ANS-1416 · SUITESCRIPT DEVELOPMENT
How to Securely Store and Use Secret Keys for Encryption in NetSuite APIs?
NetSuite provides mechanisms to securely manage and utilize sensitive secret keys for HMAC encryption in API calls, ensuring data integrity and authentication.
Short answer
To securely handle secret keys for HMAC encryption in NetSuite, avoid storing them in plain text. Instead, leverage NetSuite's secure storage options like API Secrets or credential fields (GUIDs) to retrieve and use keys with the N/crypto module for encryption.
Scenario
Organizations often need to use a secret key to HMAC encrypt a string, which is then passed as a header in an API call for security or authentication purposes. The challenge is securely storing and retrieving this sensitive key within NetSuite.
Solution
NetSuite does not store secrets in plain text on its servers. To securely manage and retrieve sensitive customer secrets, administrators can utilize NetSuite's API Secrets feature or create a GUID within a credential field. API Secrets provide a dedicated secure vault, while GUIDs from credential fields also allow NetSuite to retrieve the secret securely. The process involves two main steps:
Securely Store the Secret Key:
NetSuite recommends using API Secrets (Setup > Company > Preferences > API Secrets) for dedicated secure storage, referencing secrets by their script ID. Alternatively, a GUID can be generated and stored in a credential field, often managed via a Suitelet. When using a GUID, the parameter,
restrictToScriptIds, must include the IDs of any scripts authorized to use it. While specific external examples or internal repository names may vary, the core principle involves securely generating and storing a reference to the secret.Perform Encryption:
Once the secret key is securely stored and accessible, the N/crypto module can be used for encryption. The general steps for encryption are:
Retrieve the secret key using its secure reference (e.g., API Secret script ID or GUID).
Create the desired cipher, HMAC, or hash object and select the appropriate algorithm.
Feed the input string to the cipher, HMAC, or hash function.
Output the encrypted string.It is crucial to select the correct encoding at each stage of the process. Refer to the N/crypto module documentation for detailed examples and available functions.
Expert NetSuite Support
Need help with this NetSuite issue?
SuiteScript Development consulting and configuration support
