ANS-1466 · WEB SERVICES & INTEGRATIONS

How to Resolve ‘Invalid Login Attempt’ for NetSuite Sandbox TBA Web Services?

When connecting to a NetSuite sandbox via web services using Token-Based Authentication, ensure the account ID (realm) is correctly formatted to prevent login failures.

Short answer

The 'Invalid Login Attempt' error when connecting to a NetSuite sandbox via web services with TBA often stems from an incorrect account ID format. For sandbox accounts, the realm must be `{accountId}_SB#` and is case-sensitive. Correcting this specific format in the tokenPassport XML typically resolves the 'Invalid Signature' detail.

Scenario

Users attempting to connect to a NetSuite sandbox account via web services using Token-Based Authentication (TBA) encounter an 'invalid login attempt' error. The Login Audit Trail details 'Invalid Signature', even when all other authentication parameters like tokens, secret keys, timestamp, nonce, and signature algorithm appear to be correct.

Solution

The 'Invalid Login Attempt' error, particularly when accompanied by an 'Invalid Signature' detail in the Login Audit Trail, often indicates an incorrect account ID (realm) format for sandbox connections.When connecting to a NetSuite sandbox account via web services, the account ID (realm) must adhere to a specific, case-sensitive format:

{accountId}_SB#

For example: 1234567_SB1

The tokenPassport XML structure should reflect this format, as shown below:

xml
<tokenPassport xsi:type="platformCore:TokenPassport">
            <account xsi:type="xsd:string">1234567_SB1</account>
            <consumerKey xsi:type="xsd:string">****************************************************************</consumerKey>
            <token xsi:type="xsd:string">****************************************************************</token>
            <nonce xsi:type="xsd:string">MTU1ODcxNDQ3Mw</nonce>
            <timestamp xsi:type="xsd:long">1558714473</timestamp>
            <signature xsi:type="platformCore:TokenPassportSignature" algorithm="HMAC_SHA256">********************************************</signature>
</tokenPassport>

It is important to note that the account ID returned by runtime.accountId and the account ID found in the URL use a different format: {accountId}-sb#.

Expert NetSuite Support

Need help with this NetSuite issue?

Web Services & Integrations consulting and configuration support

Talk to a consultant