Skip to content
Desktop Accounting API

Rotate the signing secret

Try itPOST /v1/webhook-endpoints/{id}/rotate-secret

This request changes data. It runs for real against the QuickBooks Desktop company file of the end user you choose. Use a test key (sk_test_) and a test company file.

Generated for you. Resending with the same key replays the original result instead of writing twice; a new key is generated after each response unless the API says the request is safe to retry.
POST
/v1/webhook-endpoints/{id}/rotate-secret
curl --request POST \
--url https://api.desktopaccountingapi.com/v1/webhook-endpoints/whe_01j9x4m6v4c8k2t7q0r5s3w1zg/rotate-secret \
--header 'Authorization: Bearer <token>' \
--header 'Idempotency-Key: 6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10'

Creates a new signing secret and returns it once. For 24 hours deliveries carry two signatures (new and previous secret, space separated in webhook-signature), so you can deploy the new secret without dropping events.

id
required

Unique identifier for the webhook endpoint.

string
/^whe_[0-9a-hjkmnp-tv-z]{26}$/
Example
whe_01j9x4m6v4c8k2t7q0r5s3w1zg

Unique identifier for the webhook endpoint.

Idempotency-Key
string
>= 1 characters <= 255 characters /^[\x20-\x7e]+$/

Makes a write safe to retry. Repeating a key with the same request attaches to or replays the original instead of creating a second one. 1–255 printable ASCII characters, retained 7 days. Reusing a key with a different request returns 422 IDEMPOTENCY_KEY_REUSED.

Example
6f1c2a0e-1f7e-4c55-9a7a-0b2d2c9e3a10

The endpoint with its new secret.

Media typeapplication/json
object
id
required

Unique identifier for the webhook endpoint.

string
/^whe_[0-9a-hjkmnp-tv-z]{26}$/
objectType
required

Always webhook_endpoint.

string
Allowed values: webhook_endpoint
createdAt
required

When the endpoint was created. UTC, ISO 8601 with milliseconds.

string format: date-time
projectId
required

Unique identifier for the project.

string
/^proj_[0-9a-hjkmnp-tv-z]{26}$/
url
required

Where events are delivered.

string
description
required

Your note about the endpoint.

string | null
eventTypes
required

Subscribed event types.

Array<string>
Allowed values: request.succeeded request.failed request.canceled request.outcome_unknown request.outcome_resolved connection.setup_completed connection.status_changed
enabled
required

Whether events are delivered.

boolean
disabledReason
required

Why the endpoint was disabled automatically (5 days of failed deliveries), or null.

string | null
includeSyncRequests
required

Whether request events of synchronous calls whose caller received the result are delivered.

boolean
secretRotatedAt
required

When the signing secret was last rotated. UTC, ISO 8601.

string | null
previousSecretExpiresAt
required

Until when deliveries also carry a signature made with the previous secret. UTC, ISO 8601.

string | null
secret
required

Signing secret (whsec_..., Standard Webhooks format). Shown only when the endpoint is created and when the secret is rotated; store it securely.

string
Example
{
"id": "whe_01j9x4m6v4c8k2t7q0r5s3w1zg",
"objectType": "webhook_endpoint",
"createdAt": "2026-10-05T16:03:59.002Z",
"projectId": "proj_01j9x4m6v4c8k2t7q0r5s3w1zf",
"eventTypes": [
"request.succeeded"
],
"secret": "whsec_MfKQ9r8GKYqrTwjUPD8ILPZIo2LaLaSw"
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

The request is invalid. Codes: UNKNOWN_HEADER, INVALID_PARAMETER, IDEMPOTENCY_KEY_INVALID.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

The API key is missing or invalid. Codes: API_KEY_MISSING, API_KEY_INVALID.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

The operation is not permitted. Codes: API_KEY_READ_ONLY.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

The object does not exist in this project. Codes: RESOURCE_MISSING.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

The request is well formed but cannot be processed. Codes: IDEMPOTENCY_KEY_REUSED.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

Too many requests. Codes: RATE_LIMITED.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

Unexpected server error. Codes: INTERNAL_ERROR.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.

QuickBooks Desktop or the service is not available. Codes: SERVICE_UNAVAILABLE.

Media typeapplication/json
object
error
required
object
type
required

Error category. Use it to choose between retrying, fixing the request and asking the end user to act.

string
Allowed values: INVALID_REQUEST_ERROR AUTHENTICATION_ERROR PERMISSION_ERROR BILLING_ERROR RATE_LIMIT_ERROR INTEGRATION_CONNECTION_ERROR INTEGRATION_ERROR OUTCOME_UNKNOWN_ERROR INTERNAL_ERROR
code
required

Stable error code from the error catalog. New codes may be added; a code’s meaning never changes.

