What an integration asks for before you connect it
A walk through the QuickBooks Online, IT Glue, Pax8 and AI provider pages exactly as they look before anything is connected, so you know what each one asks for and what its Connect or import door does first.
What you will have
- What the Connect to QuickBooks button actually does, and what to set up before your first invoice pushes cleanly
- What the Documentation tab's import model is, in general, before picking a provider
- How IT Glue's account-wide password export door works, including 2FA seeds, re-imports and a failed upload
- What the AI tab does (and does not) let you configure
- What Pax8's Invoice grouping setting decides once subscriptions start syncing
Why it works this way
None of these steps click Connect, Save, Test, or Upload and process - every page in this walkthrough is left exactly as it was found, so you can read what a door asks before you walk through it.
IT Glue's password-export card and Pax8's pricing card both render fully before the integration is ever connected - a file import and a billing setting, not the vendor API credentials, so neither one is gated behind Not Configured the way the Sync health card on the same pages is.
Steps
Open Integrations, then Billing.
The Billing tab filters the marketplace to accounting and billing platforms: Pax8, QuickBooks Online, and Stripe. All three read Not Configured on an instance with nothing connected yet.
Open Integrations, then Billing. Click the QuickBooks Online card to open its detail page, then find Connect to QuickBooks.
Connect to QuickBooks starts an OAuth sign-in with Intuit, QuickBooks' own login, never a password typed into the portal. Signing in with an account that has access to more than one company brings up Intuit's own company picker; whichever company gets picked becomes the one this connection pushes invoices to and pulls payments from for good, since there's no in-portal company switcher afterward - reconnecting from scratch is the only way to point it at a different company later.
Click the QuickBooks Online card to open its detail page, then find Connect to QuickBooks. Note the Product catalog card on the same page.
Two things are worth doing before that first invoice push: curate this Product Catalog so billed line items map to real QuickBooks items, and match each portal client to its QuickBooks customer record from Integrations, then Matching. An unmatched client's invoice fails to push instead of silently landing on the wrong customer. An active QuickBooks Online subscription is required - QuickBooks Desktop isn't supported - along with an admin-level login on that company.
Note the Product catalog card on the same page. Back on Integrations, open the Documentation tab and find IT Glue.
Documentation platforms all follow the same shape: enter an API key on the provider's own card, then pull articles, passwords, procedures and assets into the portal from Clients, then a client, then Documentation, then Imports. Re-running an import is idempotent - existing entries are matched and updated by their external id, so a re-pull updates the same records instead of duplicating them.
Back on Integrations, open the Documentation tab and find IT Glue. Click into IT Glue and find Import password export.
This is a separate door from the API credentials above it, and it works whether or not IT Glue is ever connected as an API integration: it imports the vendor's account-wide password export, one file covering every client, in a single pass. Upload the vendor's export zip directly (with its password) or an already-extracted passwords.csv. TOTP (2FA) seeds import too, which the API sync can never deliver on its own - the card above this one explains why, and points here as the canonical way to bring them in.
Click into IT Glue and find Import password export. Read the Link your clients before importing notice before choosing a file.
Every row in the export is routed to a client through your organization links; anything belonging to an unlinked or ambiguously-linked organization is skipped, never imported. Once a file uploads, a routing preview lists exactly which organizations are unlinked and how many rows each one would lose, before anything is confirmed - Review client links jumps to the Matching page to fix that first.
Warning: This walkthrough never chooses a file or clicks Upload and process - that would write real password entries into a client's vault.Read the Link your clients before importing notice before choosing a file. Know what happens on a second import of the same export.
Each row is stamped with its source record id, so importing the same export twice updates the same vault entries instead of creating duplicates - the periodic API sync recognizes the same stamp too, so both stay converged. A technician's deletion stays deleted; the import never resurrects a row a person removed. Archived rows in the export are always skipped, and the uploaded file itself is purged from storage as soon as the import commits.
Know what the analyzing step and a failed password mean.
Large exports parse and match in the background rather than tying up the browser: an analyzing progress state runs first, then a routing preview to confirm before anything writes to the vault. Once confirmed, it commits client by client and each one is visible landing. If the export zip was password-protected and the password was missing or wrong, the import stops and asks for it again without re-uploading the file - and it can be cancelled any time before it starts committing.
Open Integrations, then AI.
This tab only connects AI providers - it has no control for choosing which model powers which feature. The portal maps each AI task to a tier (standard for quality work, fast for cheap classification, reasoning for the hardest calls, plus an embedding tier for search), and each tier resolves to the best available model automatically, so a model retirement is handled without any action here. Overriding the model for one specific feature lives under Settings, then AI Assistant, not on this tab; the sensible defaults only need overriding for a specific reason.
Open Integrations, then AI. Open the Pax8 detail page and find Invoice grouping under Pricing & Plan Type.
This setting decides how a client's Pax8 subscriptions land on invoices once billing runs. Bill all plans separately, shown here, issues one invoice per Pax8 plan. Combine all invoices into one keeps Pax8 off the Core rollup but puts every Pax8 plan due in the same period onto one invoice per month, named after the plan type. Roll up to Core merges the Pax8 lines onto the client's Core rollup invoice instead, so a client with no Core plan simply gets one invoice per Pax8 plan. Changing this applies from the next billing run onward and never touches an invoice that already exists.
