{"id":2562,"date":"2017-09-19T19:15:58","date_gmt":"2017-09-19T19:15:58","guid":{"rendered":"https:\/\/answers.gurussolutions.com\/answers\/comment-configurer-lauthentification-par-jeton-tba-pour-les-services-web-soap-netsuite-dans-postman\/"},"modified":"2026-07-28T18:25:01","modified_gmt":"2026-07-28T18:25:01","slug":"comment-configurer-lauthentification-par-jeton-tba-pour-les-services-web-soap-netsuite-dans-postman","status":"publish","type":"qa_entry","link":"https:\/\/answers.gurussolutions.com\/fr\/answers\/comment-configurer-lauthentification-par-jeton-tba-pour-les-services-web-soap-netsuite-dans-postman\/","title":{"rendered":"Comment configurer l&rsquo;authentification par jeton (TBA) pour les services Web SOAP NetSuite dans Postman"},"content":{"rendered":"","protected":false},"template":"","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","ga_subtitle":"Apprenez \u00e0 configurer un environnement Postman avec un script de pr\u00e9-requ\u00eate et un en-t\u00eate SOAP pour effectuer des appels s\u00e9curis\u00e9s \u00e0 l'API NetSuite SuiteTalk \u00e0 l'aide de HMAC-SHA256.","ga_short_answer":"Pour utiliser l\u2019authentification par jeton (TBA) avec les services Web NetSuite SuiteTalk dans Postman, configurez un script de pr\u00e9-requ\u00eate afin de g\u00e9n\u00e9rer une signature dynamique, un nonce et un horodatage. Enregistrez les identifiants d\u2019authentification sous forme de variables d\u2019environnement. Le script utilisera HMAC-SHA256 pour signer la requ\u00eate, garantissant ainsi une communication s\u00e9curis\u00e9e. Int\u00e9grez ces valeurs g\u00e9n\u00e9r\u00e9es dynamiquement dans l\u2019en-t\u00eate SOAP pour que les appels API aboutissent.","ga_scenario":"Les organisations qui s'int\u00e8grent \u00e0 NetSuite via les services Web SuiteTalk ont souvent besoin de m\u00e9thodes d'authentification s\u00e9curis\u00e9es. Lors de l\u2019utilisation de Postman pour tester ou d\u00e9velopper ces int\u00e9grations, l\u2019un des d\u00e9fis courants consiste \u00e0 mettre en \u0153uvre correctement l\u2019authentification par jeton (TBA) afin de g\u00e9n\u00e9rer les en-t\u00eates de s\u00e9curit\u00e9 n\u00e9cessaires pour chaque requ\u00eate. Cela implique la cr\u00e9ation dynamique d\u2019une signature, d\u2019un nonce et d\u2019un horodatage pour garantir l\u2019int\u00e9grit\u00e9 et l\u2019authenticit\u00e9 des appels API.","ga_solution":"La mise en \u0153uvre de l\u2019authentification par jeton (TBA) pour les services Web NetSuite SuiteTalk dans Postman implique la configuration de variables d\u2019environnement et d\u2019un script de pr\u00e9-requ\u00eate afin de g\u00e9n\u00e9rer dynamiquement les param\u00e8tres d\u2019authentification.\n\nRemarque importante : bien que les int\u00e9grations existantes utilisant l\u2019authentification par jeton (TBA) continuent de fonctionner, NetSuite d\u00e9pr\u00e9cie la TBA pour les nouvelles int\u00e9grations \u00e0 compter de la version 2027.1, et recommande \u00e0 la place OAuth 2.0 pour les nouvelles int\u00e9grations de services Web SOAP et REST. Ce guide pr\u00e9sente la m\u00e9thode TBA pour les configurations existantes ou les exigences h\u00e9rit\u00e9es sp\u00e9cifiques.nn\n1. Configurer les variables d\u2019environnement dans Postman :n    Cr\u00e9ez les variables d\u2019environnement suivantes dans Postman. Les variables `nonce`, `timestamp` et `signature` doivent \u00eatre laiss\u00e9es vides, car leurs valeurs seront g\u00e9n\u00e9r\u00e9es dynamiquement par le script de pr\u00e9-requ\u00eate.nn    *   GA_KEEP_0004n    *   GA_KEEP_0005n    *   GA_KEEP_0006n    *   GA_KEEP_0007n    *   GA_KEEP_0008n    *   `nonce` (laisser vide)n    *   `timestamp` (laisser vide)n    *   `signature` (laisser vide)nn\n2. Mettez en \u0153uvre le script de pr\u00e9-requ\u00eate :n    Ajoutez le code JavaScript suivant dans l\u2019onglet \u00ab Pre-request Script \u00bb de votre requ\u00eate Postman. Ce script g\u00e9n\u00e8re un nonce al\u00e9atoire, un horodatage et calcule la signature HMAC-SHA256 \u00e0 l\u2019aide des identifiants fournis et des valeurs dynamiques.nn\n\n```\njavascriptn    function generateRandomString(length) {n        var text = \"\";n        var possible = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789\";n        for(var i = 0; i < length; i++) {n            text += possible.charAt(Math.floor(Math.random() * possible.length));n        }n        return text;n    }nn    var