Oracle NetSuite Connector
Description
Oracle NetSuite is a unified business management suite, encompassing ERP/Financials, CRM and ecommerce. This component allows creating, reading, updating, deleting, and listing records in NetSuite, as well as executing SuiteQL queries.
API Documentation
This component was built using the following API References currently utilizing REST API v1:
For more details refer to NetSuite's API documentation.
Connections
NetSuite OAuth Auth Code
key: oauthTo connect to NetSuite using OAuth 2.0 Authorization Code flow, create an OAuth 2.0 application in NetSuite with authorization code grant enabled.
Refer to NetSuite's OAuth 2.0 documentation for additional details.
Tokens retrieved using NetSuite's OAuth 2.0 Auth Code flow expire after 7 days and cannot be refreshed. This requires users to re-authenticate every 7 days, which is not a good user experience. We recommend using the OAuth 2.0 Client Credentials flow instead.
Prerequisites
- NetSuite administrator access
- SuiteTalk enabled in the NetSuite account
Setup Steps
-
Enable SuiteTalk:
- Navigate to Setup > Company > Enable Features
- Under the Suite Cloud tab, ensure REST WEB SERVICES and OAUTH 2.0 are both checked
-
Create an OAuth 2.0 Application:
- Navigate to Setup > Integration > Manage Integrations > New
- Enter a name and description for the integration
- Under Token-based Authentication, un-check TOKEN-BASED AUTHENTICATION and TBA: AUTHORIZATION FLOW
- Under OAuth 2.0, ensure the following are checked:
- AUTHORIZATION CODE GRANT
- REST WEB SERVICES
- Under SCOPE, enable REST WEB SERVICES
- Set the REDIRECT URI to:
https://oauth2.prismatic.io/callback - After saving, copy the CONSUMER KEY and CONSUMER SECRET
-
Configure OAuth 2.0 Roles:
- Ensure that users who will authenticate via OAuth have been assigned a proper role with appropriate permissions
Configure the Connection
- Enter the Consumer Key (Client ID) and Consumer Secret (Client Secret) from the NetSuite integration
- Token URL: Enter the NetSuite account's token URL in the format:
https://[ACCOUNT_ID].suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token- Replace
[ACCOUNT_ID]with the NetSuite account ID (found in Setup > Company > Company Information) - Example:
https://1234567.suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token
- Replace
Verify Connection
Save the connection to authenticate with NetSuite. Users will be redirected to NetSuite to authorize access.
Tokens expire after 7 days and cannot be refreshed. Users will need to re-authenticate every 7 days by opening the connection configuration and re-authorizing.
| Input | Notes | Example |
|---|---|---|
| Authorize URL | The OAuth 2.0 Authorization URL for NetSuite. | https://system.netsuite.com/app/login/oauth2/authorize.nl |
| Consumer Key (Client ID) | The consumer key generated when you create your OAuth 2.0 application in NetSuite. Navigate to Setup > Company > Enable Features > SuiteCloud > Manage Authentication to create an application. | a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e1f2 |
| Consumer Secret (Client Secret) | The consumer secret generated when you create your OAuth 2.0 application in NetSuite. Navigate to Setup > Company > Enable Features > SuiteCloud > Manage Authentication to create an application. | z9y8x7w6v5u4t3s2r1q0p9o8n7m6l5k4j3i2h1g0f9e8d7c6b5a4z3y2x1w0v9u8 |
| Scopes | A space-delimited set of one or more scopes. This will always be rest_webservices | rest_webservices |
| Token URL | The OAuth 2.0 Token URL for NetSuite. Replace <ACCOUNT_ID> with your NetSuite account ID, which can be found in your browser's URL bar when you log in: https://<ACCOUNT_ID>.app.netsuite.com/ | https://<ACCOUNT_ID>.suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token |
NetSuite OAuth Client Credentials
key: oauthClientCredentialsTo connect to NetSuite using OAuth 2.0 Client Credentials, configure an OAuth 2.0 application with the Client Credentials (M2M) grant in NetSuite.
This authentication method is recommended for server-to-server integrations and provides a better user experience than the Authorization Code flow, as credentials do not expire and require no user re-authentication.
Refer to NetSuite's OAuth Client Credentials documentation for additional details.