Open the Pax8 detail page and find Invoice grouping under Pricing & Plan Type.
If it did not work
- If a card under a provider's detail page still reads "Configure <provider> credentials first to use this section", that section (Sync health, Synced Client Plans, Needs Attention & Coverage) only fills in once real API credentials are saved - the Product catalog, password-export and pricing cards above it are read-only or file-based and render either way.
Questions this page answers
How do I connect QuickBooks?
Click Connect on the QuickBooks card and complete the OAuth flow in the popup. The portal stores the connection's tokens encrypted and refreshes them automatically as they are used. If the connection goes dead (revoked, or the refresh token expired), the card stops showing Connected and prompts you to re-authorize; reconnect from the same card to restore it.
How do I connect QuickBooks?
QuickBooks uses OAuth. Open the QuickBooks Online card on Integrations > Billing and click Connect to start the authorization flow. Once connected, customers, invoices, estimates, payments, and products sync automatically. The sync runs on a scheduled job and can also be triggered manually.
What happens when I click Connect on this page?
It starts an OAuth sign-in with Intuit (QuickBooks' own login, not a portal password). Sign in with an admin account on the QuickBooks Online company you want to connect. If that login has access to more than one company, Intuit shows a company picker, choose carefully: the company you pick becomes the ONE company this connection pushes invoices to and pulls payments from, and switching to a different company later means disconnecting and reconnecting from scratch, there is no in-portal company switcher.
What do I need before connecting QuickBooks?
You need an active QuickBooks ONLINE subscription. QuickBooks Desktop is not supported. You also need an admin-level login on that company. After you connect, do two things before your first invoice pushes. First, curate the Product Catalog card on this page. That maps your billed line items to real QuickBooks items. Second, use Client Matching, also linked from this page, to link each portal client to its QuickBooks customer. An unmatched client's invoice fails to push. It never goes to the wrong customer by mistake.
How does importing from a docs provider work?
Configure the provider with an API key, then go to Clients > [client] > Documentation > Imports to pull articles, passwords, procedures, and assets into the portal. Re-running the import is idempotent, existing entries are matched and updated by their external ID, so a re-pull updates the same entries instead of creating duplicates.
What does "Import password export" do?
It imports the vendor's account-wide password export - one file covering every client - in a single pass. Each row is routed to the matching client through your organization links, and passwords land in that client's encrypted vault. TOTP (2FA) seeds import too, which the API sync can never deliver. Upload the vendor's export zip directly and enter its password, or upload an already-extracted passwords.csv. The file uploads with a progress bar, then a background job parses it and shows you a routing preview - nothing imports until you confirm it.
Why do I need to link clients before importing?
Rows are routed through organization links, and only linked organizations import - anything belonging to an unlinked or ambiguously-linked organization is skipped, never ingested. The preview lists exactly which organizations are unlinked and how many rows would be skipped, before you confirm the import. Link them on the Matching page, then start the import over with the same file; already-imported rows update in place rather than duplicating.
What happens if I import the same export twice?
Each row is stamped with its source record id, so a re-import updates the same vault entries instead of creating duplicates - and the periodic API sync recognizes the same stamp, keeping everything converged. Entries a technician deleted stay deleted (the import never resurrects them), archived rows in the export are always skipped, and the uploaded file itself is purged from storage as soon as the import commits.
Why does the import show an "analyzing" step, and what if it fails partway?
Large exports are parsed and matched in the background rather than tying up your browser - you'll see an "analyzing" progress state, then a routing preview to confirm before anything writes to the vault. Once you confirm, it commits client by client and you can watch each one land. If the export was password-protected and the password was missing or wrong, the import stops and asks you to re-enter it without re-uploading the file. You can cancel an import any time before it starts committing.
How does the portal choose which AI model each feature uses?
The portal maps each AI task to a tier, standard for quality work, fast for cheap classification, reasoning for the hardest calls, plus an embedding tier for search, and each tier resolves to the best available model automatically, so a model retirement is handled for you. You don't pick models on this tab; this is where you connect and configure your AI providers. If you want to override the model for a specific feature, that control lives under Settings → AI Assistant. Defaults are sensible, only override when you have a reason.
Pax8: what does the Invoice grouping setting do?
It decides how a client's Pax8 subscriptions land on invoices when billing runs. Roll up to Core merges the Pax8 lines onto the client's Core rollup invoice (the Core invoice's billing window captures them), so they get one invoice for everything; a client with no Core plan simply gets one invoice per Pax8 plan instead. Combine all invoices into one keeps Pax8 on its own invoice but puts every Pax8 plan for that client that is due in the same billing period on a single invoice, named after the Pax8 plan type (Software Licensing by default); plans due in different months get their own combined invoice for their month. Bill all plans separately issues one invoice per Pax8 plan. Changing the setting applies from the next billing run onward and never touches invoices that already exist.
Was this helpful?