Online integrations for SaaS companies, accounting firms, and enterprise teams. Whether you need a custom QuickBooks integration, API integration services, or AI-powered accounting automation, our team can help you ship faster and avoid the pitfalls covered in this guide.

Contact us

Article by

Chintan Prajapati

Chintan Prajapati is the Founder and CEO of Satva Solutions and a seasoned computer engineer with over two decades of experience in the software industry. His expertise spans Accounting & ERP Integrations, Robotic Process Automation, and the development of technology solutions built around leading ERP and accounting platforms with a particular focus on responsible AI and machine learning in fintech.Chintan holds a BE in Computer Engineering and carries an impressive roster of certifications, including Microsoft Certified Professional, Microsoft Certified Technology Specialist, Certified Azure Solution Developer, Certified Intuit Developer, Certified QuickBooks ProAdvisor, and Xero Developer.Over the course of his career, he has made a measurable impact on the accounting industry consulting on and delivering integration and automation solutions that have collectively saved thousands of man-hours. His writing aims to offer readers practical, insight-driven advice on harnessing technology to unlock greater business efficiency.When he steps away from the desk, Chintan can be found trekking through mountain trails or watching birds in the wild. Grounded in the philosophy of delivering the highest value to clients, he continues to champion innovation and excellence in digital transformation from his home base in Ahmedabad, India.