Prerequisites
- NetSuite administrator access
- SuiteTalk enabled in the NetSuite account
- OpenSSL installed on the local machine (for certificate generation)
Setup Steps
-
Enable SuiteTalk:
- Navigate to Setup > Company > Enable Features
- Under the Suite Cloud tab, ensure both REST WEB SERVICES and OAUTH 2.0 are checked
-
Create an OAuth 2.0 Application with JWT Option:
- Navigate to Setup > Integration > Manage Integrations > New
- Enter a name and description for the integration
- Under Token-based Authentication, un-check TOKEN-BASED AUTHENTICATION and TBA: AUTHORIZATION FLOW
- Under OAuth 2.0, ensure the following are checked:
- REST WEB SERVICES
- CLIENT CREDENTIALS (MACHINE TO MACHINE) GRANT
- Under SCOPE, enable REST WEB SERVICES
- After saving, copy the CONSUMER KEY. It will not be shown again in NetSuite
-
Generate Certificate and Private Key for JWT:
A private key and certificate are required for JWT-based authentication. Refer to the NetSuite documentation for more information on generating or importing certificates.
-
On the local machine, generate a valid certificate using OpenSSL:
openssl req -new -x509 -newkey rsa:4096 -keyout private.pem \-sigopt rsa_padding_mode:pss -sha256 -sigopt rsa_pss_saltlen:64 \-out public.pem -nodes -days 730This command will:
- Generate a new RSA 4096-bit key pair with PSS padding
- Create a self-signed X.509 certificate valid for 730 days (2 years)
- Output two files in the current directory:
private.pem- The private key (keep this secure)public.pem- The public certificate (upload to NetSuite)
The system will prompt to enter certificate details (country, organization, common name, etc.). Press Enter to skip these prompts, though providing values helps with tracking and identification.
-
The private.pem file contains the private key and must be kept secure. Never commit this file to version control, share it publicly, or store it in an unsecured location. Only the application should have access to this file.
-
Configure OAuth 2.0 Client (M2M) in NetSuite:
- Navigate to Setup > Integration > OAUTH 2.0 CLIENT (M2M) SETUP and select Create New
- Choose the appropriate Entity and Role
- Select the Application created in step 2
- For Certificate, upload the
public.pemfile generated in step 3 - After saving, NetSuite will generate a Certificate ID (a unique identifier). Copy this value. It is needed to configure the connection. The Certificate ID will be a string similar to
zzP3z13fkaZsCcwCbmMpd5GvvPs9DTPIquAI83MnNx4.
-
Assign Roles:
- Ensure that the entity used in the OAuth 2.0 Client setup has been assigned appropriate roles and permissions
Configure the Connection
When configuring the NetSuite OAuth 2.0 Client Credentials connection, enter the following values:
- Certificate ID: From the OAuth 2.0 Client (M2M) setup in step 4
- Private Key: The entire contents of the
private.pemfile from step 3. Copy the full file including the header and footer lines. Format example:-----BEGIN PRIVATE KEY-----MIIJQwIBADANBgkqhkiG9w0BAQEFAASCCS0wggkpAgEAAoICAQC......key content here...-----END PRIVATE KEY----- - Consumer Key (Client ID): From the integration created in step 2
- Token URL: The NetSuite account's token URL in the format:
https://[ACCOUNT_ID].suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token- Replace
[ACCOUNT_ID]with the NetSuite account ID (found in Setup > Company > Company Information) - Example:
https://1234567.suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token
- Replace
| Input | Notes | Example |
|---|---|---|
| Consumer Key (Client ID) | The consumer key generated when you create your OAuth 2.0 application in NetSuite. Navigate to Setup > Company > Enable Features > SuiteCloud > Manage Authentication to create an application. | a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v2w3x4y5z6a7b8c9d0e1f2 |
| Certificate ID (Key ID) | The certificate ID (key ID) from your NetSuite certificate, used for signing the JWT token. Found in Setup > Company > Company Information > Certificates. | a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0 |
| Private Key for JWT | The private key (RSA or EC format) used for signing the JWT token. This is the private key corresponding to your NetSuite certificate. Include the full key with BEGIN/END markers. | |
| Scopes | A space-delimited set of one or more scopes. This will always be rest_webservices | rest_webservices |
| Token URL | The OAuth 2.0 Token URL for NetSuite. Replace <ACCOUNT_ID> with your NetSuite account ID, which can be found in your browser's URL bar when you log in: https://<ACCOUNT_ID>.app.netsuite.com/ | https://<ACCOUNT_ID>.suitetalk.api.netsuite.com/services/rest/auth/oauth2/v1/token |
Triggers
New and Updated Records
Retrieves existing and ongoing records for a specified NetSuite record type. Load history once, check for changes on a schedule, or both. | key: pollRecords
| Input | Notes | Example |
|---|---|---|
| Additional Filter | Additional WHERE clause conditions to append to the polling query. Do not include 'AND' prefix - it will be added automatically. See Record Collection Filtering for query syntax. | isinactive = 'F' |
| Connection | The NetSuite connection to use. | |
| Look-back Date | The date the initial sync starts from, in YYYY-MM-DD format. Cannot be a future date. Leave empty to start from the first recurrence with no backfill. When set, the initial sync seeds each record modified on or after this date once, ignoring the additional filter. | 2026-01-01 |
| Record Type | Record type to perform the action against. | |
| Show New Records | When true, includes new records in the results. | true |
| Show Updated Records | When true, includes updated records in the results. | true |
The New and Updated Records trigger checks for new and updated records in NetSuite based on the lastmodifieddate field on a configured schedule.
