Connecting NetSuite with Machine-to-Machine Access
Connecting NetSuite with Machine-to-Machine Access
Which sign-in method should I use?
Use Machine-to-machine (recommended). NetSuite expires the "Sign in with NetSuite" login about once a week, so someone has to sign in again. Machine-to-machine (M2M) uses a certificate instead, so Velaro stays connected with no re-login. A NetSuite Administrator does the setup once per NetSuite account. Sandbox and production are separate connections, so set up each one.
If your existing connection uses Sign in with NetSuite, it keeps working. On Integrations → NetSuite you will see a Switch to machine-to-machine card whenever you are ready.
Who does the setup and what do they need?
A NetSuite Administrator (or a user with the OAuth 2.0 Authorized Applications Management permission), once per account. Before starting, have your NetSuite account ID (Setup → Company → Company Information; sandbox looks like 1234567_SB1) and decide which Velaro features you will use, because that decides the permissions in step 2.
Step 1: Enable the features
In NetSuite go to Setup → Company → Enable Features → SuiteCloud. Check OAuth 2.0 and REST Web Services, then Save.
Step 2: Create a Velaro user and a least-privilege role
Create a dedicated integration user for Velaro (not a person's login). Create a role for it under Setup → Users/Roles → Manage Roles. On the Permissions subtab add Log in using OAuth 2.0 Access Tokens and REST Web Services (Setup subtab), plus record access for what you use:
- Customer and contact lookups: View on Customers and Contacts (add Edit to create or update contacts).
- Support cases: View, Create and Edit on Support Cases.
- Orders and returns: View on Sales Orders and Invoices, Edit on Sales Orders for notes, and Return Authorizations if Velaro creates returns.
- SuiteQL and RESTlets: the record permissions those queries read, and the Velaro RESTlet deployed to this role.
Step 3: Create the integration record
Go to Setup → Integration → Manage Integrations → New. Under Authentication check Client Credentials (Machine to Machine) Grant. Save and copy the Client ID right away, because NetSuite shows it only once.
Step 4: Map the integration and upload the Velaro certificate
In Velaro open Integrations → NetSuite → Add Account, choose Machine-to-machine, and click Generate Velaro certificate. Download or copy it. In NetSuite go to Setup → Integration → Manage Authentication → OAuth 2.0 Client Credentials (M2M) Setup → Create New. Choose the integration, the Velaro user and the role, upload the certificate, and Save. NetSuite shows a Certificate ID.
Step 5: Verify in Velaro
Paste the Client ID and Certificate ID into Velaro and click Save and verify. Velaro checks three things: it can get a token, it can reach the NetSuite REST service, and it can read a customer. A failed check tells you what is wrong and how to fix it. When all pass, click Finish.
After you connect
NetSuite allows up to 5 active certificates per integration record. If the certificate expires, create a new mapping with a new certificate. Setup is not copied between production and sandbox, and refreshing a sandbox clears it.
The status card shows the sign-in method, account, environment (production or sandbox), the last successful sign-in, and when the certificate expires. Use Rotate certificate before it expires, Test connection any time, or Disconnect to remove it.
Why did my NetSuite connection disconnect?
Open Integrations → NetSuite. The red or amber panel names the reason and the fix. See the NetSuite connection problems section in the integration troubleshooting guide for each reason and its fix.
References: Oracle NetSuite Help Center, "OAuth 2.0 Client Credentials Setup" (https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_162686838198.html) and "Set Up OAuth 2.0 Roles" (https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_157771510070.html).
Was this article helpful?