Skip to content

Connect TenkeyBridge on Rightworks (formerly Right Networks) ​

Hosted QuickBooks

This page is for QuickBooks hosted by Rightworks (rebranded from Right Networks) — the remote desktop you reach through a browser or RDP client rather than a machine you can install anything on yourself. It only covers what's Rightworks-specific. For the general Web Connector setup — the portal steps, the grant dialog, latency, troubleshooting codes — read Connect with QuickBooks Web Connector first and come back here for the Rightworks details.

Rightworks' standard hosted desktops don't let you install anything (no admin rights, no cmd.exe, writes outside your own profile are blocked). Web Connector is the default path on Rightworks, and the one we recommend starting with: it's a small client Rightworks already ships, it only ever handles an XML file (never an .exe), and it talks to TenkeyBridge over outbound HTTPS the same way any other Web Connector app does.

If you need answers faster than Web Connector's polling, there is an opt-in second path — the TenkeyBridge edge agent, installed for you by Rightworks support on a Deluxe plan. It is covered in The agent option below. Both can be live for the same realm at once.

Before you start ​

  • A Rightworks login with catalog access, or your firm's Rightworks admin if you don't have that yourself.
  • QuickBooks Desktop or Enterprise, hosted on your Rightworks account, with the company file you want to connect.
  • Your TenkeyBridge realm's .qwc file, downloaded from the developer portal (Web Connector setup walks through this on the general guide).

Step 1 — Confirm Web Connector is on your Rightworks desktop ​

Rightworks' own help desk says Web Connector doesn't need installing:

The QuickBooks Web Connector is already installed on all Rightworks Accounts. To access this functionality, please follow the steps below while logged in to your company file: Click on the File menu. Select Update Web Services.

— Rightworks: QuickBooks Web Connector

So check first, before going looking for an install step: open QuickBooks on your hosted desktop, click File → Update Web Services. If that opens the Web Connector window, you're done — skip to Step 2.

If it isn't there, a third-party guide (Conductor, not Rightworks) describes installing it from your Rightworks Dashboard instead:

If you don't find the Web Connector in your Start menu, you can install it from the Rightworks Dashboard: Log in to your Rightworks Dashboard. Select "My Apps" in the left sidebar. In the search bar, type "Web Connector". Locate "QuickBooks Web Connector" in the results. Click the "+" button next to it to add it to your account. Wait 5-10 minutes for the installation to complete.

— Conductor: Connecting to QuickBooks Desktop on Rightworks (third-party guide, not Rightworks-authored)

Rightworks' own article never mentions "My Apps" or an install step — treat "already installed" as the default and only fall back to the Rightworks Dashboard's app catalog (Conductor calls the sidebar item "My Apps"; the Rightworks help desk elsewhere refers to the same catalog as "AppHub" — we found no page confirming they're the identical UI, so don't assume the label an agent uses matches what you see) if File → Update Web Services genuinely isn't there for your account.

Step 2 — Get the .qwc onto the hosted desktop ​

The .qwc is a small XML file, not a program, so it's allowed through paths that block .exe files. Two ways to get it onto the hosted desktop:

  • Download it inside the hosted browser. Open the TenkeyBridge portal from a browser running on the Rightworks desktop itself and download the .qwc there directly — no transfer step needed.
  • Email it to yourself, then open the email inside the hosted desktop and save the attachment. Rightworks' shared drive for files visible to everyone on your account is I: — save it there if others on the account need to see it, or to Desktop (Hosted) / My Documents (Hosted) if it's just for you. (Rightworks' own File Manager article names the shared drive as I:, not H: — double-check the drive letter if you're following older or third-party instructions that say otherwise.)

Either way, don't try to move the .qwc in through a file type that gets blocked — it's XML, so it isn't.

Put it on the Desktop if you want to follow Rightworks' screenshots

Rightworks' own Web Connector article walks through Add an Application → Desktop → select the .qwc → Open, with screenshots that assume the file is sitting on the hosted desktop. Saving it to Desktop (Hosted) lets you follow their steps one-to-one; any other folder works too, you just browse to it instead.

Step 3 — Add it in Web Connector and grant access ​

With the .qwc on the hosted desktop:

  1. Open QuickBooks, sign in to the company file, then File → Update Web Services (Rightworks' name for opening Web Connector — see Step 1's quote).

  2. Add an Application → browse to the .qwc → Open. If prompted to authorize a new web service, select OK.

    TIP

    Web Connector dials qbwc.tenkeybridge.com, which uses a certificate Rightworks desktops already trust. If you see QBWC1048, either your .qwc is an old one or Rightworks' web filter hasn't rated the address yet — see Troubleshooting.

