ANS-1767 · SUITESCRIPT DEVELOPMENT

nlapiRequestURL Content-Type and HTTPS Certificate Requirements

This article explains how NetSuite's nlapiRequestURL function handles content types and the necessary certificate validations for secure external integrations.

Short answer

The nlapiRequestURL function respects manually set Content-Type headers, including 'application/atom+xml', and supports 'PUT' and 'DELETE' HTTP methods. For HTTPS requests, external services must use valid certificates from CAs aligned with Microsoft's trusted root program; self-signed certificates are not supported.

Scenario

NetSuite developers integrating with external web services via the nlapiRequestURL function may encounter questions regarding how the function processes Content-Type headers for specific data formats. Additionally, understanding the requirements for valid HTTPS certificates is crucial for successful and secure communication with external endpoints.

Solution

The nlapiRequestURL function from the SuiteScript API respects the values manually set for the Content-Type header. This allows for successful posting of various content types, such as 'application/atom+xml', to external APIs. The function also supports additional HTTP actions, including 'PUT' and 'DELETE', which are essential for certain operations on various Web Service APIs. For requests to an HTTPS URL, the external service must have a valid and supported certificate. Self-signed certificates are not supported. The list of supported Certificate Authorities (CAs) aligns with Microsoft's trusted root certificate program participants.

Expert NetSuite Support

Need help with this NetSuite issue?

SuiteScript Development consulting and configuration support

Talk to a consultant