Personal bookkeeper

NijemTech books, visible throughout

Settings

Connect read-only sources, then promote autonomy per action type as the track record earns it.

missing-gmail-callback
QuickBooks Online
Official Accounting API, OAuth2, scope com.intuit.quickbooks.accounting, used read-only. The live NIJEMTech company (Guardian Bank, invoices 8327/8328, Tillman & Tillman) requires Production keys after Intuit’s App Assessment Questionnaire. Development keys only list sandbox companies.

Status: connected app registered sandbox keys

Live company Sandbox Company US 0f6c · realm 9341457917215601

Sandbox keys cannot open the live NijemTech company

The VPS is still on QBO_ENVIRONMENT=sandbox. Intuit will not list the production NIJEMTech company (the one sending invoices 8327/8328 and depositing to Guardian Bank). Put AiBooks Production Client ID/Secret in /opt/aibooks/.env, set QBO_ENVIRONMENT=production, add redirect https://aibooks.nijemtech.com/api/qbo/callback, recreate app and worker, then Connect. Consent must say AiBooks — if it still says Telegram, those are the old app’s Development keys.

  1. Create an app at developer.intuit.com and select the QuickBooks Online Accounting scope.
  2. Add redirect URI https://aibooks.nijemtech.com/api/qbo/callback
  3. Production keys only after the App Assessment. Put Client ID / Secret in /opt/aibooks/.env and set QBO_ENVIRONMENT=production.
  4. Connect and pick the live NIJEMTech company. Consent must say AiBooks.
Intuit production keys (verified)
Intuit still requires the App Assessment Questionnaire for production credentials — including this private, unlisted NijemTech app. There is no App Store listing review. Verified against Intuit’s FAQ and the 15 Sep 2026 confirmation to tnijem@nijemtech.com.

Questionnaire submitted 2026-09-15 — waiting on Intuit

Intuit Developer Relations confirmed the AiBooks assessment. Review is typically 5–10 business days (sometimes ~2 if nothing is missing). No App Store listing review. When Show Credentials appears under Production, put those Client ID/Secret in /opt/aibooks/.env, set QBO_ENVIRONMENT=production, recreate app and worker, then Connect the live NIJEMTech company. Development keys still cannot attach it.

Host domainaibooks.nijemtech.com

Keep these URLs on Production → App details. After approval, turn on Show Credentials, then Connect.

Gmail
Read-only ingest of Tillman & Tillman, QBO notifications, and bank/tax mail. Send scope comes later with L3.

Status: mock using mock inbox

Redirect URI https://aibooks.nijemtech.com/api/gmail/callback. Google’s consent screen also needs the privacy policy.

Google Drive
Read statements and exports; store close packages locally until report-send is promoted. Same Google OAuth client as Gmail, with Drive scopes.

Status: mock using mock folder

Redirect URI https://aibooks.nijemtech.com/api/drive/callback

Google Cloud OAuth (Gmail + Drive)
One Web application client covers both connectors. Gmail readonly is a restricted scope — keep the consent screen in Testing and add tnijem@nijemtech.com as a test user so Connect works without a full Google verification. Same privacy policy URL as Intuit.

Scopes: gmail.readonly, drive.readonly, drive.file. Put Client ID/Secret in GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET in /opt/aibooks/.env, then recreate app and worker.

Per-type autonomy
L0 Observe · L1 Assist · L2 Auto-match · L3 Auto-send routine · L4 Supervised autonomy

Email draft

L0 Observe

Track record: 0 approved / 0 rejected of 2 proposed (0% agreement)

Email send

L0 Observe

Track record: 0 approved / 0 rejected of 2 proposed (0% agreement)

Report send

L0 Observe

Track record: 0 approved / 0 rejected of 1 proposed (0% agreement)

QuickBooks write

L0 Observe

Track record: 0 approved / 0 rejected of 0 proposed

Categorize

L0 Observe

Track record: 0 approved / 0 rejected of 0 proposed

Match

L0 Observe

Track record: 0 approved / 0 rejected of 0 proposed