For more information on NetSuite REST API filtering, see Record Collection Filtering.
How It Works
- Run on the configured schedule (e.g., every 5 minutes)
- Query records using the REST API Record Service with a filter on
lastmodifieddate - Fetch all matching records using automatic pagination (1,000 records per page)
- Return both new and updated records that have been modified since the last poll
- Maintain state to track the last poll time automatically
Records are classified against the stored cursor: a record whose datecreated is later than the cursor is reported as created; a record created on or before the cursor whose lastmodifieddate is later than its datecreated is reported as updated. A record matching neither test is dropped. createdRecords is present only when Show New Records is enabled, and updatedRecords only when Show Updated Records is enabled.
On the first recurrence with no stored cursor and no Look-back Date, the trigger sets the cursor to the current time and reports nothing. Later recurrences report records modified after the stored cursor.
Initial sync
An initial sync seeds a complete starting state rather than a change feed, so inputs that narrow which changes are reported would leave gaps in it: Additional Filter, Show New Records, and Show Updated Records are ignored while it runs. All three inputs take effect again from the next recurrence onward. Setting Look-back Date (in YYYY-MM-DD format) seeds the cursor from that date on the first recurrence instead of from the current time, and each record modified on or after it is seeded exactly once. A future date is rejected by validation. Leaving it empty starts from the first recurrence with no backfill.
The backfill window has no fixed upper bound: its query asks NetSuite for every record modified on or after the look-back date, and the trigger fetches all of them in that first recurrence. Once the cursor advances to the recurrence's own timestamp, later recurrences resume from that stored cursor. Because the cursor is the recurrence's own start time, a record modified while the sync is still draining can be reported again on the next recurrence. No field in the payload marks the handoff from backfill to incremental polling.
Record Type still applies throughout. The trigger has no page-size or field-selection input, so nothing else is suppressed.
Batching
Batching is enabled per flow on this trigger: each changed record is dispatched as its own execution, or grouped by the configured batch size. Batch size and batch concurrency can both be overridden per instance. Raising concurrency increases the request volume sent to NetSuite.
To turn it on, select the flow's trigger, open the Flow control tab, and switch on Enable Batching. Under Batch Size, keep Trigger default or choose Custom batch size. Batch Concurrency is optional; leave it blank for no batch-level limit.
Until batching is enabled the payload shape is unchanged: a downstream step reads payload.body.data.createdRecords and payload.body.data.updatedRecords. With batching on, those two arrays do not exist; each execution receives a flattened item of shape { changeType, record }, or an array of them when the batch size is greater than 1. Any step reading createdRecords or updatedRecords must be updated to read the flattened item before batching is enabled. Because batching is enabled per flow, this change is scoped to that flow and does not affect the component or other flows using the same trigger.
Notes
The query is built in the format lastmodifieddate AFTER {lastPolledAt}, and any additional filter conditions are appended to it. During an initial sync the query uses ON_OR_AFTER with the look-back date and no additional filter.
Example additional filters:
isinactive = 'F'- Only active recordssubsidiary.id = '2'- Records from a specific subsidiaryemail IS NOT NULL- Records with email addresses
See Record Collection Filtering documentation for complete filter syntax.
Returned Data
With batching off, the trigger returns all records created or modified since the last poll, split into createdRecords and updatedRecords. Each array is present only when the corresponding option is enabled. When no changes are detected, the arrays are empty and polledNoChanges is set to true.
