Automate QBO refresh token rotation #3
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#3
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
QuickBooks Online refresh tokens expire after 100 days of inactivity. The current token is stored in
seahaven/qbo/oauthin Secrets Manager and must be rotated before expiry to avoid breaking vendor lookups.Current behavior: Manual rotation via the Intuit OAuth Playground — update
refreshTokenin the secret.Desired behavior: Automated rotation via a scheduled Lambda or EventBridge rule.
Suggested approach:
Risk: If the token expires, all vendor QBO lookups will fail silently (the agent will fall through to Google Maps without finding existing vendors).
Resolved across several commits:
acfe818— Add QBO OAuth endpoints (/qbo/connect,/qbo/callback,/qbo/disconnect,/qbo/launch) for full automated OAuth 2.0 flow266fe83— Fix Intuit security compliance (CSRF validation, Cache-Control headers, safe logging)066ff59— Place QBO Lambdas in VPC for static outbound IP (Intuit allowlist)9463a07— Use Intuit discovery document for OAuth endpointsd1b91ae— Read OAuth client credentials from Secrets Manager at runtimeWhat changed:
qbo-lookupLambda now persists the rotated refresh token back to Secrets Manager after every API call, so the token auto-renews and never expires from inactivity.bot.seahaven.com/qbo/connecteliminates the need for the Intuit OAuth Playground entirely. If the token ever does expire, reconnecting is a single click.