Personal bookkeeper

NijemTech books, visible throughout

Settings

Connect read-only sources, then promote autonomy per action type as the track record earns it.

Disconnected qbo. The Intuit refresh token was revoked; last known books are held.
QuickBooks Online
Official Accounting API, OAuth2, scope com.intuit.quickbooks.accounting, used read-only. Production keys require Intuit’s app-assessment questionnaire — sandbox keys work for development without that step.

Status: mock app registered sandbox keys

Use the AiBooks Development keys, then a sandbox company

Open the AiBooks app (workspace Ai Integration, In Development). Copy Client ID and Secret from Keys → Development into /opt/aibooks/.env, add redirect URI https://aibooks.nijemtech.com/api/qbo/callback, recreate app and worker, then Connect. The consent screen must say AiBooks — if it still says Telegram, the VPS still has the old app’s keys. Development keys only list sandbox companies; create one at Intuit Developer → Sandbox. The live NijemTech company needs Production keys after the App Assessment.

  1. Create an app at developer.intuit.com and select the QuickBooks Online Accounting scope.
  2. Add redirect URI https://aibooks.nijemtech.com/api/qbo/callback
  3. Put Client ID / Secret in /opt/aibooks/.env. Sandbox first; production after assessment.
  4. Connect a sandbox company first. Switch to production keys before connecting NijemTech live.
Intuit production keys (verified)
Intuit still requires the App Assessment Questionnaire for production credentials — including this private, unlisted NijemTech app. There is no App Store listing review. Paste these URLs into the app’s Production → App details, then start the questionnaire under Production → Compliance.
Host domainaibooks.nijemtech.com

After approval, turn on Show Credentials, put the Production Client ID/Secret in /opt/aibooks/.env, set QBO_ENVIRONMENT=production, recreate app and worker, then Connect the NijemTech company.

Gmail
Read-only ingest of accountant and related threads. Send scope comes later with L3.

Status: mock using mock inbox

Redirect URI https://aibooks.nijemtech.com/api/gmail/callback. Google’s consent screen also needs the privacy policy.

Google Drive
Read statements and exports; store close packages locally until report-send is promoted. Same Google OAuth client as Gmail, with Drive scopes.

Status: mock using mock folder

Redirect URI https://aibooks.nijemtech.com/api/drive/callback

Google Cloud OAuth (Gmail + Drive)
One Web application client covers both connectors. Gmail readonly is a restricted scope — keep the consent screen in Testing and add tnijem@nijemtech.com as a test user so Connect works without a full Google verification. Same privacy policy URL as Intuit.

Scopes: gmail.readonly, drive.readonly, drive.file. Put Client ID/Secret in GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET in /opt/aibooks/.env, then recreate app and worker.

Per-type autonomy
L0 Observe · L1 Assist · L2 Auto-match · L3 Auto-send routine · L4 Supervised autonomy

Email draft

L0 Observe

Track record: 0 approved / 0 rejected of 4 proposed (0% agreement)

Email send

L0 Observe

Track record: 0 approved / 0 rejected of 4 proposed (0% agreement)

Report send

L0 Observe

Track record: 0 approved / 0 rejected of 1 proposed (0% agreement)

QuickBooks write

L0 Observe

Track record: 0 approved / 0 rejected of 9 proposed (0% agreement)

Categorize

L0 Observe

Track record: 0 approved / 0 rejected of 1 proposed (0% agreement)

Match

L0 Observe

Track record: 0 approved / 0 rejected of 9 proposed (0% agreement)