Create a webhook endpoint
Try itPOST /v1/webhook-endpoints
This request changes data. It runs for real against the QuickBooks Desktop company file of the end user you choose. Use a test key (sk_test_) and a test company file.
const url = 'https://api.desktopaccountingapi.com/v1/webhook-endpoints';const options = { method: 'POST', headers: { 'Idempotency-Key': '6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10', Authorization: 'Bearer <token>', 'Content-Type': 'application/json' }, body: '{"url":"https://example.com/webhooks/desktop-accounting","eventTypes":["request.succeeded"],"description":"Production sync worker","enabled":true,"includeSyncRequests":false}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.desktopaccountingapi.com/v1/webhook-endpoints \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --header 'Idempotency-Key: 6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10' \ --data '{ "url": "https://example.com/webhooks/desktop-accounting", "eventTypes": [ "request.succeeded" ], "description": "Production sync worker", "enabled": true, "includeSyncRequests": false }'Registers an HTTPS endpoint for events of this project. The response contains the signing secret once. Deliveries are signed with the Standard Webhooks scheme (webhook-id, webhook-timestamp, webhook-signature), retried on failure for about 27 hours (after 5 s, 5 min, 30 min, 2 h, 5 h, 10 h and 10 h) and recorded in the delivery log. A project can have up to 20 endpoints.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”Makes a write safe to retry. Repeating a key with the same request attaches to or replays the original instead of creating a second one. 1–255 printable ASCII characters, retained 7 days. Reusing a key with a different request returns 422 IDEMPOTENCY_KEY_REUSED.
Example
6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10Request Bodyrequired
Section titled “Request Bodyrequired”object
HTTPS URL on a public DNS name and the default port. IP addresses, internal names and redirects are not allowed.
Example
https://example.com/webhooks/desktop-accountingEvent types to deliver. At least one.
Your note about the endpoint, up to 500 characters.
Example
Production sync workerDeliver events. Default true.
Also deliver request events for synchronous calls whose caller already received the result. Default false: synchronous requests produce events only when the caller did not get the final result (timeout after sending, disconnect) or the outcome is unknown.
Responses
Section titled “Responses”The created endpoint with its signing secret.
object
Unique identifier for the webhook endpoint.
Always webhook_endpoint.
When the endpoint was created. UTC, ISO 8601 with milliseconds.
Unique identifier for the project.
Where events are delivered.
Your note about the endpoint.
Subscribed event types.
Whether events are delivered.
Why the endpoint was disabled automatically (5 days of failed deliveries), or null.
Whether request events of synchronous calls whose caller received the result are delivered.
When the signing secret was last rotated. UTC, ISO 8601.
Until when deliveries also carry a signature made with the previous secret. UTC, ISO 8601.
Signing secret (whsec_..., Standard Webhooks format). Shown only when the endpoint is created and when the secret is rotated; store it securely.
Example
{ "id": "whe_01j9x4m6v4c8k2t7q0r5s3w1zg", "objectType": "webhook_endpoint", "createdAt": "2026-10-05T16:03:59.002Z", "projectId": "proj_01j9x4m6v4c8k2t7q0r5s3w1zf", "eventTypes": [ "request.succeeded" ], "secret": "whsec_MfKQ9r8GKYqrTwjUPD8ILPZIo2LaLaSw"}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
The request is invalid. Codes: UNKNOWN_HEADER, INVALID_JSON, INVALID_PARAMETER, UNKNOWN_PARAMETER, IDEMPOTENCY_KEY_INVALID.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
The API key is missing or invalid. Codes: API_KEY_MISSING, API_KEY_INVALID.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
The operation is not permitted. Codes: API_KEY_READ_ONLY.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
The request is well formed but cannot be processed. Codes: IDEMPOTENCY_KEY_REUSED, WEBHOOK_ENDPOINT_LIMIT_REACHED.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
Too many requests. Codes: RATE_LIMITED.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
Unexpected server error. Codes: INTERNAL_ERROR.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.
QuickBooks Desktop or the service is not available. Codes: SERVICE_UNAVAILABLE.
object
object
Error category. Use it to choose between retrying, fixing the request and asking the end user to act.
Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.
Developer-facing explanation. May include IDs and field paths; never includes secrets.
A message that is safe to show to the end user.
HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).
Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.
The Daapi-Request-Id of this response. Include it when contacting support.
Why this error happens.
Ordered actions that resolve the error, each with the responsible actor.
object
Who can apply the fix.
What to do.
Documentation section for this code.
Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.
Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).
Request field, query parameter or header the error refers to, when known.
Code-specific details, documented per code in the error catalog.
object
Example
{ "error": { "type": "INVALID_REQUEST_ERROR", "code": "INVALID_JSON", "httpStatusCode": 503, "integrationCode": "0x80040414", "requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd", "fixes": [ { "actor": "developer" } ], "docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open", "outcome": "applied", "param": "companyName" }}Headers
Section titled “Headers”Unique ID of this API call (req_...). Present on every response.
Requests allowed per window for the project (all keys together).
Requests left in the current window, as counted by the edge location that served this call.
Seconds until the current window resets.
true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.
Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.