Foes Conduit

Connect or reconnect a QuickBooks company

Conduit connections are issued by Foes to clients with an active engagement. There is no self-serve signup and no public authorization link, because a connection only means something once a destination warehouse exists to sync into.

How to start

Write to hello@foes.co from an address at your organization, and say which QuickBooks Online company you want connected. If you are an existing client, name the engagement. If you are not yet a client, that message starts a scoping conversation rather than a connection.

What happens next

  1. Foes confirms the destination: the Supabase project or Azure database your organization owns, which is where your data will land. If that does not exist yet, it gets set up first, in an account belonging to you.
  2. Foes sends you a one-time authorization link for the Foes Conduit app. The link takes you to Intuit's own sign-in and consent screen, on an Intuit domain.
  3. A user with admin rights on the QuickBooks company signs in there and grants read access to accounting data. You are shown exactly what is being requested before you approve it.
  4. Intuit returns an authorization code to Conduit's registered redirect route, and the browser lands on a confirmation page. A Foes operator completes the token exchange from the runner, because the app's client secret lives in Foes' 1Password vault and is never deployed to the web tier. The resulting refresh token goes back into that vault rather than into any application database, and the company identifier is recorded.
  5. Foes runs an initial backfill, checks the landed record counts against QuickBooks, and confirms with you before the recurring schedule starts.

Foes will never ask for your QuickBooks username or password. The only thing you ever type your Intuit credentials into is Intuit's own sign-in page. If anyone claiming to be from Foes asks for those credentials, or asks you to install software to connect QuickBooks, refuse and write to hello@foes.co.

Reconnecting

The same route handles reconnection. You will need it if the authorization was revoked from inside QuickBooks, if the refresh token expired because the connection sat unused past Intuit's limit, if the admin who originally granted access left and the grant lapsed with their account, or if you moved to a different QuickBooks company file. Foes usually notices first, because a failing run is logged and reviewed, and will contact you with a fresh authorization link. You do not need to undo anything before reconnecting.

What access is granted

Read access to accounting data on the QuickBooks company you authorize, and nothing else. Conduit does not request payroll or payments scopes, does not request write scopes, and cannot create, edit or delete anything in your books. One grant covers one company. Connecting a second company is a separate authorization that you approve separately. The privacy policy lists the record types Conduit reads and what it does with them.

Ending the connection

You can revoke access yourself at any time from inside QuickBooks, without asking Foes first. See disconnecting.