Contreol: Intuit Sandbox test
Release 0.9.6 · September 19, 2026
Use your existing Contreol administrator account at https://contreol.com/admin/billing.html. No second Contreol customer account is needed.
1. Connect a Sandbox company
In Intuit, open My Hub → Sandboxes and verify that a QuickBooks Online test company appears. A developer workspace or an app with Development credentials is separate from a sandbox company. If the company list is empty, choose Create sandbox → United States → QuickBooks Online Plus, then create it.
In Intuit, use the app's development Client ID and Client Secret and a QuickBooks Online Sandbox company. Register this exact redirect URI:
https://contreol.com/admin/quickbooks-callback.php
In Contreol, select Sandbox, save the credentials, acknowledge the Accounting permission, and select Connect to QuickBooks. Authorize the Sandbox company, return to Contreol, check its name and company ID, and confirm it. The company ID is not the Client ID.
Keep real card/bank details and production credentials out of this test. Contreol requests Accounting scope only; it does not call the Payments API.
2. Add the test customer and prepare the order
Select Open Sandbox test client, then Add or match in QuickBooks. If a matching customer exists, review it before linking. Reload the workbench and confirm that it retains the same QuickBooks customer ID.
Select Prepare billing order, with tax set to 0.00 for this fixture. The order is $21.00 USD/month and has a unique CT-… reference. Copy that reference.
The invitation section is optional in Sandbox. Do not open or create a production recurring-payment request for this example.test customer.
3. Create an accounting test transaction in the Sandbox company
Using the Sandbox company or Intuit API Explorer, create either:
- A SalesReceipt for the test customer, total $21.00 USD; or
- An Invoice for that customer, total $21.00 USD, plus a Payment fully allocated only to that invoice. Its balance and unapplied payment amount must both be zero.
Use the current company-local transaction date. Put the complete Contreol CT-… reference in the sales receipt or invoice's internal memo (PrivateNote). Use only test items/accounts available in the Sandbox. Do not send an invoice email.
Copy the entity Id returned by Intuit. This is the API record ID, which may differ from the displayed invoice/receipt number. For an invoice, also copy the Payment entity Id.
An Accounting API SalesReceipt or Payment records bookkeeping. It does not demonstrate that a card was charged or that recurring consent was accepted. Native recurring-payment invitations may not be available in the Sandbox experience. Record that as an untested production handoff, not a passed payment-processor test.
4. Verify and build privately
In the workbench, open Match the accounting transaction, choose the transaction type, and enter its ID (plus Payment ID for an invoice). Select Verify with QuickBooks.
A successful result should match the company, customer, USD amount, date and order reference. For an invoice, it also checks the zero balance, payment allocation and duplicate use.
For this Sandbox exercise only, review the simulated payment scenario, select the two Sandbox acknowledgements, and choose Complete Sandbox billing check. These acknowledgements are not an assertion that real money moved.
Choose Build private Sandbox release. Reopen the Sandbox workbench after about two minutes. Expect sandbox built, with page count and the saved draft revision. The build uses your administrator builder draft when available, otherwise a small test draft. It remains in private storage: no public subdomain, DNS change, mailbox, charge or email is created by a Sandbox build.
5. Check recovery and authorization
- Try an incorrect transaction ID or wrong amount before approval: verification must stop without changing your draft.
- Open billing settings in a signed-out/private browser: it must require administrator sign-in.
- Disconnect through Contreol, then reconnect the same Sandbox company and confirm it again. Reopen the workbench and check that the existing customer/order mapping remains.
- Open Connection diagnostics after a successful request. It should show request outcome and, when supplied in a recognized format, Intuit's intuit_tid; no credential or transaction body should appear.
- Note the test date, company, customer ID, transaction IDs, outcome and any diagnostic reference. Do not copy tokens or secrets into a report or chat.
What this test can establish
The real Sandbox authorization lifecycle, customer creation/matching, authenticated accounting reads, order matching and private build can be marked tested once these steps pass. Controlled tests already cover expired access/refresh tokens, invalid grants, throttling, malformed responses, provider faults and access isolation.
The test does not establish live payment processing, actual recurring consent, Intuit approval, production refunds/disputes, mailbox provisioning or custom-domain ownership. Those remain separate checks. Leave Intuit's assessment saved but unsubmitted until the applicable real tests and business-history answers are complete.
Production operation after review
The owner creates the native recurring-payment request in QuickBooks, verifies its customer/amount, and saves the invitation on the Contreol order. The customer opens it from their account. After matching the resulting accounting record, the owner verifies accepted recurring consent and successful first payment in QuickBooks Payments. Contreol can then prepare a temporary subdomain and HTTPS; the owner explicitly publishes the reviewed release. Customer custom-domain mapping and mailboxes are handled separately before their DNS instructions are acted on.
There is no unattended recurring enrollment, charge, refund, suspension, cancellation or financial reconciliation scheduler in this release. Signed change notifications are recorded; they do not approve launch. Automated follow-up emails are not enabled. Customer billing and launch progress appear in their account.