string
Allowed values: INVALID_JSON INVALID_PARAMETER UNKNOWN_PARAMETER UNKNOWN_HEADER DECIMAL_PRECISION_EXCEEDED STRING_TOO_LONG UNSUPPORTED_CHARACTER FIELD_NOT_CLEARABLE END_USER_ID_MISSING PAYLOAD_TOO_LARGE IDEMPOTENCY_KEY_INVALID IDEMPOTENCY_KEY_REUSED CURSOR_INVALID CURSOR_PARAMS_MISMATCH CURSOR_EXPIRED RESOURCE_MISSING REQUEST_NOT_CANCELABLE PASSTHROUGH_INVALID_QBXML QBD_FIELD_UNSUPPORTED_BY_VERSION QBD_REGION_UNSUPPORTED API_KEY_MISSING API_KEY_INVALID PUBLISHABLE_KEY_INVALID PUBLISHABLE_KEY_PROJECT_MISMATCH TEST_COMPANY_FILE_LIMIT_REACHED API_KEY_READ_ONLY PERMISSION_DENIED BILLING_REQUIRED PAYMENT_FAILED RATE_LIMITED CONNECTION_QUEUE_FULL WEBHOOK_ENDPOINT_LIMIT_REACHED INTEGRATION_CONNECTION_NOT_SET_UP INTEGRATION_CONNECTION_NOT_ACTIVE INTEGRATION_CONNECTION_DISABLED QBD_CONNECTION_ERROR QBD_CANNOT_START QBD_STARTING QBD_MODAL_DIALOG_OPEN QBD_QUICKBOOKS_NOT_RESPONDING QBD_WRONG_COMPANY_FILE_OPEN QBD_COMPANY_FILE_MISMATCH QBD_COMPANY_FILE_NOT_FOUND QBD_FILE_MODE_CONFLICT QBD_ADMIN_REQUIRED QBD_ACCESS_NOT_GRANTED QBD_VERSION_UNSUPPORTED QBD_REQUEST_ERROR QBD_OBJECT_NOT_FOUND QBD_REFERENCE_NOT_FOUND QBD_DUPLICATE_NAME QBD_REVISION_NUMBER_STALE QBD_OBJECT_IN_USE QBD_FEATURE_NOT_ENABLED QBD_INSUFFICIENT_PERMISSION QBD_RESPONSE_TOO_LARGE QBD_OPERATION_UNSUPPORTED QBD_RESPONSE_UNREADABLE REQUEST_TIMEOUT_NOT_SENT REQUEST_EXPIRED REQUEST_CANCELED QBD_REQUEST_TIMEOUT QBD_WRITE_OUTCOME_UNKNOWN QBD_READ_INTERRUPTED INTERNAL_ERROR SERVICE_UNAVAILABLE
message
required

Developer-facing explanation. May include IDs and field paths; never includes secrets.

string
userFacingMessage
required

A message that is safe to show to the end user.

string
httpStatusCode
required

HTTP status of the response. null for codes that appear only on a request resource (REQUEST_EXPIRED, REQUEST_CANCELED).

integer | null
integrationCode
required

Native QuickBooks code when one exists: a qbXML statusCode ("3200"), an HRESULT ("0x80040414") or a Web Connector code.

string | null
requestId
required

The Daapi-Request-Id of this response. Include it when contacting support.

string
cause
required

Why this error happens.

string
fixes
required

Ordered actions that resolve the error, each with the responsible actor.

Array<object>
object
actor
required

Who can apply the fix.

string
Allowed values: developer end_user support
action
required

What to do.

string
docsUrl
required

Documentation section for this code.

string format: uri
retryable
required

Repeating the identical request (with the same Idempotency-Key for writes) can succeed without changes. Also sent as the Daapi-Should-Retry header.

boolean
outcome
required

Whether a write took effect: applied (QuickBooks confirmed it), not_applied (it certainly did not happen), pending (sent, still processing), unknown (sent, result could not be confirmed) or not_applicable (a read).

string
Allowed values: applied not_applied pending unknown not_applicable
param
required

Request field, query parameter or header the error refers to, when known.

string | null
details
required

Code-specific details, documented per code in the error catalog.

object
key
additional properties
Example
{
"error": {
"type": "INVALID_REQUEST_ERROR",
"code": "INVALID_JSON",
"httpStatusCode": 503,
"integrationCode": "0x80040414",
"requestId": "req_01j9x4m6v4c8k2t7q0r5s3w1zd",
"fixes": [
{
"actor": "developer"
}
],
"docsUrl": "https://www.desktopaccountingapi.com/docs/errors/#qbd_modal_dialog_open",
"outcome": "applied",
"param": "companyName"
}
}
Daapi-Request-Id
string

Unique ID of this API call (req_...). Present on every response.

RateLimit-Limit
integer

Requests allowed per window for the project (all keys together).

RateLimit-Remaining
integer

Requests left in the current window, as counted by the edge location that served this call.

RateLimit-Reset
integer

Seconds until the current window resets.

Daapi-Should-Retry
string
Allowed values: true false

true when repeating the identical request can succeed. SDKs follow it instead of status-code heuristics.

Retry-After
integer

Seconds to wait before retrying, on 429 and on retryable 503 responses when a wait is known.