Connect to NetSuite
Data Hub connects to NetSuite through SuiteAnalytics Connect, NetSuite's service for accessing your account data outside of the NetSuite web interface. Data Hub supports two authentication methods: Token-Based Authentication (TBA) and OAuth 2.0. Complete the prerequisite tasks based on your requirement.
Note: Data Hub connects to NetSuite using the NetSuite2.com data source. The original NetSuite.com data source was removed in NetSuite 2026.1 and is no longer supported. If you are currently using a NetSuite.com-based connection, you need to migrate to NetSuite2.com.
Prerequisite Tasks
You need NetSuite administrator access to complete these steps.
Step 1: Enable SuiteAnalytics Connect
- In NetSuite, go to Setup > Company > Enable Features > Analytics.
- Select the checkbox for SuiteAnalytics Connect.
- Select Save.
Note: SuiteAnalytics Connect is an add-on feature and may not be included in your NetSuite subscription. If you do not see it listed, contact NetSuite customer support or your account manager.
For more information, see Enabling the SuiteAnalytics Connect Service Feature in the NetSuite documentation.
-
Step 2: Enable Token-Based Authentication (TBA)
- In NetSuite, go to Setup > Company > Enable Features > SuiteCloud > Manage Authentication.
- Select Token-Based Authentication.
- Select Save.
For more information, see Token-Based Authentication in the NetSuite documentation.
Step 3: Create an integration record
The integration record represents Data Hub in your NetSuite account and generates the consumer key and consumer secret needed for the connection.
- Go to Setup > Integrations > Manage Integrations.
- Select New.
- Enter a name for the integration. For example, Data Hub.
- In the Authentication tab, select Token-Based Authentication. Clear TBA: Issue Token Endpoint, TBA: Authorization Flow, OAuth 2.0 fields, and User Credentials.
- Select Save.
- Copy the Consumer Key and Consumer Secret values and store them securely.
Important: These values are displayed only once and cannot be retrieved after you leave this page.
For more information, see Create Integration Records for Applications to Use TBA in the NetSuite documentation.
Step 4: Create a role and assign permissions
You can use an existing role if it already has the required permissions, or create a new one.
- Go to Setup > User/Roles > Manage Roles > New.
- Enter a name for the role. For example, Data Hub Integration Role.
- On the Permissions tab, assign the following permissions:
Permission Type Level SuiteAnalytics Connect
Setup
Full
SuiteAnalytics Workbook
Reports
Edit
Custom Segments
Setup
View
Log in using Access Tokens
Setup
Full
REST Web Services
Setup
Full
- Select Save.
Note: The permissions above are required to establish the connection. Depending on the tables you want to replicate, you may need to assign additional permissions. For a full reference of available permissions by table, download the NetSuite Permissions Reference. The permissions available in your account depend on which modules are active.
For more information, see Requirements for Using Token-based Authentication in Connect in the NetSuite documentation.
Step 5: Assign the role to a user
- Go to Lists > Employees > Employees and open the user you want to use for the integration.
- Select the Access tab, then the Roles subtab.
- Add the role you created in step 4.
- Select Save.
For more information, see Assigning Roles to an Employee in the NetSuite documentation.
Step 6: Generate an access token
The access token generates the token ID and token secret needed for the connection.
- Go to Setup > User/Roles > Access Tokens > New.
- In the Application Name field, select the integration record you created in step 3.
- In the User field, select the integration user from step 5.
Note: If the user does not appear in the list, verify that the role has been assigned to the user and includes the required permissions.
- In the Role field, select the role from step 4.
- Select Save.
- Copy the Token ID and Token Secret values and store them securely.
Important: These values are displayed only once and cannot be retrieved after you leave this page.
For more information, see Setting Up Token-Based Authentication (TBA) - Tutorial in the NetSuite documentation.
-
Step 2: Enable OAuth 2.0
- In NetSuite, go to Setup > Company > Enable Features > SuiteCloud > Manage Authentication.
- Select OAuth 2.0.
- Select Save.
Step 3: Generate a private key and certificate
The private key and certificate let Data Hub authenticate with NetSuite without a stored password. You generate both files outside NetSuite, then upload the certificate.
This step uses OpenSSL, a tool for creating keys and certificates. Run it on a secure computer you trust with the private key, such as your own machine or a secure build server. You don't need to run it inside NetSuite or Data Hub.
Check whether OpenSSL is installed
- Open PowerShell, Command Prompt, or Git Bash.
- Run the following command:
openssl version
If OpenSSL is installed, this command returns a version number, for example,
OpenSSL 3.x.x. If it is not installed, the command returns an error such asopenssl is not recognized....Install OpenSSL (if needed)
Choose whichever option is easiest based on what is already on your computer:
Option How Notes Git for Windows
Open Git Bash, which includes OpenSSL.
Use this if Git is already installed. Run
git --versionto check.winget
Run
winget install FireDaemon.OpenSSLBuilt into Windows 10 and 11. Restart your terminal after installing.
Chocolatey
Run
choco install openssl -yUse this only if Chocolatey is already set up on your computer.
Official installer
Download and run the Win64 installer from Shining Light Productions.
Use this if package managers are not available on your computer.
After installing, open a new terminal window and run
openssl versionagain to confirm it works.Generate the key and certificate
- In your terminal, run the following command:
openssl req -x509 -newkey rsa:4096 -sha256 -keyout auth-key.pem -out auth-cert.pem -nodes -days 730 - This command creates two files:
File Purpose auth-key.pemYour private key. Never upload this file to NetSuite or share it with anyone. You will upload this file to Data Hub.
auth-cert.pemYour public certificate. You will upload this file to NetSuite.
