ANS-0823 · WEB SERVICES & INTEGRATIONS
How to Configure Token Based Authentication (TBA) for NetSuite SOAP Web Services in Postman
Learn to set up a Postman environment with a pre-request script and SOAP header for secure NetSuite SuiteTalk API calls using HMAC-SHA256.
Short answer
To use Token Based Authentication (TBA) with NetSuite SuiteTalk web services in Postman, configure a pre-request script to generate a dynamic signature, nonce, and timestamp. Store authentication credentials as environment variables. The script will use HMAC-SHA256 to sign the request, ensuring secure communication. Include these dynamically generated values in the SOAP header for successful API calls.
Scenario
Organizations integrating with NetSuite via SuiteTalk web services often require secure authentication methods. When using Postman to test or develop these integrations, a common challenge is correctly implementing Token Based Authentication (TBA) to generate the necessary security headers for each request. This involves dynamically creating a signature, nonce, and timestamp to ensure the integrity and authenticity of API calls.
Solution
The implementation of Token Based Authentication (TBA) for NetSuite SuiteTalk web services in Postman involves configuring environment variables and a pre-request script to dynamically generate authentication parameters.
Important Note: While existing integrations using Token Based Authentication (TBA) will continue to function, NetSuite is deprecating TBA for new integrations as of 2027.1, recommending OAuth 2.0 instead for new SOAP and REST web services integrations. This guide outlines the TBA method for existing setups or specific legacy requirements.nn
Configure Postman Environment Variables:n Create the following environment variables in Postman. The
nonce,timestamp, andsignaturevariables should be left blank as their values will be generated dynamically by the pre-request script.nnaccountIdnconsumerKeyntokennconsumerSecretntokenSecretnnonce(leave blank)ntimestamp(leave blank)nsignature(leave blank)nn
Implement the Pre-Request Script:n Add the following JavaScript code to the "Pre-request Script" tab of your Postman request. This script generates a random nonce, a timestamp, and computes the HMAC-SHA256 signature using the provided credentials and dynamic values.nn
javascriptn function generateRandomString(length) {n var text = "";n var possible = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789";n for(var i = 0; i < length; i++) {n text += possible.charAt(Math.floor(Math.random() * possible.length));n }n return text;n }nn var nonce = generateRandomString(16);n var timestamp = Math.floor(Date.now()/1000);n var accountId = postman.getEnvironmentVariable("accountId");n var consumerKey = postman.getEnvironmentVariable("consumerKey");n var token = postman.getEnvironmentVariable("token");n var consumerSecret = postman.getEnvironmentVariable("consumerSecret");n var tokenSecret = postman.getEnvironmentVariable("tokenSecret");nn var baseString = accountId + '&';n baseString += consumerKey + '&';n baseString += token + '&';n baseString += nonce + '&';n baseString += timestamp;nn var key = consumerSecret + '&' + tokenSecret;n var signature = CryptoJS.HmacSHA256(baseString, key).toString(CryptoJS.enc.Base64);nn postman.setEnvironmentVariable("signature", signature);n postman.setEnvironmentVariable("nonce", nonce);n postman.setEnvironmentVariable("timestamp", timestamp);nnn
Construct the SOAP Header:n Include the following
tokenPassportelement within the `section of your SOAP request body. The placeholders{{variableName}}will be automatically populated by Postman using the environment variables set by the pre-request script. Note thealgorithm="HMAC-SHA256"` attribute.nn
xmln <soapenv:Header>n <tokenPassport xmlns="urn:messages_2017_1.platform.webservices.netsuite.com">n <account>{{accountId}}</account>n <consumerKey>{{consumerKey}}</consumerKey>n <token>{{token}}</token>n <nonce>{{nonce}}</nonce>n <timestamp>{{timestamp}}</timestamp>n <signature algorithm="HMAC-SHA256">{{signature}}</signature>n </tokenPassport>n </soapenv:Header>nExpert NetSuite Support
Need help with this NetSuite issue?
Web Services & Integrations consulting and configuration support
