ANS-0823 · WEB SERVICES & INTEGRATIONS

How to Configure Token Based Authentication (TBA) for NetSuite SOAP Web Services in Postman

Learn to set up a Postman environment with a pre-request script and SOAP header for secure NetSuite SuiteTalk API calls using HMAC-SHA256.

Short answer

To use Token Based Authentication (TBA) with NetSuite SuiteTalk web services in Postman, configure a pre-request script to generate a dynamic signature, nonce, and timestamp. Store authentication credentials as environment variables. The script will use HMAC-SHA256 to sign the request, ensuring secure communication. Include these dynamically generated values in the SOAP header for successful API calls.

Scenario

Organizations integrating with NetSuite via SuiteTalk web services often require secure authentication methods. When using Postman to test or develop these integrations, a common challenge is correctly implementing Token Based Authentication (TBA) to generate the necessary security headers for each request. This involves dynamically creating a signature, nonce, and timestamp to ensure the integrity and authenticity of API calls.

Solution

The implementation of Token Based Authentication (TBA) for NetSuite SuiteTalk web services in Postman involves configuring environment variables and a pre-request script to dynamically generate authentication parameters.

Important Note: While existing integrations using Token Based Authentication (TBA) will continue to function, NetSuite is deprecating TBA for new integrations as of 2027.1, recommending OAuth 2.0 instead for new SOAP and REST web services integrations. This guide outlines the TBA method for existing setups or specific legacy requirements.nn

  1. Configure Postman Environment Variables:n Create the following environment variables in Postman. The nonce, timestamp, and signature variables should be left blank as their values will be generated dynamically by the pre-request script.nn

    • accountIdn
    • consumerKeyn
    • tokenn
    • consumerSecretn
    • tokenSecretn
    • nonce (leave blank)n
    • timestamp (leave blank)n
    • signature (leave blank)nn
  2. Implement the Pre-Request Script:n Add the following JavaScript code to the "Pre-request Script" tab of your Postman request. This script generates a random nonce, a timestamp, and computes the HMAC-SHA256 signature using the provided credentials and dynamic values.nn

javascriptn    function generateRandomString(length) {n        var text = "";n        var possible = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";n        for(var i = 0; i < length; i++) {n            text += possible.charAt(Math.floor(Math.random() * possible.length));n        }n        return text;n    }nn    var nonce = generateRandomString(16);n    var timestamp = Math.floor(Date.now()/1000);n    var accountId = postman.getEnvironmentVariable("accountId");n    var consumerKey = postman.getEnvironmentVariable("consumerKey");n    var token = postman.getEnvironmentVariable("token");n    var consumerSecret = postman.getEnvironmentVariable("consumerSecret");n    var tokenSecret = postman.getEnvironmentVariable("tokenSecret");nn    var baseString = accountId + '&';n    baseString += consumerKey + '&';n    baseString += token + '&';n    baseString += nonce + '&';n    baseString += timestamp;nn    var key = consumerSecret + '&' + tokenSecret;n    var signature = CryptoJS.HmacSHA256(baseString, key).toString(CryptoJS.enc.Base64);nn    postman.setEnvironmentVariable("signature", signature);n    postman.setEnvironmentVariable("nonce", nonce);n    postman.setEnvironmentVariable("timestamp", timestamp);n

nn

  1. Construct the SOAP Header:n Include the following tokenPassport element within the ` section of your SOAP request body. The placeholders {{variableName}} will be automatically populated by Postman using the environment variables set by the pre-request script. Note the algorithm="HMAC-SHA256"` attribute.nn

xmln    <soapenv:Header>n    <tokenPassport xmlns="urn:messages_2017_1.platform.webservices.netsuite.com">n    <account>{{accountId}}</account>n    <consumerKey>{{consumerKey}}</consumerKey>n    <token>{{token}}</token>n    <nonce>{{nonce}}</nonce>n    <timestamp>{{timestamp}}</timestamp>n    <signature algorithm="HMAC-SHA256">{{signature}}</signature>n    </tokenPassport>n    </soapenv:Header>n

Expert NetSuite Support

Need help with this NetSuite issue?

Web Services & Integrations consulting and configuration support

Talk to a consultant