Sample code for 30+ languages & platforms
Node.js

Quickbooks OAuth1 Authorization (3-legged)

See more QuickBooks Examples

Demonstrates 3-legged OAuth1 authorization for Quickbooks.

Chilkat Node.js Downloads

Node.js
NODEJS_PRELUDE

function chilkatExample() {

    var success = false;

    var consumerKey = "QUICKBOOKS_CONSUMER_KEY";
    var consumerSecret = "QUICKBOOKS_CONSUMER_SECRET";

    var requestTokenUrl = "https://oauth.intuit.com/oauth/v1/get_request_token";
    var authorizeUrl = "https://appcenter.intuit.com/Connect/Begin";
    var accessTokenUrl = "https://oauth.intuit.com/oauth/v1/get_access_token";

    //  The port number is picked at random. It's some unused port that won't likely conflict with anything else..
    var callbackUrl = "http://localhost:3017/";
    var callbackLocalPort = 3017;

    //  The 1st step in 3-legged OAuth1.0a is to send a POST to the request token URL to obtain an OAuth Request Token
    var http = new chilkat.Http();

    http.OAuth1 = true;
    http.OAuthConsumerKey = consumerKey;
    http.OAuthConsumerSecret = consumerSecret;
    http.OAuthCallback = callbackUrl;

    var req = new chilkat.HttpRequest();
    req.HttpVerb = "POST";
    req.ContentType = "application/x-www-form-urlencoded";

    var resp = new chilkat.HttpResponse();
    success = http.HttpReq(requestTokenUrl,req,resp);
    if (success == false) {
        console.log(http.LastErrorText);
        return;
    }

    if (resp.StatusCode >= 400) {
        console.log("Error response status code = " + resp.StatusCode);
        console.log(resp.BodyStr);
        return;
    }

    //  If successful, the resp.BodyStr contains this:  
    //  oauth_token=-Wa_KwAAAAAAxfEPAAABV8Qar4Q&oauth_token_secret=OfHY4tZBX2HK4f7yIw76WYdvnl99MVGB&oauth_callback_confirmed=true
    console.log(resp.BodyStr);

    var hashTab1 = new chilkat.Hashtable();
    hashTab1.AddQueryParams(resp.BodyStr);

    var requestToken = hashTab1.LookupStr("oauth_token");
    var requestTokenSecret = hashTab1.LookupStr("oauth_token_secret");
    http.OAuthTokenSecret = requestTokenSecret;

    console.log("oauth_token = " + requestToken);
    console.log("oauth_token_secret = " + requestTokenSecret);

    //  ---------------------------------------------------------------------------
    //  The next step is to form a URL to send to the AuthorizeUrl
    //  This is an HTTP GET that we load into a popup browser.
    var sbUrlForBrowser = new chilkat.StringBuilder();
    sbUrlForBrowser.Append(authorizeUrl);
    sbUrlForBrowser.Append("?oauth_token=");
    sbUrlForBrowser.Append(requestToken);
    var url = sbUrlForBrowser.GetAsString();

    //  When the urlForBrowser is loaded into a browser, the response from Quickbooks will redirect back to localhost:3017
    //  We'll need to start a socket that is listening on port 3017 for the callback from the browser.
    var listenSock = new chilkat.Socket();

    var backLog = 5;
    success = listenSock.BindAndListen(callbackLocalPort,backLog);
    if (success == false) {
        console.log(listenSock.LastErrorText);
        return;
    }

    //  Wait for the browser's connection in a background thread.
    //  (We'll send load the URL into the browser following this..)
    //  Wait a max of 60 seconds before giving up.
    var sock = new chilkat.Socket();
    var maxWaitMs = 60000;
    // task: Task
    var task = listenSock.AcceptNextAsync(maxWaitMs,sock);
    task.Run();

    //  Launch the system's default browser navigated to the URL.
    var oauth2 = new chilkat.OAuth2();
    success = oauth2.LaunchBrowser(url);
    if (success == false) {
        console.log(oauth2.LastErrorText);
        return;
    }

    //  Wait for the listenSock's task to complete.
    success = task.Wait(maxWaitMs);
    if (!success || (task.StatusInt !== 7) || (task.TaskSuccess !== true)) {
        if (!success) {
            //  The task.LastErrorText applies to the Wait method call.
            console.log(task.LastErrorText);
        }
        else {
            //  The ResultErrorText applies to the underlying task method call (i.e. the AcceptNextConnection)
            console.log(task.Status);
            console.log(task.ResultErrorText);
        }

        return;
    }

    //  If we get to this point, the connection from the browser arrived and was accepted.

