Qubit Docs العربية

NetSuite

Connect Oracle NetSuite so Qubit can read your transactions, their lines and GL impact, and the lists behind them. Qubit reads through SuiteQL with read-only access and signs in with a certificate, so no password or user session is involved.

Before you start

You need a NetSuite administrator for these steps.

  1. Enable the features. Open Setup > Company > Enable Features. On the SuiteCloud tab, check REST Web Services and, under Manage Authentication, OAuth 2.0. Save.
  2. Create a read-only role. Open Setup > Users/Roles > Manage Roles > New and add these permissions:
    • Setup: REST Web Services and Log in using OAuth 2.0 Access Tokens.
    • Reports: SuiteAnalytics Workbook.
    • Transactions and Lists: View on the records you want in Qubit, for example Find Transaction, Sales Order, Invoice, Bills, Journal Entry, Customers, Vendors, Items, Accounts, Subsidiaries, Departments, Classes, Locations, and Currency.
  3. Give the role to an employee. Qubit acts as this employee, with this role only.
  4. Create the integration record. Open Setup > Integration > Manage Integrations > New, name it Qubit, and under OAuth 2.0 check Client Credentials (Machine to Machine) Grant with the REST Web Services scope. Save, then copy the Client ID. NetSuite shows it only once. Qubit does not need the client secret.

Connect NetSuite

  1. Open Data Catalog from the sidebar, click Add Data, then choose Connect a database.
  2. On the New Data Source page, click NetSuite. It is under Accounting.
  3. Enter a Connection Name.
  4. Under Certificate, click Generate certificate. Your browser downloads qubit-netsuite-certificate.pem. Qubit keeps the matching private key encrypted with this connection.
  5. In NetSuite, open Setup > Integration > Manage Authentication > OAuth 2.0 Client Credentials (M2M) Setup and click Create New. Choose the employee as the Entity, the read-only role as the Role, the Qubit integration as the Application, and upload the certificate file. Save, then copy the Certificate ID.
  6. Back in Qubit, fill in the fields:
    • Account ID: from Setup > Company > Company Information, for example 1234567. A sandbox ID ends in _SB1 or similar.
    • Client ID: from the integration record.
    • Certificate ID: from the M2M setup.
    • Read transactions from: optional. Qubit reads transactions, their lines, and their GL impact from this date. Leave it empty to read the full history.
  7. Choose a Sync Schedule. The default is Daily.
  8. Click Create.

If you already have a certificate of your own, choose Use my own certificate instead and paste its private key in PEM format, without a passphrase. NetSuite accepts RSA keys of 3072 or 4096 bits and EC keys.

What Qubit reads

TableWhat it holds
transactionEvery transaction: invoices, sales orders, bills, payments, journal entries
transactionlineThe lines of each transaction
transactionaccountinglineThe GL impact of each line, per accounting book
account, accountingperiodChart of accounts and accounting periods
customer, vendor, itemCustomers, vendors, and items
subsidiary, department, classification, location, currencySegments and currencies
employeeNames, titles, department, and supervisor only, never personal or pay details

Custom fields (custbody_, custcol_, custentity_, custitem_) are read too, once a recent record has a value in them.

  • Amounts arrive as NetSuite sends them, as exact decimal text.
  • Dates and times read as YYYY-MM-DD HH:MM:SS in the time zone of the integration's employee.
  • Check boxes read as T or F, as in NetSuite.

After you connect

Qubit signs in to NetSuite and reads one row of each table before saving the connection. The result lists any table the role cannot read. Qubit skips those tables in every sync until you add the permission. Then it starts the first sync.

Replacing the certificate

A certificate is valid for two years. Replace it before it expires: open the connection's menu in the Data Catalog, choose Edit, click Generate a new certificate, add the new file in OAuth 2.0 Client Credentials (M2M) Setup for the same integration, employee, and role, paste its new Certificate ID, and save. Remove the old certificate in NetSuite once the connection tests successfully.

Troubleshooting

  • NetSuite refused the sign-in: check that the Client ID belongs to the integration, that the certificate is in its M2M setup, and that the Certificate ID matches. NetSuite's Login Audit Trail, under Setup > Users/Roles > View Login Audit Trail, shows the exact reason.
  • Could not reach NetSuite: check the account ID. A sandbox ID ends in _SB1 or similar.
  • A table is not readable: give the role View permission on that record type, then run Test connection again.