Important: Store
auth-key.pemsomewhere secure, such as a password manager or secrets vault. Anyone with this file can authenticate as your integration.Note: The
-days 730value sets the certificate to expire after two years. Track this expiration date. Before it expires, you need to generate a new key and certificate and repeat the steps.Step 4: Create an integration record
The integration record represents Data Hub in your NetSuite account and generates the client ID needed for the connection.
- Go to Setup > Integration > Manage Integrations.
- Select New.
- Enter a name for the integration. For example, Data Hub.
- In the Authentication tab, select OAuth 2.0, then select Client Credentials (Machine to Machine) Grant. If Authorization Code Grant is selected, clear it.
- Under Scope, select SuiteAnalytics Connect.
- Select Save.
- Copy the Client ID and store it securely.
Important: This value is displayed only once and cannot be retrieved after you leave this page.
Step 5: Create a role and assign permissions
You can use an existing role if it already has the required permissions, or create a new one.
- Go to Setup > User/Roles > Manage Roles > New.
- Enter a name for the role. For example, Data Hub Integration Role.
- On the Permissions tab, assign the following permissions:
Permission Type Level SuiteAnalytics Connect
Setup
Full
SuiteAnalytics Workbook
Reports
Edit
Custom Segments
Setup
View
Log in using Access Tokens
Setup
Full
REST Web Services
Setup
Full
- Select Save.
Note: The permissions above are required to establish the connection. Depending on the tables you want to replicate, you may need to assign additional permissions. For a full reference of available permissions by table, download the NetSuite Permissions Reference. The permissions available in your account depend on which modules are active.
Step 6: Upload the certificate and assign a role
- Go to Setup > Integration > Manage Authentication > OAuth 2.0 Client Credentials (M2M) Setup.
- Select Create New.
- Upload the certificate file
auth-cert.pemfrom step 3. - Map the certificate to the role that will run this connection.
- Select Save.
- Copy the generated Certificate ID and store it alongside your Client ID.
Create a Connection
Once you have completed the prerequisites, you are ready to set up the connection in Data Hub.
- In Data Hub, go to Connections and select Add Connection in the top-right corner of the page.
- Search for and select NetSuite.
Basics Tab
Replication Environment: A replication environment is a dedicated infrastructure layer that Data Hub uses to extract and stage data from NetSuite. Your organization's default environment is selected. Select Set ERP to assign this environment to the NetSuite data source.
-
If you need to add a new environment, select Provision and complete the following fields:
Field Description Environment Name
A name for the environment as it will appear across Data Hub. For example, Production.
ERP
Defaults to NetSuite.
Hosting Region
The AWS region where replicated data will be stored. Defaults to US East (N. Virginia) based on your organization's region (NA). If your organization has data residency or compliance requirements, select the appropriate region before proceeding.
Select Start Provisioning. Provisioning may take up to 30 minutes. You will receive an email notification when provisioning completes or if it encounters an issue. Once complete, select Continue. The replicated data endpoint is created, and the environment is now available for selection.
Note: Each connection requires a dedicated replication environment. Once assigned, the environment is dedicated to that ERP and cannot be shared or reassigned. The number of connections you can create depends on your organization's subscription.
- Enter a Connection Name and an optional Description.
- Select Next.
Connect Tab
Fill in the following fields:
| Field | Description | Where to get it? |
|---|---|---|
Service Host |
The hostname used to connect to NetSuite. |
In NetSuite, go to Set Up SuiteAnalytics Connect. Use the format |
Account ID |
Your NetSuite account identifier. |
In NetSuite, go to Set Up SuiteAnalytics Connect. |
Auth Type |
Token-Based Authentication (TBA). Connects to NetSuite using a consumer key and secret, paired with a token ID and secret. |
Select the required option from the dropdown menu. |
Consumer Key |
The key generated when you created the integration record in NetSuite. |
Copy from the integration record in step 3 of the TBA prerequisites. |
Consumer Secret |
The secret paired with the consumer key. |
Copy from the integration record in step 3 of the TBA prerequisites. |
Token ID |
The token ID generated when you created the access token in NetSuite. |
Copy from the access token in step 6 of the TBA prerequisites. |
Token Secret |
The secret paired with the token ID. |
Copy from the access token in step 6 of the TBA prerequisites. |
Role ID |
The role ID from your NetSuite configuration. |
In NetSuite, go to Set Up SuiteAnalytics. You can also find it in the web address when logged into NetSuite. For example, |
Auth Type |
OAuth 2.0. Connects to NetSuite using a client ID and certificate. Data Hub requests a new access token automatically, so there's no token to store or manage. |
Select the required option from the dropdown menu. |
Client ID |
The ID generated when you created the integration record in NetSuite. |
Copy from the integration record in step 4 of the OAuth 2.0 prerequisites. |
Certificate ID |
The ID NetSuite assigns to your uploaded certificate. |
Copy from the uploaded certificate in step 6 of the OAuth 2.0 prerequisites. |
Private Key File |
The private key you generated locally. |
Upload the full contents of the |
Important: Ensure no extra spaces are copied from NetSuite into any of the fields above, as this will cause the connection to fail.
Select Test Connection to verify the connection, then select Next. A successful connection test is required before you can create the connection.
Advanced Tab
The following settings are pre-configured with required values. You only need to change them if your environment has specific requirements.
| Field | Description | Value |
|---|---|---|
Driver Path |
The file path to the NetSuite SuiteAnalytics ODBC driver. |
|
Port |
The port used to connect to the NetSuite SuiteAnalytics Connect service. |
|
Encrypted |
Controls whether the connection to NetSuite is encrypted. |
Enabled |
Trust Store |
The file path to the SSL certificate used to verify the NetSuite connection. |
|
Select Create Connection.
Your NetSuite data source is ready and appears on the Connections page. Data Hub creates predefined replication tasks once data is pulled in. See the Data Replication section for more information.