booksguard · QuickBooks and Xero · updated
Approve every AI change to QuickBooks and Xero before it posts
Your AI assistant can create, change and delete invoices, bills, payments and journal entries in QuickBooks and Xero through their MCP servers, and the open-source servers write the moment they are called. booksguard is a free hook for Claude Code, Cowork, Codex and Gemini CLI that holds each of those writes until you approve it, shows you what would change, and keeps a log, per client, of what the AI wrote and who said yes.
One command, no signup
$ npx --allow-git=root github:agentwares/booksguard installWrites the hook into Claude Code, Codex and Gemini CLI where they are installed (user level), and ~/.booksguard/rules.json. No account, no signup. uninstall removes only booksguard's entries. For Cowork, add the booksguard plugin instead.
What you see
The agent's write is refused with a dry-run diff: the fields it would set, line totals, and for a journal entry the debits against the credits, flagged when they do not balance. The agent shows it to you and asks. Your yes, in your own message after the hold, lets the identical call through once. Text the agent writes never counts as your yes. A write identical to one already posted is flagged as a duplicate.
agent mcp__quickbooks__create_invoice
hook deny: held until a person approves
+ customer_ref: "58"
+ doc_number: "1042"
+ line 1: 1,250.00 · item_ref "12" · qty 10 · unit_price 125
= total 1,250.00 across 2 lines
person types: yes, post it
agent mcp__quickbooks__create_invoice (same arguments)
hook released, approved by your message at 14:05 UTC (“yes, post it”)What is held, server by server (read 9 October 2026)
| Server | Where it runs | Tools that write | Examples |
|---|---|---|---|
| Intuit QuickBooks connector (Claude directory) | ai-inc.quickbooks.intuit.com/v1/mcp | 27 of 74 | qbo_sales_create_invoice, qbo_sales_send_invoice, qbo_sales_delete_invoice, qbo_contact_create_customer, qbo_payroll_create_employee, quickbooks-transaction-import |
| Intuit's open-source QuickBooks Online MCP server | your machine (stdio) | 71 of 142 | create_invoice, update_invoice, delete_invoice, create_journal_entry, create-bill, create_payment, create_bill_payment, create_deposit, create_transfer |
| Meridian Connector for QuickBooks (Pilot) | qbo-connector.meridian.pilot.com/mcp | 32 of 63 | create_journal_entry, create_bill, delete_transaction, delete_entity, void_invoice, batch_entity_operations |
| Xero connector (Claude directory) | mcp.xero.com/mcp | none (read-only at launch) | — |
| Xero's open-source MCP server | your machine (npx @xeroapi/xero-mcp-server) | 24 of 50 | create-invoice (bills are type ACCPAY), create-payment, create-manual-journal, create-bank-transaction, update-contact, approve-timesheet |
Reads pass untouched. Calls to the QuickBooks or Xero API with curl, wget or HTTPie that are not a GET are held too, and so is any other command that names their API host. A tool on a server named for QuickBooks or Xero that booksguard has not catalogued is held unless it reads.
Where it works
| Where the agent runs | How you approve a held write |
|---|---|
| Claude Code | In your own next message (“yes, post it”), read from the session transcript; or in a terminal |
| Cowork | The same, through the booksguard plugin's hook (plugin hooks load in Cowork) |
| Codex | In a terminal: npx --allow-git=root github:agentwares/booksguard approve <id>. Trust the hook once in Codex's /hooks |
| Gemini CLI | In a terminal: npx --allow-git=root github:agentwares/booksguard approve <id> (written to Gemini CLI's hook docs) |
| Claude chat (web, desktop, mobile) | Not covered: chat ignores plugin hooks |
What it does not do
- It never calls QuickBooks or Xero, and sends nothing anywhere: the hook reads the call it is shown, the rulebook and the log on your machine.
- It cannot see inside a script the agent writes and then runs, unless the command line names the QuickBooks or Xero API host. A local hook is a seatbelt, not a vault.
- An update shows the fields it would set, not the values they replace: reading those would mean calling the ledger.
- The log records what was held, released and refused, and who approved each; the ledger's own answer to a released write is not recorded.
A dated price change
Intuit Books Close is free in beta and becomes $8 per onboarded client a month for up to 50 clients, or $6 above 50, from 21 January 2027 (Intuit's accountant pricing, read 9 October 2026). If your firm is re-pricing its close tools, the AI-write log is the part no ledger keeps for you.
Questions people ask
- Is the QuickBooks MCP server safe to let write?
- Xero MCP: approve before the AI posts
- Stop AI from changing your books without asking
For a bookkeeping firm
The free log stays on one machine. One firm-wide record of every client's AI changes, with a monthly sign-off, is not built yet. It would keep every client's held and approved writes across your staff in one place, with a reviewer sign-off per client per month. I want that record
Sources, each read on 9 October 2026
- Intuit QuickBooks connector, Claude's connector directory
- intuit/quickbooks-online-mcp-server on GitHub (commit 31a1dd5c3e17, 15 Sep 2026)
- Meridian Connector for QuickBooks, Claude's connector directory
- Xero: Get clear answers on your Xero finances from Claude
- XeroAPI/xero-mcp-server on GitHub (commit f24583c867df, 5 Jun 2026)
- QuickBooks Online Accountant pricing (Intuit)
- Claude Code hooks reference
- Plugin feature support across platforms (Claude)
- Codex hooks
- Gemini CLI hooks reference