Connect anything to OneBooks.
A standards-based OAuth 2.0 API with scoped tokens and webhooks, plus MCP for AI agents — the foundation of the OneBooks developer platform. Sync your system or build an agent here, then go further with apps that run inside OneBooks and a listing in the marketplace.
OAuth 2.0 + PKCE
authorization code, refresh rotation, dynamic registration, device flow
Scoped tokens
read and write scopes per domain — invoices, payments, reports…
Every plan
API and MCP access on every OneBooks plan, Free included
From console to customers.
Register your app
Create it in the developer console and build against free sandbox businesses.
Build
Standard OAuth 2.0 with PKCE and scopes; documented endpoints for documents, payments and reports; webhooks for what changes; MCP if you're building an agent.
Go live
Pass app review and your app can connect to any OneBooks business. To be found in the marketplace, submit a listing for its own review.
Standards, not surprises.
If you've integrated with any modern OAuth provider, you already know how this works.
- ✓ OAuth 2.0 — authorization code with PKCE, refresh-token rotation, RFC 7591 dynamic registration, RFC 8628 device flow for native apps, RFC 8414 / 9728 discovery.
- ✓ Scopes per domain — invoices, payments, purchases, reports and more, read or write, consented per business.
- ✓ Idempotency everywhere — every financial write accepts an idempotency key, so retries are safe.
- ✓ Webhooks and an Events API — signed deliveries with retries for 40+ events, plus an event log you can catch up from.
- ✓ Dated API versions — pin the version you built against; each one stays supported for 12 months after the next arrives.
- ✓ MCP for agents — the same authorization surface exposes typed tools for AI agents, with human-confirmed writes.
Go beyond the API.
The API is one part of the OneBooks developer platform. When an integration isn't enough, build an app that merchants use inside OneBooks.
- ✓ Apps inside OneBooks — your own pages, actions in a record's Apps menu, and cards on records and the dashboard, in a sandboxed frame with short-lived session tokens.
- ✓ App data on records — your own typed fields on invoices, customers, items and nine more kinds of record.
- ✓ Hosted functions — your code runs on events in an isolated sandbox that can reach only the hosts you declare.
- ✓ The App Marketplace — pass listing review and every OneBooks business can find and install your app; you bill your customers directly and keep 100% of what you charge.
- ✓ Sandbox businesses — build and test without touching real books.
OneBooks API — common questions
What auth does the API use?
OAuth 2.0 — authorization code with PKCE for apps, dynamic client registration for self-service clients, the device flow for native apps without a redirect, and refresh-token rotation throughout.
Is there a sandbox?
Yes — the developer console provisions sandbox businesses so you can build and test against realistic books without touching a customer's data.
Which OneBooks plans can connect my app?
All of them. API and MCP access is included on every plan, including Free, so any OneBooks business can connect your app.
Do I need a marketplace listing?
No. App review is what lets your app connect to real businesses. A marketplace listing is optional, and it has its own review before it's published.
Can I build an AI agent on it?
Yes — OneBooks exposes an MCP server on the same OAuth surface, with typed tools, scoped access and human-confirmed writes.
Can my customers get OneBooks at no cost?
Through our partner program, POS and platform vendors can give their verified customers the OneBooks Standard plan at no cost. Tell us about your product on the Partner with us page.
Build the integration your customers are asking for.
Create a free developer account, build against a sandbox, and go live after a single review.