nonce = generateRandomString(16);n    var timestamp = Math.floor(Date.now()\/1000);n    var accountId = postman.getEnvironmentVariable(\"accountId\");n    var consumerKey = postman.getEnvironmentVariable(\"consumerKey\");n    var token = postman.getEnvironmentVariable(\"token\");n    var consumerSecret = postman.getEnvironmentVariable(\"consumerSecret\");n    var tokenSecret = postman.getEnvironmentVariable(\"tokenSecret\");nn    var baseString = accountId + '&';n    baseString += consumerKey + '&';n    baseString += token + '&';n    baseString += nonce + '&';n    baseString += timestamp;nn    var key = consumerSecret + '&' + tokenSecret;n    var signature = CryptoJS.HmacSHA256(baseString, key).toString(CryptoJS.enc.Base64);nn    postman.setEnvironmentVariable(\"signature\", signature);n    postman.setEnvironmentVariable(\"nonce\", nonce);n    postman.setEnvironmentVariable(\"timestamp\", timestamp);n\n```\n\nnn\n3. Cr\u00e9ez l\u2019en-t\u00eate SOAP :n    Int\u00e9grez l\u2019\u00e9l\u00e9ment `tokenPassport` suivant dans la section `<soapenv:Header>` du corps de votre requ\u00eate SOAP. Les espaces r\u00e9serv\u00e9s `{{variableName}}` seront automatiquement renseign\u00e9s par Postman \u00e0 l\u2019aide des variables d\u2019environnement d\u00e9finies par le script de pr\u00e9-requ\u00eate. Veuillez noter l\u2019attribut `algorithm=\"HMAC-SHA256\"`.nn\n\n```\nxmln    <soapenv:Header>n    <tokenPassport xmlns=\"urn:messages_2017_1.platform.webservices.netsuite.com\">n    <account>{{accountId}}<\/account>n    <consumerKey>{{consumerKey}}<\/consumerKey>n    <token>{{token}}<\/token>n    <nonce>{{nonce}}<\/nonce>n    <timestamp>{{timestamp}}<\/timestamp>n    <signature algorithm=\"HMAC-SHA256\">{{signature}}<\/signature>n    <\/tokenPassport>n    <\/soapenv:Header>n\n```","ga_source_author":"Riley Van Ryswyk","ga_source_author_email":"","ga_date_original":"2017-09-19T12:15:58-07:00","ga_date_verified":"2026-07-05","ga_source_subject":"How to use Token Based Authentication (TBA) with Suitetalk \/ Webservices in Postman?","ga_ans_id":"ANS-0823","ga_publish_decision":"publish_with_edits","ga_staleness_risk":"high","ga_review_priority":"verify_soon","ga_tier2_verdict":"partially_outdated","ga_tier2_concerns":"The signature algorithm 'HMAC-SHA1' specified in the sample SOAP Header and used in the Pre-Request Script (CryptoJS.HmacSHA1) is deprecated and no longer supported; it should be 'HMAC-SHA256'.; While existing integrations using Token Based Authentication (TBA) will continue to function, NetSuite is deprecating TBA for new integrations as of 2027.1, recommending OAuth 2.0 instead for new SOAP and REST web services integrations.","ga_final_category":"Web Services & Integrations","footnotes":""},"ga_category":[102,28,102],"ga_audience":[10],"ga_difficulty":[92],"class_list":["post-2562","qa_entry","type-qa_entry","status-publish","hentry","ga_category-services-web-et-integrations","ga_category-web-services-integrations","ga_audience-developer-suitescript","ga_difficulty-niveau-intermediaire"],"taxonomy_info":{"ga_category":[{"value":102,"label":"Services Web et int\u00e9grations"},{"value":28,"label":"Web Services & Integrations"},{"value":102,"label":"Services Web et int\u00e9grations"}],"ga_audience":[{"value":10,"label":"Developer\/SuiteScript"}],"ga_difficulty":[{"value":92,"label":"Niveau interm\u00e9diaire"}]},"featured_image_src_large":[],"author_info":[],"comment_info":"","_links":{"self":[{"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/qa_entry\/2562","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/qa_entry"}],"about":[{"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/types\/qa_entry"}],"version-history":[{"count":1,"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/qa_entry\/2562\/revisions"}],"predecessor-version":[{"id":4482,"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/qa_entry\/2562\/revisions\/4482"}],"wp:attachment":[{"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/media?parent=2562"}],"wp:term":[{"taxonomy":"ga_category","embeddable":true,"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/ga_category?post=2562"},{"taxonomy":"ga_audience","embeddable":true,"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/ga_audience?post=2562"},{"taxonomy":"ga_difficulty","embeddable":true,"href":"https:\/\/answers.gurussolutions.com\/fr\/wp-json\/wp\/v2\/ga_difficulty?post=2562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}