    //  We no longer need the listen socket...
    //  Close it so that it's no longer listening on port 3017.
    listenSock.Close(10);

    //  Read the start line of the request..
    var startLine = sock.ReceiveUntilMatch("\r\n");
    if (sock.LastMethodSuccess == false) {
        console.log(sock.LastErrorText);
        return;
    }

    //  Read the request header.
    var requestHeader = sock.ReceiveUntilMatch("\r\n\r\n");
    if (sock.LastMethodSuccess == false) {
        console.log(sock.LastErrorText);
        return;
    }

    //  The browser SHOULD be sending us a GET request, and therefore there is no body to the request.
    //  Once the request header is received, we have all of it.
    //  We can now send our HTTP response.
    var sbResponseHtml = new chilkat.StringBuilder();
    sbResponseHtml.Append("<html><body><p>Chilkat thanks you!</b></body</html>");

    var sbResponse = new chilkat.StringBuilder();
    sbResponse.Append("HTTP/1.1 200 OK\r\n");
    sbResponse.Append("Content-Length: ");
    sbResponse.AppendInt(sbResponseHtml.Length);
    sbResponse.Append("\r\n");
    sbResponse.Append("Content-Type: text/html\r\n");
    sbResponse.Append("\r\n");
    sbResponse.AppendSb(sbResponseHtml);

    sock.SendString(sbResponse.GetAsString());
    sock.Close(50);

    //  The information we need is in the startLine.
    //  For example, the startLine will look like this:
    //   GET /?oauth_token=abcdRQAAZZAAxfBBAAABVabcd_k&oauth_verifier=9rdOq5abcdCe6cn8M3jabcdj3Eabcd HTTP/1.1
    var sbStartLine = new chilkat.StringBuilder();
    sbStartLine.Append(startLine);
    var numReplacements = sbStartLine.Replace("GET /?","");
    numReplacements = sbStartLine.Replace(" HTTP/1.1","");
    sbStartLine.Trim();

    //  oauth_token=qyprdP04IrTDIXtP1HRZz0geQdjXHVlGDxXPexlXZsjZNRcY&oauth_verifier=arx5pj5&realmId=193514465596199&dataSource=QBO
    console.log("startline: " + sbStartLine.GetAsString());

    hashTab1.Clear();
    hashTab1.AddQueryParams(sbStartLine.GetAsString());

    requestToken = hashTab1.LookupStr("oauth_token");
    var authVerifier = hashTab1.LookupStr("oauth_verifier");

    //  ------------------------------------------------------------------------------
    //  Finally , we must exchange the OAuth Request Token for an OAuth Access Token.

    http.OAuthToken = requestToken;
    http.OAuthVerifier = authVerifier;

    req.HttpVerb = "POST";
    req.ContentType = "application/x-www-form-urlencoded";

    success = http.HttpReq(accessTokenUrl,req,resp);
    if (success == false) {
        console.log(http.LastErrorText);
        return;
    }

    //  Make sure a successful response was received.
    if (resp.StatusCode !== 200) {
        console.log(resp.StatusLine);
        console.log(resp.Header);
        console.log(resp.BodyStr);
        return;
    }

    //  If successful, the resp.BodyStr contains something like this:
    //  oauth_token=12347455-ffffrrlaBdCjbdGfyjZabcdb5APNtuTPNabcdEpp&oauth_token_secret=RxxxxJ8mTzUhwES4xxxxuJyFWDN8ZfHmrabcddh88LmWE
    console.log(resp.BodyStr);

    var hashTab2 = new chilkat.Hashtable();
    hashTab2.AddQueryParams(resp.BodyStr);

    var accessToken = hashTab2.LookupStr("oauth_token");
    var accessTokenSecret = hashTab2.LookupStr("oauth_token_secret");

    //  The access token + secret is what should be saved and used for
    //  subsequent REST API calls.
    console.log("Access Token = " + accessToken);
    console.log("Access Token Secret = " + accessTokenSecret);

    //  Save this access token for future calls.
    var json = new chilkat.JsonObject();
    json.AppendString("oauth_token",accessToken);
    json.AppendString("oauth_token_secret",accessTokenSecret);

    //  Also save the realmId and dataSource from hashTab1.
    var realmId = hashTab1.LookupStr("realmId");
    console.log("realmId = " + realmId);
    var dataSource = hashTab1.LookupStr("dataSource");
    console.log("dataSource = " + dataSource);

    json.AppendString("realmId",realmId);
    json.AppendString("dataSource",dataSource);

    var fac = new chilkat.FileAccess();
    fac.WriteEntireTextFile("qa_data/tokens/quickbooks.json",json.Emit(),"utf-8",false);

    console.log("Success.");

}

chilkatExample();