# Make cards from QuickBooks or Xero events

1. Connect a QuickBooks or Xero preset and attach it to a board.
2. Call `manage_connection_webhook` with action `create` and its `connection_id`. The result gives `receive_url` and `secret_link`; it contains no signing secret. The webhook starts paused.
3. A person opens `secret_link` in the BakedBrie web app, pastes the provider's signing secret and sets the daily card cap. The person registers `receive_url` in the provider's developer portal. For Xero, click **Validate 'Intent to receive'** there.
4. Call `manage_connection_webhook` with action `add_rule`, the board attachment, event entity and operations, destination column and optional title and brief templates. Templates may use only `{{event.entity}}`, `{{event.id}}` and `{{event.operation}}`. Rules made through MCP are read-only; only a person in the web app may let event cards change records.
5. After the person has saved the signing secret and the rule exists, call `manage_connection_webhook` with action `resume` and the `connection_webhook_id`. The webhook stays paused until this step. A person can also resume it in the web app.

BakedBrie verifies the raw payload signature before reading it, drops repeats and events more than 72 hours old, and stops cards at the person-set daily cap. An invalid signature returns HTTP 401 `WEBHOOK_SIGNATURE_INVALID`; BakedBrie stores no event and makes no card. Xero can replay saved events after a long outage; those older than 72 hours are dropped. Pause a webhook or rule through MCP at any time. Source: [Intuit webhooks](https://developer.intuit.com/app/developer/qbo/docs/develop/webhooks/configure-webhooks), [Xero webhooks](https://developer.xero.com/documentation/guides/webhooks/overview), read 2026-09-29.
