LPTools

LP Tools

Documentation

Everything you need to run the Lewis Partners QuickBooks connector.

What this is

This connector links each client's QuickBooks Online company to Claude AI. There is one connector for the whole firm, and what it reaches is decided by who signed in — the clients that person has been granted, and the tools they have been given. Stored QuickBooks tokens are AES-256 encrypted; passwords and session tokens are kept only as hashes.

Onboard a client (2 steps)

1 — Create and connect. On the Dashboard, click Create & connect under Add a client. You do not need a name first — leave the field blank and you go straight to QuickBooks. Sign in with your QBOA login and pick that client's company in Intuit's company picker. One authorization = one company, always with your own login — clients are never involved.

2 — Name it (optional). The client is named after the QuickBooks company automatically. If you want a different label, edit the name on its dashboard row and click Save name. Renaming is safe at any time — it only changes how the client is identified, never the connection.

Adding to Claude. Nothing to do per client — the connector covers all of them. Add https://tools.lewispartners.ca/mcp once in Claude (Settings → Connectors → Add custom connector, OAuth fields left blank) and sign in when asked. See The Claude connector & signing in below.

The Claude connector & signing in

There is one URL to give Claude — https://tools.lewispartners.ca/mcp — and it is safe to paste anywhere, because on its own it opens nothing. The first time Claude uses it, Claude sends you here to sign in with your LP Tools email and password and to approve the connection. Only then does Claude receive an access token, and that token belongs to you: every request it makes shows up in the audit trail under your name.

Each person adds the same URL and signs in as themselves. Access lasts 90 days per device and refreshes quietly while it is in use. Claude never sees your password — it only ever receives a token, and you can cut that token off at any moment from My profile → Devices & AI connections.

Every connector URL on the dashboard is hidden when the page loads and only shows when you press the eye beside it, so nothing sensitive is sitting on screen during a screen-share. Copy copies the real URL whether it is showing or hidden.

Once connected, Claude reaches every client with read and write access, picking the client per request and confirming the client name before any change. New clients you add later are included automatically — nothing to change in Claude.

Connector keys — withdrawn

Until 7 August 2026 a connector could also be a URL with a secret key in it: a master key reaching every client, and a key per client. Anyone holding one of those URLs reached the books with no sign-in, was bound by no permissions, never expired, and could only ever be recorded in the audit trail as "master key" rather than by name.

All of them have been withdrawn and the keys destroyed. Those URLs now answer 410 and point here. If you find one written down in an old note, it is worthless — use the sign-in connector above.

Audit trail

The Audit tab records who did what, when, and from which network address — sign-ins and failed sign-in attempts, user and role changes, client changes, settings changes, AI connections being approved or revoked, and every request Claude makes to QuickBooks. Changes to a client's books are marked separately from reads, so "what did we change in this client's file, and who asked for it" is one filter away.

Super admins see the whole firm's trail and can filter by user, activity type, period, or free text. Staff see their own. Entries are not editable or deletable from the interface.

Devices & AI connections

Every browser sign-in and every authorized AI platform is listed with its device, approximate location, network address, and when it was last active — on My profile for yourself, and on a user's Edit page for anyone else. In the Users table, click the “N devices · N AI apps” line on any row to open the same detail inline.

Location comes from the network address, so treat it as a rough hint rather than an exact place. If something looks wrong, Sign out that device or Disconnect that AI platform — it stops working immediately, and the person simply signs in again next time.

Disconnecting and removing clients

Disconnect drops the QuickBooks link but keeps the client in your list: the stored tokens are deleted here and revoked at Intuit, so Claude can no longer reach those books. Use Reconnect when you want it back.

Remove deletes the client outright — its tokens, its connector key and its row. The books themselves in QuickBooks are untouched; this only removes LP Tools' access and record of the client. Both actions ask for confirmation and are written to the audit trail.

Settings & environments

Environment toggle — Sandbox uses Intuit's test company with your Development keys; Production uses live client books with your Production keys. Both key sets are stored side by side — the toggle chooses which set is active. Switching applies immediately, no redeploy.

Clients connected earlier keep working: each client remembers which environment it was connected under.

Keys — from developer.intuit.com → your app → Keys & credentials (Development and Production tabs). Secrets are encrypted before storage; leaving a secret field blank keeps the saved one.

Redirect URI — both key sets in the Intuit portal must list:
https://tools.lewispartners.ca/callback

Users

Super admin can change settings, manage users, and manage clients. Staff can onboard and view clients but cannot change settings or users.

Add someone from the Users panel with a temporary password, then use Edit on their row to change their name, email, role, or to set a new password for them (leave the password blank to keep the current one). Promoting a staff member to super admin is done the same way — Edit → Role → Super admin.

One safeguard: the last remaining super admin cannot be demoted, so the firm can never lock itself out. Promote a second super admin first if you need to change that role.

Everyone has a profile. Click your picture at the top right → My profile to change your own name, email, password (you must enter your current one), and profile picture. Pictures are cropped square and resized to 256px in your browser before saving. Sign out lives in that same menu.

Things Claude can do once connected

Reports (P&L, Balance Sheet, Trial Balance, GL, aging), querying any entity (invoices, customers, vendors, accounts…), and creating / updating / deleting records. Tip: tell Claude to always confirm before writing to the books — the connector has write access.

Staff accounts & what they can reach

Nobody is added by hand any more. On the Dashboard, Invite a user opens the Invitations page, where you enter a name and an email and choose a role. The person receives an email, picks their own password, and the account exists only once they do. The link lasts seven days and works once; you can revoke it before it is used.

Super admin reaches every client and every tool, and manages users and settings. Staff reaches only what you tick, and nothing is ticked to begin with.

Two things are chosen per staff member. Which clients — tick them one by one, or tick All clients to include any added later. What they may do — Read only covers querying, reports, single records and the company profile; Read + write adds create, update and delete. Under Advanced you can mix them, for instance allowing create and update but not delete.

These limits are enforced inside the connector, not merely hidden in the dashboard. A tool that is not granted never appears in Claude's tool list, a client that is not granted never appears in qbo_list_clients, and naming that client directly is refused rather than answered. Change any of it later from Access beside the person's name in the Users table; every change is written to the audit trail.

Two doors do not go through these limits, by design: a client's own connector key, and the master key. Both are firm-level credentials rather than personal ones — treat them accordingly.

Troubleshooting

A connector URL suddenly returns an error — if it has a long key in it, it is one of the withdrawn ones. Replace it in Claude with https://tools.lewispartners.ca/mcp and sign in.

"Your LP Tools account has not been given access to that client" — the person is signed in, but that client is not in their grant. A super admin can change it under Access beside their name in Users.

A tool is missing in Claude — tools that have not been granted are never offered. Check the same Access page.

"Tenant is not connected to QuickBooks yet" — the client was added but the Connect step wasn't finished. Open the Dashboard and click Connect QuickBooks.

Token / auth errors — reconnect the client (Connect link again). Errors include an intuit_tid you can quote to Intuit support. Full error logs: Cloudflare dashboard → Workers & Pages → lp-tools → Logs.

Locked out? — the emergency admin key still works: https://tools.lewispartners.ca/admin?key=<ADMIN_KEY>. It is traded once for a short-lived session and stripped from the address bar, and every use is recorded and emailed to the super admins.