booksguard · QuickBooks and Xero · updated
Is the QuickBooks MCP server safe to let write?
As safe as your review of each write. Intuit's open-source QuickBooks Online MCP server has 71 tools that create, update or delete records across 29 entities, and runs each one as soon as it is called (its only switch removes the write tools altogether). Intuit's hosted connector in Claude has 27 tools that create, change, delete or send invoices, estimates, payment links, customers and employees, and Meridian's connector has 32, including delete_transaction and void_invoice (each read from its public source on 9 October 2026). booksguard holds every one of those writes until you approve it, whichever server makes it.
What each QuickBooks server can change
| Server | Where it runs | Tools that write | Examples |
|---|---|---|---|
| Intuit QuickBooks connector (Claude directory) | ai-inc.quickbooks.intuit.com/v1/mcp | 27 of 74 | qbo_sales_create_invoice, qbo_sales_send_invoice, qbo_sales_delete_invoice, qbo_contact_create_customer, qbo_payroll_create_employee, quickbooks-transaction-import |
| Intuit's open-source QuickBooks Online MCP server | your machine (stdio) | 71 of 142 | create_invoice, update_invoice, delete_invoice, create_journal_entry, create-bill, create_payment, create_bill_payment, create_deposit, create_transfer |
| Meridian Connector for QuickBooks (Pilot) | qbo-connector.meridian.pilot.com/mcp | 32 of 63 | create_journal_entry, create_bill, delete_transaction, delete_entity, void_invoice, batch_entity_operations |
| Xero connector (Claude directory) | mcp.xero.com/mcp | none (read-only at launch) | — |
| Xero's open-source MCP server | your machine (npx @xeroapi/xero-mcp-server) | 24 of 50 | create-invoice (bills are type ACCPAY), create-payment, create-manual-journal, create-bank-transaction, update-contact, approve-timesheet |
What goes wrong without a review
- A retried create posts twice: the open-source server has no idempotency guard yet (issue #100, open since 10 July 2026). booksguard flags a write identical to one already posted in the last 24 hours.
- A journal entry the model wrote out of balance: booksguard adds up the debits and credits and says so in the diff before anything posts.
- The wrong company: where the call names a QuickBooks company (realm), the diff and the log show it.
The built-in switches, and why they are not enough for a bookkeeper
Intuit's open-source server can drop whole categories of tools with QUICKBOOKS_DISABLE_WRITE, QUICKBOOKS_DISABLE_UPDATE and QUICKBOOKS_DISABLE_DELETE. That makes it read-only, which is right when the AI should never write. When you want it to write after you look, the write tools must stay, and something has to hold each call. Claude Code's own permissions.ask rules can prompt for named tools, in Claude Code only, with no record kept of what was approved.
Hold every write instead
$ npx --allow-git=root github:agentwares/booksguard installWrites the hook into Claude Code, Codex and Gemini CLI where they are installed (user level), and ~/.booksguard/rules.json. No account, no signup. uninstall removes only booksguard's entries. For Cowork, add the booksguard plugin instead.
agent mcp__quickbooks__create_invoice
hook deny: held until a person approves
+ customer_ref: "58"
+ doc_number: "1042"
+ line 1: 1,250.00 · item_ref "12" · qty 10 · unit_price 125
= total 1,250.00 across 2 lines
person types: yes, post it
agent mcp__quickbooks__create_invoice (same arguments)
hook released, approved by your message at 14:05 UTC (“yes, post it”)Limits
- It never calls QuickBooks or Xero, and sends nothing anywhere: the hook reads the call it is shown, the rulebook and the log on your machine.
- It cannot see inside a script the agent writes and then runs, unless the command line names the QuickBooks or Xero API host. A local hook is a seatbelt, not a vault.
- An update shows the fields it would set, not the values they replace: reading those would mean calling the ledger.
- The log records what was held, released and refused, and who approved each; the ledger's own answer to a released write is not recorded.
For a bookkeeping firm
The free log stays on one machine. One firm-wide record of every client's AI changes, with a monthly sign-off, is not built yet. It would keep every client's held and approved writes across your staff in one place, with a reviewer sign-off per client per month. I want that record
Sources, each read on 9 October 2026
- intuit/quickbooks-online-mcp-server on GitHub (commit 31a1dd5c3e17, 15 Sep 2026)
- Intuit QuickBooks connector, Claude's connector directory
- Meridian Connector for QuickBooks, Claude's connector directory
- quickbooks-online-mcp-server issue #100, DocNumber-based idempotency guard for create-tool retries (10 Jul 2026)
- Claude Code hooks reference