NetSuite: "Invalid login attempt" and missing permissions

Edited

NetSuite connections use Token-Based Authentication. The consumer creates a role, a user and an access token in NetSuite and enters them in Vault. Most NetSuite problems come down to that setup: a missing feature, a missing permission on the role, or a token that was revoked.

Missing permissions are tricky in NetSuite because they don't always produce an error. Some just return an empty list. Use the table below to match what you're seeing to the fix.

Symptom → fix

What you see

Most likely cause

Fix

"Invalid login attempt", "Invalid configuration", or the connection won't validate after saving

The role is missing a required Setup permission, or the token was created for the wrong application or role

Give the role SOAP Web Services, REST Web Services and Log in using Access Tokens (all under Setup). Check that the access token was created with the right Application *and* Role, and that the role is assigned to the integration user.

The connection stopped working after it worked before

The token was revoked or regenerated, the Integration Record was deleted, the role changed, or the sandbox was refreshed

Create a new access token and update the Token ID and Token Secret on the connection.

A list returns 200 OK with an empty data array

The role is missing the permission for that record type (for example Invoice, Bill or Credit Memo). NetSuite filters the rows out silently instead of returning an error.

Add the missing Transactions permission to the role.

A filtered list (e.g. with filter[updated_since]) returns 400 … Your current role does not have permission to perform this action

SuiteAnalytics Workbook is missing

Add Reports → SuiteAnalytics Workbook (Edit).

A filtered list returns 400 … Record 'transaction' was not found

Find Transaction is missing

Add Transactions → Find Transaction (View).

A filtered list returns 400 … Record 'customer' was not found

Customers is missing

Add Lists → Customers (View).

Profit & Loss or Balance Sheet returns 401

Financial Statements is missing

Add Reports → Financial Statements (View).

Profit & Loss or Balance Sheet returns all zeros

The connection's Default Subsidiary points to a subsidiary that no longer exists

Pick an existing subsidiary, or All subsidiaries.

Creating invoice items fails because the currency couldn't be resolved

Currency is missing

Add Lists → Currency (View).

Creating expenses with per-line tax fails with "Permission Violation … Tax Details Tab" (SuiteTax accounts)

Tax Details Tab is missing

Add Lists → Tax Details Tab (Full).

Tax rates don't match what NetSuite shows

The account uses SuiteTax but the connection isn't set up for it

Set SuiteTax enabled to Yes on the connection, and give the role Lists → Sales Tax Items.

The Default Subsidiary dropdown is empty

The connection hasn't been saved yet, or Subsidiaries is missing

Save the connection with the token fields filled in, then reopen the form. Check the role has Lists → Subsidiaries.

Creates for one record type suddenly fail while others work

A custom field was made mandatory on that record's form

Check that record type's form in NetSuite for new mandatory fields.

The easiest way to get permissions right

Install the Apideck Integration bundle (bundle ID 705521). It creates a ready-made Apideck Unify role with the permissions the standard accounting resources need, plus a pre-configured Integration Record. The consumer then only enters three fields in Vault: Account ID, Token ID and Token Secret.

Two things to know about the bundle:

  • Some features need permissions added by hand: bank feeds, Tax Details Tab, and Sales Tax Items on SuiteTax accounts.

  • Updating the bundle removes permissions you added by hand, so re-add them after each update.

Also check

  • Features enabled: *SOAP Web Services*, *REST Web Services* and *Token-Based Authentication* must be enabled at Setup → Company → Enable Features → SuiteCloud.

  • Account ID: use it exactly as shown in Company Information, including the _SB1 suffix for sandboxes.

  • Secrets are shown once: NetSuite only displays the token secret when it's created. If it's lost, create a new token.

For the full list of permissions and step-by-step setup, see the NetSuite connection guide.

Related

Was this article helpful?

Sorry about that! Care to tell us more?

Thanks for the feedback!

There was an issue submitting your feedback
Please check your connection and try again.