  3. QuickBooks shows the grant dialog. Choose "Yes, always; allow access even if QuickBooks is not running." This is unattended mode — Web Connector can open the company file itself and hand it requests without anyone sitting in front of QuickBooks. On a hosted desktop this matters more than usual: you want Web Connector polling to work even if nobody has QuickBooks in focus. (Full detail on the two grant options is on the general Web Connector guide.)

  4. Paste the password from the portal into the row Web Connector adds, tick the checkbox, and click Update Selected once to confirm the connection — or just wait for the next scheduled poll. Leave the Every-Min box alone: blank is correct (the .qwc polls every 10 seconds, faster than that box can display), and typing a number there slows every request down to that many minutes — see Troubleshooting on the general guide to undo it.

Step 4 — Keep it running ​

This is the part that's different from installing on your own PC: a Rightworks session isn't always-on the way a desktop under your own desk is.

Rightworks has not published its own statement on what happens to background programs when you disconnect. The only claim we found anywhere is from Conductor's third-party guide, not from Rightworks:

Important: To sync data with your QuickBooks Desktop, you must be actively connected to your Rightworks remote desktop session with QuickBooks Desktop open. This is because Rightworks stops all background programs when you disconnect from your session.

— Conductor: Connecting to QuickBooks Desktop on Rightworks (third-party claim about Rightworks' behavior — Rightworks itself does not publish this in its own words)

Treat that as unconfirmed rather than gospel, and ask Rightworks support to confirm it for your account when you contact them in the next section — it's in the copy-paste script below.

What's confirmed and published by Rightworks: your hosted desktop disconnects automatically after 2 hours of inactivity, and that timer can't be changed per account or user:

For security reasons, the Rightworks hosted desktop is configured to disconnect after 2 hours of inactivity. … Can you extend or shorten the timeout period for me? Unfortunately, no. This is a system-wide setting and it cannot be altered for individual users or accounts.

— Rightworks: Idle Time Disconnection

Rightworks doesn't publish what happens to QuickBooks or Web Connector specifically at that 2-hour mark (resumed on reconnect vs. closed) — that's also on the support script below.

Two ways to handle this in practice:

  • Ask Rightworks support to auto-start QuickBooks and Web Connector at logon. This doesn't get around the idle-disconnect timer, but it means every time someone (or a scheduled reconnect) signs into the account, both are already running and Web Connector resumes polling without anyone manually reopening File → Update Web Services. This has to go through Rightworks support — there's no self-service toggle for it. Use the script in the next section.
  • A dedicated always-on user. If you want TenkeyBridge to sync continuously rather than only while someone happens to be connected, Rightworks offers dedicated hosted-desktop seats — ask your Rightworks admin or support about adding one just for this purpose. That's an additional seat on your Rightworks account (and its own idle-disconnect timer still applies at 2 hours, so someone or something still needs to keep it connected, or reconnect periodically), not a way around the session model — it just means the "someone connected" requirement is met by a seat dedicated to staying connected instead of competing with a real user's work session.

The agent option ​

The edge agent is a small Windows program that keeps one outbound, encrypted WebSocket open to TenkeyBridge. While it is connected, an API call reaches QuickBooks immediately; over Web Connector the same call waits for the next poll (about 10 seconds), and the first calls after you sign in can return 503 AGENT_OFFLINE until Web Connector's first check-in.

Read this before you ask for it

  • Web Connector stays the default. It needs no install and no permission from Rightworks. Start there; add the agent only if latency matters to you.
  • Rightworks has to install it. You can't run an .exe on a standard Rightworks desktop. Other desktop-integration vendors get their programs installed by asking Rightworks support, and the same route applies here — but Rightworks has no public certification or approved-application list for TenkeyBridge, so each request is theirs to approve or decline.
  • Reported plan requirement: Deluxe. Other vendors' Rightworks guides say Rightworks only installs external programs for Deluxe-plan accounts. Rightworks doesn't publish that rule itself, so confirm your plan when you ask.
  • It only runs while your session is live. The agent lives inside your Rightworks Windows session, exactly like Web Connector. Rightworks disconnects idle sessions after 2 hours (system-wide, not configurable), and nothing runs on your behalf while no session exists. When the session is gone, API calls return 503 AGENT_OFFLINE — quickly, not after a hang — and when it's back the agent reconnects by itself.
  • Not offered in the portal today. The agent isn't part of the self-serve product; email sales@tenkeybridge.com for the installer and a vendor packet (what it does, network endpoints, hashes) you can hand to Rightworks.
  • Signing. Until a trusted code-signing certificate ships, builds are signed with a development certificate, so Windows shows an "unknown publisher" warning — see Verifying the download.

