Book a Check-up
For IT and admins

Set up your NetSuite connection

Last reviewed

Connecting NetSuite is a one-time technical job for an administrator. You enable the API features, create a read-only role, map CO2 Lab's certificate for OAuth 2.0, deploy a small read-only script, and hand back three identifiers. The role you build here is the exact boundary of what CO2 Lab can see, and nothing is ever written back to NetSuite.

Step 1

Enable the API features

In NetSuiteSetup → Company → Enable Features → SuiteCloud
  • SuiteTalk (Web Services): REST Web Services
  • Manage Authentication: OAuth 2.0
  • Analytics: SuiteAnalytics Workbook
  • Invoice access: Client SuiteScript and Server SuiteScript

Save. NetSuite may first ask you to accept the SuiteCloud Terms of Service.

Step 2

Create the integration record

In NetSuiteSetup → Integration → Manage Integrations → New
  1. Name the integration CO2 Lab and leave its state enabled.
  2. Enable the Client Credentials (Machine to Machine) grant.
  3. Enable the REST Web Services scope.
  4. Enable the RESTlets scope.
  5. Save and copy the 64-character Client ID. Do not include the field label's trailing ID.

CO2 Lab does not use the Consumer Secret shown on the confirmation page.

Step 3

Create the view-only role

In NetSuiteSetup → Users/Roles → Manage Roles → New
  1. Name the role CO2 Lab Integration.
  2. Leave Web Services Only disabled, because enabling it blocks the RESTlet.
  3. Add the core ledger permissions:
    Core permissions for the CO2 Lab integration role
    SubtabPermission and levelReason
    SetupLog in using OAuth 2.0 Access Tokens (Full)Authenticate the mapped integration identity
    SetupREST Web Services (Full)Query SuiteTalk REST
    SetupManage Accounting Periods (View)Read period close status
    ReportsSuiteAnalytics Workbook (Edit)Execute SuiteQL
    ListsAccounts (View)Read account codes, names and types
    ListsVendors (View)Read vendor identity and permitted vendor metadata
    ListsSubsidiaries (View)Read the OneWorld structure and line subsidiary
    ListsCurrency (View)Read currencies used by the account
    ListsItems (View)Read item and physical-quantity attributes where available
    ListsLocations (View)Read the location assigned to a line
    ListsDepartments (View)Read the department assigned to a line
    ListsClasses (View)Read the class assigned to a line
    TransactionsBills (View)Read vendor bills
    TransactionsEnter Vendor Credits (View)Read vendor credits

    SuiteAnalytics Workbook requires Edit to run SuiteQL. It does not permit transaction changes.

  4. Add the document-access permissions, which let CO2 Lab read the invoice files behind your bills:
    Document-access permissions for the CO2 Lab integration role
    SubtabPermission and levelReason
    SetupSuiteScript (View)Run the read-only attachment RESTlet
    ListsDocuments and Files (View)Read permitted File Cabinet files
    ListsMessages (View)Find files attached through transaction messages
    ListsPerform Search (View)Search transaction-to-file links
    TransactionsFind Transaction (View)Find the source transaction for a file
  5. On OneWorld, set the role's Subsidiary Restrictions to Selected and add each in-scope subsidiary.

Two of these permissions grant less than their names suggest:

Permissions whose real boundary is a separate NetSuite control
PermissionWhat it grantsWhat actually bounds it
Subsidiaries (View)Opens the list of subsidiary records. It does not expose their transactions.Subsidiary Restrictions, a separate field on the role. Set to Selected, the role reads data only for the subsidiaries an administrator has picked.
Documents and Files (View)Reads the files the role is permitted to see. It cannot upload or edit.File Cabinet folder controls. A folder marked private, or restricted to a group or subsidiary, stays hidden from the role.

Step 4

Assign the role to a NetSuite user

Add the role to the employee who will own the certificate mapping. You can use an existing licensed user. A dedicated user may require another licence.

Step 5

Map the certificate

In NetSuiteSetup → Integration → Manage Authentication → OAuth 2.0 Client Credentials (M2M) Setup

Select Create New.

  1. For Entity, select the user from step 4.
  2. For Role, select the CO2 Lab Integration role.
  3. For Application, select the CO2 Lab integration record.
  4. For Certificate, upload the public certificate supplied by CO2 Lab.
  5. Save, then copy the Certificate ID.

Do not send CO2 Lab a private key or NetSuite password.

Step 6

Deploy the file-fetch script

CO2 Lab reads each invoice PDF through the read-only RESTlet from step 2. It only searches and loads files. It never creates, edits or deletes anything, and it runs under the same read-only role.

  1. Upload netsuite-file-fetch.js (supplied by CO2 Lab) to the File Cabinet, usually the SuiteScripts folder. Keep the .js file name.
  2. Create the script record. In the ID field, type _co2lab_filefetch. NetSuite adds the customscript prefix on save, giving customscript_co2lab_filefetch.
  3. Add a deployment the same way for customdeploy_co2lab_filefetch, with status Released and the CO2 Lab Integration role in its audience.

The fixed IDs mean there is nothing extra to send CO2 Lab. Full source is available for review, and a signed SDF bundle on request.

Step 7

Send the connection identifiers

Send CO2 Lab these values:

Account ID
Setup → Company → Company Information
Client ID
Created with the integration record in step 2
Certificate ID
Created with the certificate mapping in step 5

On a sandbox, the Account ID uses an uppercase suffix with an underscore, for example 1234567_SB1. If Company Information shows the hyphen form 1234567-sb1, convert it to the underscore form.

These identifiers cannot grant access without the private key and active mapping.

Step 8

Test and reconcile

CO2 Lab runs four checks before the connection is accepted:

  1. NetSuite issues an OAuth 2.0 access token.
  2. The role can read the chart of accounts and configured subsidiaries.
  3. A bounded reporting period returns posted ledger lines.
  4. The imported total is compared with the equivalent NetSuite report.
A connected NetSuite account.

NetSuite references