Fields shown are representative. The full response object includes additional properties.
View example response (batching off)
{
"data": {
"createdRecords": [
{
"id": "456",
"entityid": "CUST-001",
"companyname": "Acme Corporation",
"email": "contact@acmecorp.example.com",
"phone": "555-0123",
"lastmodifieddate": "2026-01-23T10:30:00.000Z",
"datecreated": "2026-01-23T10:30:00.000Z",
"subsidiary": {
"id": "1",
"refName": "Parent Company"
}
}
],
"updatedRecords": [
{
"id": "457",
"entityid": "CUST-002",
"companyname": "Global Tech Inc",
"email": "info@globaltech.example.com",
"phone": "555-0456",
"lastmodifieddate": "2026-01-23T10:35:00.000Z",
"datecreated": "2026-01-22T14:20:00.000Z",
"subsidiary": {
"id": "1",
"refName": "Parent Company"
}
}
]
}
}
With batching on, the createdRecords and updatedRecords arrays are flattened into individual items. Each execution receives one such item, or an array of them when the batch size is greater than 1. The record is the NetSuite record object, carrying id, datecreated, lastmodifieddate, and its type-specific fields.
View example item (batching on)
{
"changeType": "updated",
"record": {
"id": "457",
"entityid": "CUST-002",
"companyname": "Global Tech Inc",
"email": "info@globaltech.example.com",
"phone": "555-0456",
"lastmodifieddate": "2026-01-23T10:35:00.000Z",
"datecreated": "2026-01-22T14:20:00.000Z",
"subsidiary": {
"id": "1",
"refName": "Parent Company"
}
}
}
Example Payload for New and Updated Records⤓
Data Sources
Select Record
Select a record from a list of records. | key: selectRecord | type: picklist
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Pagination | Page and page-size controls. | |
| Query | Query string to filter records. Use operators like START_WITH, EQUAL, CONTAIN. See Record Collection Filtering for details. | email START_WITH barbara |
| Record Field | The record field to use as the label for the picklist. If unspecified, the record ID is used. | |
| Record Type | Record type to perform the action against. |
Select SuiteQL
Execute a SuiteQL query to create a picklist. | key: selectSuiteQl | type: picklist
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Key Field | The field name from returned items to use as the key for the picklist. | id |
| Label Field | The field name from returned items to use as the label for the picklist. | |
| Pagination | Page and page-size controls. | |
| SuiteQL Payload | SuiteQL query string to execute. See Executing SuiteQL Queries for details. |
Actions
Create Record
Create record of specified type. | key: createRecord
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Payload | Data payload to send in the action request. See REST API Browser for details. | |
| Record Type | Record type to perform the action against. |
Example Payload for Create Record⤓
Delete Record
Delete record of the specified type. | key: deleteRecord
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Record ID | The internal ID of the record. For external IDs, use the format 'eid:YOUR_EXTERNAL_ID'. See Getting a Record Instance for details. | 107 |
| Record Type | Record type to perform the action against. |
Example Payload for Delete Record⤓
Get Record
Get record of specified type. | key: getRecord
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Expand Sub-Resources | When true, automatically expands all sublists, sublist lines, and subrecords on this record. | false |
| Fields to Return | Specific fields and sublists to return in the request. If unspecified, the full record is returned. | ["email", "companyname", "subsidiary"] |
| Record ID | The internal ID of the record. For external IDs, use the format 'eid:YOUR_EXTERNAL_ID'. See Getting a Record Instance for details. | 107 |
| Record Type | Record type to perform the action against. | |
| Simple Enum Format | When true, returns enumeration values in a format that only shows the internal ID value. | false |
Example Payload for Get Record⤓
List Records
List records of specified type. | key: listRecord
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Pagination | Page and page-size controls. | |
| Query | Query string to filter records. Use operators like START_WITH, EQUAL, CONTAIN. See Record Collection Filtering for details. | email START_WITH barbara |
| Record Type | Record type to perform the action against. |
Example Payload for List Records⤓
Raw Request
Send raw HTTP request to NetSuite. | key: rawRequest
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Data | The HTTP body payload to send to the URL. | {"exampleKey": "Example Data"} |
| File Data | File Data to be sent as a multipart form upload. | [{key: "example.txt", value: "My File Contents"}] |
| File Data File Names | File names to apply to the file data inputs. Keys must match the file data keys above. | |
| Form Data | The Form Data to be sent as a multipart form upload. | [{"key": "Example Key", "value": new Buffer("Hello World")}] |