What the agent needs from Rightworks ​

NeedDetail
NetworkOutbound wss://api.tenkeybridge.com on port 443 only. No inbound ports. If Rightworks' web filter blocks the address, the agent logs connection failures and retries — ask them to allow it
RightsNone beyond your normal user. Per-user install under %LOCALAPPDATA%; no admin, no service, no driver
QuickBooksEnterprise 2023 R16 or later, with the one-time QuickBooks grant ("Yes, always; allow access even if QuickBooks is not running") done for the company file
SessionA logged-in Windows session for the agent to live in (disconnected is fine, signed-out is not)
Start at sign-inThe installer's Startup shortcut (setup --startup on), so the agent is back whenever you sign in

How to ask Rightworks support ​

Use the Rightworks chat in the support center and have the account's primary contact send it. Copy and paste, filling in the brackets:

Hi — please install an external program on my hosted desktop for account
[account name], user [username]. My plan is [Deluxe / please confirm].

Program: TenkeyBridge Agent, version [x.y.z] — a per-user Windows program
(no admin rights, no service) from TenkeyBridge / Empire Innovations, LLC.
It makes one outbound HTTPS/WebSocket connection to api.tenkeybridge.com
on port 443 and opens no inbound ports. It talks to QuickBooks through the
normal QuickBooks integrated-application interface on my own company file.

The vendor's security packet and SHA-256 checksums are attached / at
[link] (contact: sales@tenkeybridge.com).

Please also confirm:
1. That outbound access to api.tenkeybridge.com:443 (wss) is allowed.
2. That the program can start at my logon (per-user Startup shortcut).
3. What happens to a running program at the 2-hour idle disconnect, and
   whether my sessions can land on different servers (the program
   reconnects on its own either way).

Thanks!

Anything about the agent itself (won't connect, QuickBooks errors, logs) goes to hello@tenkeybridge.com, not Rightworks.

Running it ​

  1. After Rightworks installs it, run tenkeybridge-agent setup in your Rightworks session with the agent token from the portal, and grant access in QuickBooks — the steps are on the install page.
  2. Because your session can move between servers and be disconnected, consider setting RequireQuickBooksRunning to true in appsettings.json. With it, a closed QuickBooks is answered immediately with 503 QB_NOT_OPEN instead of the agent trying to launch QuickBooks (which can take 30 seconds or more, or stall behind a dialog). Nothing was executed, so retrying is always safe.
  3. Both transports together. If Web Connector is also live for the realm, TenkeyBridge prefers the agent and, if the agent reports QB_NOT_OPEN, retries the request over Web Connector automatically.

What happens as your session changes ​

EventWhat you'll seeWhat the agent does
You sign inFirst calls may be 503 AGENT_OFFLINE for a few secondsStarts, connects; calls succeed as soon as it says hello
Rightworks moves you to another server (network change)A brief gap at mostReconnects immediately, without waiting out its backoff
Session reconnect after a disconnectA brief gap at mostDrops its old connection and dials a fresh one
2-hour idle logoff / sign-out503 AGENT_OFFLINE right away — the gateway sees the connection closeCloses cleanly when it gets the chance; otherwise the gateway notices within seconds to a minute
QuickBooks closed inside the session503 QB_NOT_OPEN (with RequireQuickBooksRunning) or a slower launchReports the state; never guesses
A call was in flight when the connection dropped504 AGENT_TIMEOUT (outcome unknown — re-query before retrying a write, or use requestid)Reconnects

The agent also checks once a day whether a newer version exists and logs a line if so. It never downloads or replaces itself — Rightworks (or you) installs updates the same way it installed the first version.

Multiple company files on one Rightworks login ​

Web Connector — like QuickBooks itself — can only have one company file open at a time in a given Windows session. If you have more than one TenkeyBridge realm, each needs its own .qwc and its own row in Web Connector, same as the general guide's multiple-file section describes. On Rightworks specifically: while one file's connection is actively running (QuickBooks has that file open), the others sit idle in Web Connector's list — they aren't broken, they just wait until their own scheduled poll and QuickBooks has that file open instead. If your Rightworks account has multiple company files that all need to sync regularly, ask about a separate hosted-desktop session per file (one Windows session per company file) so each has QuickBooks open on its own file continuously rather than swapping.

What to tell Rightworks support ​

First, know where the line is. Rightworks' Web Connector article ends with:

Most Web Connector applications work with Rightworks, but for any setup issues or errors with any given Web Connector application we suggest contacting the manufacturer of the application.

— Rightworks: QuickBooks Web Connector

For TenkeyBridge, that manufacturer is us. Anything about the connector itself — the portal status badge, a .qwc that won't add, a password Web Connector rejects, a sync that errors, an API call that times out — goes to hello@tenkeybridge.com first; Rightworks will only send you back to us. Take the items below to Rightworks: they're about the hosted desktop, not the app.

Rightworks' general support line is 866-828-4629 ext. 2, chat Monday–Friday 8:00 AM–8:00 PM ET, from the Rightworks support center. (A different Rightworks help-desk page — the File Manager article, for File Manager specifically — lists a separate 24/7 number — 888-417-4448 ext. 2 — and a slightly different chat window, 8:00 AM–9:00 PM EST; the two pages disagree, so start with the general support center above and only use the File-Manager number if that's the department you're actually routed to.)

