OAUTH & PERMISSIONS

What Analytir accesses

When you connect Square or QuickBooks, you're granting Analytir read-only access to specific pieces of your data. Here's the exact list — no marketing fluff, no hidden scopes.

Scope 01 · OAuth

How OAuth works

When you click Connect Square or Connect QuickBooks, Analytir redirects you to Square's or Intuit's own login page. You authenticate there, not here. Analytir never sees your Square or QuickBooks password.

After you log in, the provider shows you exactly what permissions Analytir is requesting. If you approve, the provider sends Analytir a token — a limited-scope credential that lets Analytir read the data you approved, and nothing else.

You can revoke that token anytime from your Square or QuickBooks account dashboard. Revoke, and Analytir loses access immediately.

Scope 02 · Square

Square permissions

Analytir requests the following read-only scopes from Square. Each one is disclosed below with what it lets Analytir see and why it's needed.

  • MERCHANT_PROFILE_READ — your business name, timezone, and location metadata. Analytir uses this to label your dashboard and bucket data in your local timezone.
  • PAYMENTS_READ — every payment processed through Square. This is the core of what Analytir shows: gross sales, tips, tax, and processing fees.
  • ORDERS_READ — order-level detail behind each payment, used to attribute payments to the orders that produced them.
  • PAYOUTS_READ — settlement and payout records. Analytir uses this to match deposits to the sales that produced them, so you can see why the bank number differs from the register.

Scope 03 · QuickBooks

QuickBooks permissions

Analytir requests one scope from QuickBooks:

com.intuit.quickbooks.accounting — this is the standard scope Intuit provides to all accounting-connected apps. It covers reading transactions, chart of accounts, invoices, bills, and other accounting records.

Intuit doesn't offer a narrower read-only variant of this scope — it's a broad permission by design. Analytir uses it in read-only mode: your QuickBooks records are never written, modified, or deleted by Analytir, even though the scope technically permits it.

This is standard for QuickBooks integrations. Xero, Bill.com, Ramp, and other accounting tools all request the same scope the same way.

Scope 04 · Limits

What Analytir cannot do

Regardless of scope, here's what Analytir is architecturally incapable of, on both Square and QuickBooks:

  • Move money in or out of any account
  • Issue refunds or process transactions
  • Modify or delete records inside Square or QuickBooks
  • Change your bank account, payout schedule, or business settings
  • Access other apps you've connected to Square or QuickBooks
  • Share your data with any third party

This is enforced at two layers: the read-only scopes above, and Analytir's own code, which contains no write, update, or delete operations against provider APIs.

Scope 05 · Revoke

Revoking access

You can revoke Analytir's access at any time, in three places:

From Analytir — visit your integrations page and click Disconnect on any connected platform. Access ends immediately.

From Square — go to your Square Dashboard, open Apps & Subscriptions, find Analytir, and disconnect. Access ends immediately.

From QuickBooks — go to your Intuit Account settings, open Apps, find Analytir, and disconnect. Access ends immediately.

Revoking access from any of these three places terminates Analytir's ability to read your data on that platform. If you want your historical data deleted as well, email support@analytir.com — full data deletion completes within seven days.

If you're evaluating Analytir on behalf of a client or you want to walk through any of these scopes before connecting, email support@analytir.com and I'll answer directly.

— James