| Header | A list of headers to send with the request. | User-Agent: curl/7.64.1 |
| Max Retry Count | The maximum number of retries to attempt. Specify 0 for no retries. | 0 |
| Method | The HTTP method to use. | |
| Query Parameter | A list of query parameters to send with the request. This is the portion at the end of the URL similar to ?key1=value1&key2=value2. | |
| Response Type | The type of data you expect in the response. You can request json, text, or binary data. | json |
| Retry On All Errors | If true, retries on all erroneous responses regardless of type. This is helpful when retrying after HTTP 429 or other 3xx or 4xx errors. Otherwise, only retries on HTTP 5xx and network errors. | false |
| Retry Delay (ms) | The delay in milliseconds between retries. This is used when 'Use Exponential Backoff' is disabled. | 0 |
| Service Type | Selects which NetSuite REST service the request targets: the record service for CRUD operations, or the query service for SuiteQL. | record |
| Timeout | The maximum time that a client will await a response to its request | 2000 |
| URL | The request path only, relative to the base URL. The base URL is supplied automatically from the connection and the selected Service Type (https://{accountId}.suitetalk.api.netsuite.com/services/rest/record/v1 or .../query/v1). For example, enter /contact to reach the contact record endpoint. | /contact |
| Use Exponential Backoff | Specifies whether to use a pre-defined exponential backoff strategy for retries. When enabled, 'Retry Delay (ms)' is ignored. | false |
Example Payload for Raw Request⤓
SuiteQL Query
Execute a SuiteQL query through NetSuite's REST Web Services. | key: suiteQLQuery
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Pagination | Page and page-size controls. | |
| SuiteQL Payload | SuiteQL query string to execute. See Executing SuiteQL Queries for details. |
Example Payload for SuiteQL Query⤓
Update Record
Update record of the specified type. | key: updateRecord
| Input | Notes | Example |
|---|---|---|
| Connection | The NetSuite connection to use. | |
| Record ID | The internal ID of the record. For external IDs, use the format 'eid:YOUR_EXTERNAL_ID'. See Getting a Record Instance for details. | 107 |
| Payload | Data payload to send in the action request. See REST API Browser for details. | |
| Record Type | Record type to perform the action against. | |
| Replace | Names of sublists on this record. All specified sublists will be replaced instead of added to. | ["itemList", "addressbookList"] |
| Replace Selected Fields | When true, deletes all fields, including body fields, specified in the Replace input. | false |
Example Payload for Update Record⤓
Changelog
2026-09-22
- Added inline action calling support to the Get Record, List Records, Create Record, Update Record, Delete Record, and SuiteQL Query actions for improved example output during configuration
- Added output schemas to the Get Record and SuiteQL Query actions for improved field mapping during configuration
- Added opt-in batching to the New and Updated Records trigger, dispatching each changed record individually or in configured batches so large backlogs drain in one recurrence; enabling it changes the shape a downstream step receives
- Added an optional Look-back Date input for performing an initial sync of records on the New and Updated Records trigger. The initial sync backfills every record modified on or after the specified date, seeding each once and ignoring the field and visibility filters; later recurrences are unaffected. Leave it empty to start from the first recurrence with no backfill
2026-08-11
Restructured pagination inputs into structured objects and added output schemas for an improved user experience
- The List Records and SuiteQL Query actions and the Select Record and Select SuiteQL data sources group their pagination inputs into a Pagination structured object
- Limit is now optional on those actions and data sources, defaulting to 1000 records per page when left blank
- Added output schemas to the Create Record, Update Record, and List Records actions for improved field mapping during configuration
2026-04-30
Updated spectral version
2026-03-24
Added PKCE (S256) support to the OAuth 2.0 Authorization Code connection to comply with NetSuite's upcoming mandatory PKCE requirement in 2027.1.
2026-01-23
Added New and Updated Records polling trigger to monitor for new and updated records with support for record type filtering and additional query conditions. Includes toggle controls to filter for only new records, only updated records, or both. Added component-wide global debug support, replacing per-action debug inputs for streamlined configuration.
2025-10-28
Enhanced record management actions to include response headers for improved API metadata access and debugging.
2025-10-20
Added comprehensive example payloads for all actions to enhance integration development and documentation.