Copy and paste this when you reach a support agent:

Hi — I'm setting up a QuickBooks Web Connector integration (TenkeyBridge)
on our hosted desktop and have a few requests:

1. Please confirm QuickBooks Web Connector is enabled on our account
   (File > Update Web Services should already work; if not, please add
   "QuickBooks Web Connector" to our account from the app catalog for
   my user).

2. Please configure QuickBooks Desktop and QuickBooks Web Connector to
   auto-launch at logon for [my username / all users on this account].

3. Can you confirm: does our hosted desktop's 2-hour idle-disconnect
   timer close QuickBooks and Web Connector, or do they resume running
   when we reconnect? And are background programs (like Web Connector)
   stopped immediately when a session disconnects, or only at the idle
   timeout?

Thanks!

Troubleshooting ​

SymptomLikely causeFix
TenkeyBridge portal shows the connection offline after you've been awayYour Rightworks session disconnected (idle timeout, or you signed out) and took Web Connector down with itReconnect to your Rightworks desktop; if QuickBooks and Web Connector aren't set to auto-launch, reopen them (File → Update Web Services)
Your app's first calls fail with 503 AGENT_OFFLINE right after you sign in to Rightworks, then work a few minutes laterThe app called before Web Connector on your Rightworks desktop had checked inNothing reached QuickBooks, so retrying is always safe, writes included. Open QuickBooks and Web Connector first, then your app
Web Connector logs a QBWC1012 errorWeb Connector couldn't reach TenkeyBridge's endpoint (or hit an error) during authenticate — check your Rightworks desktop's network/proxy, and the gateway status pageRetry; if it persists, see the error-code table on the general Web Connector guide
Add an Application fails with QBWC1048: … could not verify the web application server certificateYour .qwc points at api.tenkeybridge.com — a file issued before 2026-09-22. Current .qwc files point Web Connector at qbwc.tenkeybridge.com, whose certificate chains to a root that ships in Windows itself, so this error no longer occurs on Rightworks desktops (verified 2026-09-22)Create a new Web Connector connection for the realm in the portal and add that .qwc instead. (Legacy fallback for an old .qwc: install https://letsencrypt.org/certs/isrgrootx1.der into your own user profile — no admin rights, no Rightworks ticket. In the hosted browser download it to Desktop (Hosted) or I:, double-click it → Install Certificate… → Current User → Place all certificates in the following store → Browse → Trusted Root Certification Authorities → Finish → Yes. This does not make the connection stable on hosted desktops; get a current .qwc.)
Add an Application fails with QBWC1048 even though the .qwc already points at qbwc.tenkeybridge.comRightworks' web filter doesn't recognise the address yet and is answering with its own block page instead of TenkeyBridge. Check from the hosted desktop: open https://qbwc.tenkeybridge.com/qbwc/support in Internet Explorer. A padlock and a plain-text support page means the filter is fine and something else is wrong; a certificate warning whose Issued by is not Amazon RSA 2048 M0x means the filter is interceptingEmail hello@tenkeybridge.com with a screenshot of that certificate. We request the rating from the filter vendor — it usually clears within an hour — and nothing needs installing on your side. Then Add an Application again with the same .qwc
Update runs but nothing syncs / wrong-file errorThe realm is pinned to a different company file than the one currently open on the hosted desktop (QuickBooks holds one file open at a time)Open the pinned company file in QuickBooks, or Unpin the connection in the portal if the file legitimately moved — see the general guide
Agent installed, but calls return 503 QB_NOT_OPENThe agent is connected, but QuickBooks isn't open in the same Windows session (closed, or the session was reconnected without it)Open QuickBooks on the pinned company file in your Rightworks session and retry — nothing was executed, so retrying is always safe. See The agent option
Agent installed, but calls return 503 AGENT_OFFLINE after a whileYour Rightworks session ended (2-hour idle logoff or sign-out) and took the agent with itReconnect to your Rightworks desktop; the agent starts at sign-in and reconnects on its own. Web Connector needs a live session too, so it is not a fallback for an ended session
.qwc won't open / "file blocked"You tried to run it as if it were a program, or your Rightworks profile blocks the download locationConfirm it has a .qwc extension (it's XML, always allowed) and try saving it to I: or Desktop (Hosted) instead

For error codes and behavior that aren't Rightworks-specific, see Connect with QuickBooks Web Connector.

TenkeyBridge is an independent product, not affiliated with, endorsed by, or sponsored by Intuit Inc. QuickBooks, QuickBooks Online, and QuickBooks Desktop are trademarks of Intuit Inc., used only to describe compatibility.