NetSuite: "Invalid login attempt" and missing permissions
NetSuite connections use Token-Based Authentication. The consumer creates a role, a user and an access token in NetSuite and enters them in Vault. Most NetSuite problems come down to that setup: a missing feature, a missing permission on the role, or a token that was revoked.
Missing permissions are tricky in NetSuite because they don't always produce an error. Some just return an empty list. Use the table below to match what you're seeing to the fix.
Symptom → fix
What you see | Most likely cause | Fix |
|---|---|---|
"Invalid login attempt", "Invalid configuration", or the connection won't validate after saving | The role is missing a required Setup permission, or the token was created for the wrong application or role | Give the role SOAP Web Services, REST Web Services and Log in using Access Tokens (all under Setup). Check that the access token was created with the right Application *and* Role, and that the role is assigned to the integration user. |
The connection stopped working after it worked before | The token was revoked or regenerated, the Integration Record was deleted, the role changed, or the sandbox was refreshed | Create a new access token and update the Token ID and Token Secret on the connection. |
A list returns | The role is missing the permission for that record type (for example Invoice, Bill or Credit Memo). NetSuite filters the rows out silently instead of returning an error. | Add the missing Transactions permission to the role. |
A filtered list (e.g. with | SuiteAnalytics Workbook is missing | Add Reports → SuiteAnalytics Workbook (Edit). |
A filtered list returns | Find Transaction is missing | Add Transactions → Find Transaction (View). |
A filtered list returns | Customers is missing | Add Lists → Customers (View). |
Profit & Loss or Balance Sheet returns 401 | Financial Statements is missing | Add Reports → Financial Statements (View). |
Profit & Loss or Balance Sheet returns all zeros | The connection's Default Subsidiary points to a subsidiary that no longer exists | Pick an existing subsidiary, or All subsidiaries. |
Creating invoice items fails because the currency couldn't be resolved | Currency is missing | Add Lists → Currency (View). |
Creating expenses with per-line tax fails with "Permission Violation … Tax Details Tab" (SuiteTax accounts) | Tax Details Tab is missing | Add Lists → Tax Details Tab (Full). |
Tax rates don't match what NetSuite shows | The account uses SuiteTax but the connection isn't set up for it | Set SuiteTax enabled to Yes on the connection, and give the role Lists → Sales Tax Items. |
The Default Subsidiary dropdown is empty | The connection hasn't been saved yet, or Subsidiaries is missing | Save the connection with the token fields filled in, then reopen the form. Check the role has Lists → Subsidiaries. |
Creates for one record type suddenly fail while others work | A custom field was made mandatory on that record's form | Check that record type's form in NetSuite for new mandatory fields. |
The easiest way to get permissions right
Install the Apideck Integration bundle (bundle ID 705521). It creates a ready-made Apideck Unify role with the permissions the standard accounting resources need, plus a pre-configured Integration Record. The consumer then only enters three fields in Vault: Account ID, Token ID and Token Secret.
Two things to know about the bundle:
Some features need permissions added by hand: bank feeds, Tax Details Tab, and Sales Tax Items on SuiteTax accounts.
Updating the bundle removes permissions you added by hand, so re-add them after each update.
Also check
Features enabled: *SOAP Web Services*, *REST Web Services* and *Token-Based Authentication* must be enabled at Setup → Company → Enable Features → SuiteCloud.
Account ID: use it exactly as shown in Company Information, including the
_SB1suffix for sandboxes.Secrets are shown once: NetSuite only displays the token secret when it's created. If it's lost, create a new token.
For the full list of permissions and step-by-step setup, see the NetSuite connection guide.
