Set up your NetSuite connection
Last reviewed
Connecting NetSuite is a one-time technical job for an administrator. You enable the API features, create a read-only role, map CO2 Lab's certificate for OAuth 2.0, deploy a small read-only script, and hand back three identifiers. The role you build here is the exact boundary of what CO2 Lab can see, and nothing is ever written back to NetSuite.
Step 1
Enable the API features
- SuiteTalk (Web Services): REST Web Services
- Manage Authentication: OAuth 2.0
- Analytics: SuiteAnalytics Workbook
- Invoice access: Client SuiteScript and Server SuiteScript
Save. NetSuite may first ask you to accept the SuiteCloud Terms of Service.
Step 2
Create the integration record
- Name the integration CO2 Lab and leave its state enabled.
- Enable the Client Credentials (Machine to Machine) grant.
- Enable the REST Web Services scope.
- Enable the RESTlets scope.
- Save and copy the 64-character Client ID. Do not include the field label's trailing
ID.
CO2 Lab does not use the Consumer Secret shown on the confirmation page.
Step 3
Create the view-only role
- Name the role CO2 Lab Integration.
- Leave Web Services Only disabled, because enabling it blocks the RESTlet.
- Add the core ledger permissions:
Core permissions for the CO2 Lab integration role Subtab Permission and level Reason Setup Log in using OAuth 2.0 Access Tokens (Full) Authenticate the mapped integration identity Setup REST Web Services (Full) Query SuiteTalk REST Setup Manage Accounting Periods (View) Read period close status Reports SuiteAnalytics Workbook (Edit) Execute SuiteQL Lists Accounts (View) Read account codes, names and types Lists Vendors (View) Read vendor identity and permitted vendor metadata Lists Subsidiaries (View) Read the OneWorld structure and line subsidiary Lists Currency (View) Read currencies used by the account Lists Items (View) Read item and physical-quantity attributes where available Lists Locations (View) Read the location assigned to a line Lists Departments (View) Read the department assigned to a line Lists Classes (View) Read the class assigned to a line Transactions Bills (View) Read vendor bills Transactions Enter Vendor Credits (View) Read vendor credits SuiteAnalytics Workbook requires Edit to run SuiteQL. It does not permit transaction changes.
- Add the document-access permissions, which let CO2 Lab read the invoice files behind your bills:
Document-access permissions for the CO2 Lab integration role Subtab Permission and level Reason Setup SuiteScript (View) Run the read-only attachment RESTlet Lists Documents and Files (View) Read permitted File Cabinet files Lists Messages (View) Find files attached through transaction messages Lists Perform Search (View) Search transaction-to-file links Transactions Find Transaction (View) Find the source transaction for a file - On OneWorld, set the role's Subsidiary Restrictions to
Selectedand add each in-scope subsidiary.
Two of these permissions grant less than their names suggest:
| Permission | What it grants | What actually bounds it |
|---|---|---|
Subsidiaries (View) | Opens the list of subsidiary records. It does not expose their transactions. | Subsidiary Restrictions, a separate field on the role. Set to Selected, the role reads data only for the subsidiaries an administrator has picked. |
Documents and Files (View) | Reads the files the role is permitted to see. It cannot upload or edit. | File Cabinet folder controls. A folder marked private, or restricted to a group or subsidiary, stays hidden from the role. |
Step 5
Map the certificate
Select Create New.
- For Entity, select the user from step 4.
- For Role, select the CO2 Lab Integration role.
- For Application, select the CO2 Lab integration record.
- For Certificate, upload the public certificate supplied by CO2 Lab.
- Save, then copy the Certificate ID.
Do not send CO2 Lab a private key or NetSuite password.
Step 6
Deploy the file-fetch script
CO2 Lab reads each invoice PDF through the read-only RESTlet from step 2. It only searches and loads files. It never creates, edits or deletes anything, and it runs under the same read-only role.
- Upload
netsuite-file-fetch.js(supplied by CO2 Lab) to the File Cabinet, usually the SuiteScripts folder. Keep the.jsfile name. - Create the script record. In the ID field, type
_co2lab_filefetch. NetSuite adds thecustomscriptprefix on save, givingcustomscript_co2lab_filefetch. - Add a deployment the same way for
customdeploy_co2lab_filefetch, with status Released and the CO2 Lab Integration role in its audience.
The fixed IDs mean there is nothing extra to send CO2 Lab. Full source is available for review, and a signed SDF bundle on request.
Step 7
Send the connection identifiers
Send CO2 Lab these values:
- Account ID
- Setup → Company → Company Information
- Client ID
- Created with the integration record in step 2
- Certificate ID
- Created with the certificate mapping in step 5
On a sandbox, the Account ID uses an uppercase suffix with an underscore, for example 1234567_SB1. If Company Information shows the hyphen form 1234567-sb1, convert it to the underscore form.
These identifiers cannot grant access without the private key and active mapping.
Step 8
Test and reconcile
CO2 Lab runs four checks before the connection is accepted:
- NetSuite issues an OAuth 2.0 access token.
- The role can read the chart of accounts and configured subsidiaries.
- A bounded reporting period returns posted ledger lines.
- The imported total is compared with the equivalent NetSuite report.