sadehdocs

Connect your tools

Connect NetSuite

Connect NetSuite for your whole workspace with a guided setup that uses a certificate. A Sadeh admin and a NetSuite administrator each do their part.

Connect NetSuite with the guided certificate setupClick the highlighted spot to move to the next step.

Before you start

  • In Sadeh, you need to be a workspace owner or admin. NetSuite is connected once for the whole workspace.
  • In NetSuite, you need an administrator for the setup steps. Creating the certificate mapping needs an administrator or the OAuth 2.0 Authorized Applications Management permission.

Sadeh connects with OAuth 2.0 client credentials and a certificate that Sadeh creates. The private key never leaves Sadeh; your administrator uploads only the public certificate.

Step 1: Prepare NetSuite

In Sadeh, open Integrations, find NetSuite and click Connect. The first step lists what your NetSuite administrator does. Click Copy admin instructions to send it to them.

  1. Under Setup → Company → Enable Features, enable REST Web Services and OAuth 2.0 on the SuiteCloud tab, and SuiteAnalytics Workbook on the Analytics tab.
  2. Give the integration user a dedicated role with REST Web Services (Full), Log in using OAuth 2.0 Access Tokens (Full) and SuiteAnalytics Workbook (Edit). Give it access to the customers, items, sales orders and invoices your team needs. Keep this role separate from the setup administrator.
  3. Create an integration in Setup → Integration → Manage Integrations → New. Enable Client Credentials (Machine to Machine) Grant and REST Web Services. Save the client ID shown when you create it.

Then click Create certificate.

Step 2: Certificate and account

Hand over the certificate

Sadeh creates a certificate that's valid for one year. Click Download certificate and give the file to your NetSuite administrator. They:

  1. Open Setup → Integration → Manage Authentication → OAuth 2.0 Client Credentials (M2M) Setup and create a mapping.
  2. Select the integration user, the role and the integration from step 1, and upload the certificate.
  3. Save and send you the certificate ID.

Enter the IDs

Field Where to find it
Account ID Setup → Company → Company Information, for example 1234567 or 1234567_SB1 for a sandbox. You can also paste your NetSuite URL.
Client ID The integration record from step 1.
Certificate ID The mapping from step 2.

Copy them exactly as NetSuite shows them. If you're still waiting for the certificate ID from your administrator, you can close the setup. Sadeh keeps the certificate, and the setup reopens at this step. You'll need to enter the other IDs again. Once all three IDs are filled in, Save for later saves them without running the check.

Step 3: Check access and connect

Click Check connection. Sadeh signs in with the certificate and runs a few read-only checks: Authentication, SuiteQL, Customers, Inventory, Sales orders and Invoices. The results reflect what the role can read. Nothing is connected yet.

  • Ready to connect: everything passed. Click Connect workspace.
  • Some access needs attention: some checks failed, but you can still connect. Ask your administrator to review the role's permissions for the items marked Permission needed.
  • Connection needs attention: sign-in or SuiteQL failed, or the role couldn't read any of Customers, Inventory, Sales orders or Invoices. If Authentication or SuiteQL failed, check the IDs and the mapping. If the business checks show Permission needed, ask your administrator to review the role's permissions. Then click Check again. You also see this heading when more than 15 minutes have passed since the last check, or when the certificate has expired (see below).

Connect within 15 minutes of a passing check. After that, run the check again first.

After connecting

The card shows Team and a Manage connection button. Use Who can use it to choose Everyone, Admins & owners or Owners only. Everyone uses the access of the role you set up.

Your team can then ask Sadeh about customers, stock by location, open orders and quotes, open invoices, balances and overdue receivables. Sadeh can also create sales orders and quotes. These wait for your approval, unless you chose Always allow for that kind of action. Your account may require subsidiary, location or custom fields that this integration doesn't collect yet. The Invoice overdue Watchlist is available for NetSuite.

Early support

Sadeh's NetSuite connection hasn't been verified with a live customer account yet. This includes creating sales orders and quotes. If an answer or action doesn't match what you see in NetSuite, contact support@sadeh.ai.

Renew or replace the certificate

The certificate lasts a year. When you open Manage connection within 30 days of the expiry date, Sadeh reminds you to replace it. Click Replace certificate, then Create certificate, and repeat steps 2 and 3. At the end, click Use this connection instead of Connect workspace. Your current connection keeps working until you switch to the new one; afterwards your administrator can remove the old mapping in NetSuite.

Sandboxes

Set up sandbox accounts separately. A sandbox refresh clears its certificate mappings, so you'll need to map the certificate again.

If something goes wrong

You see What to do
Check the account ID or NetSuite URL and the client and certificate IDs. Copy the IDs again exactly as NetSuite shows them.
Check the account, application and certificate mapping in NetSuite, then retry. Ask your administrator to check the mapping's user, role and integration.
This certificate has expired. Create a replacement certificate and ask your administrator to add a new mapping.
Run Check again to verify the current account and certificate details before connecting. More than 15 minutes passed since the check, or the details changed since then. Click Check again.

Your NetSuite administrator can also use Oracle's guide to OAuth 2.0 client credentials, linked from For your NetSuite administrator in the setup.

Token-based authentication

Sadeh still supports token-based authentication (TBA) for existing setups. Before anything is connected, click Use token credentials instead on the first step and enter the account ID, the consumer key and secret, and the token ID and secret.