Skip to content

OAuth redirect target for Xero/QuickBooks Online consent screens (public; authenticated by the signed state parameter, not a session)

GET
/erp-connections/oauth/callback
curl --request GET \
--url https://api.invogi.com/v1/erp-connections/oauth/callback \
--header 'Authorization: Bearer <token>'

Not called by API clients or apps/app directly — the provider’s own consent screen redirects the browser here. No Clerk session exists on this request; state (opaque, signed, short-lived) is the entire trust boundary. On success, redirects the browser to apps/app’s integrations page.

code
string

Absent when the user declined consent

state
string
error
string

Provider error such as access_denied

realmId
string

QuickBooks Online only — Intuit appends this alongside code/state; captures which QBO company (realm) was authorized

Always redirects to the apps/app integrations page, with erp_connected=<provider> on success or a stable erp_error code on failure