Every QuickBooks Online Accounting entity, plus an offline SQLite mirror and AR/AP aging.
QUICKBOOKS_ACCESS_TOKENAPI keyrequiredOAuth 2.0 bearer access token (scope com.intuit.quickbooks.accounting). Mint it from the Intuit OAuth 2.0 Playground or `quickbooks-cli auth refresh`.
QUICKBOOKS_CLIENT_IDOAuth appoptionalClient ID of your Intuit app (developer.intuit.com > your app > Keys). Set it with the client secret and refresh token so the CLI can mint a fresh access token; leave blank if you paste an access…
QUICKBOOKS_CLIENT_SECRETOAuth appoptionalClient secret paired with QUICKBOOKS_CLIENT_ID.
QUICKBOOKS_REFRESH_TOKENOAuth appoptionalOAuth 2.0 refresh token. Refresh tokens live ~100 days and rotate on every refresh, so the CLI writes the new one back to its config.
Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
The repository archive could not be read at scan time (The operation was aborted due to timeout), so no tool declarations could be extracted from it. Nothing here is a statement about what this exposes.
Every QuickBooks Online Accounting entity, plus an offline SQLite mirror and AR/AP aging.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.