Automate QBO refresh token rotation #3

Closed
opened 2026-04-12 03:53:59 +00:00 by amoussa1229 · 1 comment
amoussa1229 commented 2026-04-12 03:53:59 +00:00 (Migrated from github.com)

QuickBooks Online refresh tokens expire after 100 days of inactivity. The current token is stored in seahaven/qbo/oauth in Secrets Manager and must be rotated before expiry to avoid breaking vendor lookups.

Current behavior: Manual rotation via the Intuit OAuth Playground — update refreshToken in the secret.

Desired behavior: Automated rotation via a scheduled Lambda or EventBridge rule.

Suggested approach:

  • Add a Lambda that calls the QBO token refresh endpoint and updates the Secrets Manager secret
  • Schedule it via EventBridge to run every 60–80 days
  • Send a Slack alert if rotation fails

Risk: If the token expires, all vendor QBO lookups will fail silently (the agent will fall through to Google Maps without finding existing vendors).

QuickBooks Online refresh tokens expire after **100 days of inactivity**. The current token is stored in `seahaven/qbo/oauth` in Secrets Manager and must be rotated before expiry to avoid breaking vendor lookups. **Current behavior:** Manual rotation via the [Intuit OAuth Playground](https://developer.intuit.com/app/developer/playground) — update `refreshToken` in the secret. **Desired behavior:** Automated rotation via a scheduled Lambda or EventBridge rule. **Suggested approach:** - Add a Lambda that calls the QBO token refresh endpoint and updates the Secrets Manager secret - Schedule it via EventBridge to run every 60–80 days - Send a Slack alert if rotation fails **Risk:** If the token expires, all vendor QBO lookups will fail silently (the agent will fall through to Google Maps without finding existing vendors).
amoussa1229 commented 2026-04-14 00:26:42 +00:00 (Migrated from github.com)

Resolved across several commits:

  • acfe818 — Add QBO OAuth endpoints (/qbo/connect, /qbo/callback, /qbo/disconnect, /qbo/launch) for full automated OAuth 2.0 flow
  • 266fe83 — Fix Intuit security compliance (CSRF validation, Cache-Control headers, safe logging)
  • 066ff59 — Place QBO Lambdas in VPC for static outbound IP (Intuit allowlist)
  • 9463a07 — Use Intuit discovery document for OAuth endpoints
  • d1b91ae — Read OAuth client credentials from Secrets Manager at runtime

What changed:

  • The qbo-lookup Lambda now persists the rotated refresh token back to Secrets Manager after every API call, so the token auto-renews and never expires from inactivity.
  • Full OAuth 2.0 flow via bot.seahaven.com/qbo/connect eliminates the need for the Intuit OAuth Playground entirely. If the token ever does expire, reconnecting is a single click.
  • No scheduled Lambda needed — rotation happens inline on every vendor query.
Resolved across several commits: - [`acfe818`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/commit/acfe818) — Add QBO OAuth endpoints (`/qbo/connect`, `/qbo/callback`, `/qbo/disconnect`, `/qbo/launch`) for full automated OAuth 2.0 flow - [`266fe83`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/commit/266fe83) — Fix Intuit security compliance (CSRF validation, Cache-Control headers, safe logging) - [`066ff59`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/commit/066ff59) — Place QBO Lambdas in VPC for static outbound IP (Intuit allowlist) - [`9463a07`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/commit/9463a07) — Use Intuit discovery document for OAuth endpoints - [`d1b91ae`](https://github.com/Sea-Haven-Industries/seahaven-slack-bot/commit/d1b91ae) — Read OAuth client credentials from Secrets Manager at runtime **What changed:** - The `qbo-lookup` Lambda now persists the rotated refresh token back to Secrets Manager after every API call, so the token auto-renews and never expires from inactivity. - Full OAuth 2.0 flow via `bot.seahaven.com/qbo/connect` eliminates the need for the Intuit OAuth Playground entirely. If the token ever does expire, reconnecting is a single click. - No scheduled Lambda needed — rotation happens inline on every vendor query.
This repo is archived. You cannot comment on issues.
No description provided.