> ## Documentation Index
> Fetch the complete documentation index at: https://docs.alvys.com/llms.txt
> Use this file to discover all available pages before exploring further.

# NetSuite: Prerequisites

> Prepare NetSuite for the Alvys integration: enable SuiteTalk REST, create the integration role and user, and generate Token-Based Authentication keys.

<Note>
  Before connecting Alvys to NetSuite, your NetSuite environment must be properly prepared: the correct features, roles, users, and credentials must be configured, or the integration will fail to authenticate or export transactions.
</Note>

### Overview

Before configuring (setting up) the Alvys and NetSuite integration, your NetSuite environment must be properly prepared. Most integration failures result from misconfigured features, roles, users, or improper subsidiary access.

Alvys connects to NetSuite using **Token-Based Authentication (TBA)** through **SuiteTalk REST Web Services**. This secure authentication method allows encrypted API communication without storing user credentials. OAuth 2.0 is not used.

### Before You Start

**Required role:** Configuring the accounting integration in Alvys requires the **"CompanyProfileManager"** permission, available to the Admin, Partner Admin, or Support role. On the NetSuite side, a NetSuite Administrator (or a role with equivalent permissions) is needed only during setup to enable features, create roles, and generate tokens.

**Prerequisites:**

* An active NetSuite account with Administrator-level access
* Access to Setup, Users/Roles, and Integrations in NetSuite
* If your organization uses NetSuite OneWorld, all subsidiaries must be created and configured before starting

<Info>
  💡 **Important:** Do not use your personal Administrator login for the live integration. During setup you will create a dedicated integration role and user specifically for Alvys. Your Administrator account is used only to prepare the system, not to run the integration long-term.
</Info>

### Steps

#### Enable required NetSuite features

The required features are: REST Web Services, SOAP Web Services, Token-Based Authentication (TBA), and SuiteScript.

**Required Features**

* **REST Web Services** – Allows NetSuite to share data with Alvys
* **SOAP Web Services** – Recommended to ensure compatibility with all supported record types
* **Token-Based Authentication (TBA)** – Allows secure system access without using a password
* **SuiteScript** – While Alvys does not deploy custom scripts in your account, SuiteScript is required for NetSuite’s REST and SOAP Web Services to function properly, including internal searches and record queries executed by the integration.

  <Info>
    💡 **Important:** OAuth 2.0 is not required for this integration. Alvys authenticates exclusively using Token-Based Authentication (TBA).
  </Info>

1. Log in to NetSuite using your administrator account.
2. Navigate to **Setup > Company > Enable Features**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=d909fbf96ec37de3684dc75d7f15c6ee" alt="NetSuite menu: Setup > Company > Enable Features" data-og-width="535" width="535" data-og-height="249" height="249" data-path="images/help/c1e1fe799dd0.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=49c1b5cda278bec1e41cbaf9c57e53bf 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b0d4f664de6cd767495d502c07dedfa0 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=e571a29f5be0f28f7e605fc8960efeb9 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=1db325d95ce40dfa5105c69edbfe7fea 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=99e3f8d98ea3f81dc873a5a6f47c75bd 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=c47c4f0cc8995043a3dd8b040b5a0437 2500w" />

     *NetSuite menu: Setup > Company > Enable Features*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=d909fbf96ec37de3684dc75d7f15c6ee" alt="NetSuite menu: Setup > Company > Enable Features" data-og-width="535" width="535" data-og-height="249" height="249" data-path="images/help/c1e1fe799dd0.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=49c1b5cda278bec1e41cbaf9c57e53bf 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b0d4f664de6cd767495d502c07dedfa0 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=e571a29f5be0f28f7e605fc8960efeb9 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=1db325d95ce40dfa5105c69edbfe7fea 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=99e3f8d98ea3f81dc873a5a6f47c75bd 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c1e1fe799dd0.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=c47c4f0cc8995043a3dd8b040b5a0437 2500w" />

   *NetSuite menu: Setup > Company > Enable Features*
3. Open the **SuiteCloud** tab.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/2720b0268a33.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=6a282e7022c9b5814a79dbb9cb7d5ab8" alt="Selecting the SuiteCloud tab" width="216" height="35" data-path="images/help/2720b0268a33.png" />

     *Selecting the SuiteCloud tab*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/2720b0268a33.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=6a282e7022c9b5814a79dbb9cb7d5ab8" alt="Selecting the SuiteCloud tab" width="216" height="35" data-path="images/help/2720b0268a33.png" />

   *Selecting the SuiteCloud tab*
4. In the **SuiteTalk (Web Services)** section, enable **SOAP Web Services** and **REST Web Services**.

<Note>
  <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/4c5fb4ba07c3.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9843ba3c541a83f02a847460cfe5567a" alt="SuiteTalk (Web Services) section" width="260" height="27" data-path="images/help/4c5fb4ba07c3.png" />

  *SuiteTalk (Web Services) section*

  <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/e1efe2b692e9.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=23397cdc8a5bd3c858af9016472f04e9" alt="SOAP and REST Web Services enabled" width="971" height="212" data-path="images/help/e1efe2b692e9.png" />

  *SOAP and REST Web Services enabled*
</Note>

1. In the **Manage Authentication** section, enable **Token-Based Authentication (TBA)**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/157d531d1c98.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b801b1cc856c6abd144232a7749394a2" alt="Enabling Token-Based Authentication" width="741" height="72" data-path="images/help/157d531d1c98.png" />

     *Enabling Token-Based Authentication*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/157d531d1c98.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b801b1cc856c6abd144232a7749394a2" alt="Enabling Token-Based Authentication" width="741" height="72" data-path="images/help/157d531d1c98.png" />

   *Enabling Token-Based Authentication*
2. In the **SuiteCloud** tab, locate **SuiteScript** and enable it.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe267611e23d.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=c8a6cbaf4db596f3308cdde75799b0c4" alt="Enabling Client and Server SuiteScript" width="937" height="195" data-path="images/help/fe267611e23d.png" />

     *Enabling Client and Server SuiteScript*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe267611e23d.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=c8a6cbaf4db596f3308cdde75799b0c4" alt="Enabling Client and Server SuiteScript" width="937" height="195" data-path="images/help/fe267611e23d.png" />

   *Enabling Client and Server SuiteScript*
3. Click **Save**.

<Warning>
  **Important:** Missing any of these features may cause authentication failures or prevent transaction data from being exported correctly.
</Warning>

#### Create a dedicated integration role

A dedicated role separates automated API access from human administrator accounts and restricts permissions to only what is necessary.

1. Navigate to **Setup > Users/Roles > Manage Roles**, then click **New**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/888d49f1cab9.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=a3595e317dd18097b99144584ab7370b" alt="Creating a new role under Manage Roles" width="571" height="394" data-path="images/help/888d49f1cab9.png" />

     *Creating a new role under Manage Roles*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/888d49f1cab9.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=a3595e317dd18097b99144584ab7370b" alt="Creating a new role under Manage Roles" width="571" height="394" data-path="images/help/888d49f1cab9.png" />

   *Creating a new role under Manage Roles*
2. Enter a descriptive name such as **"Alvys Integration Role"**.
3. Assign **Subsidiary Access**: if using OneWorld, assign access to all subsidiaries used in Alvys and enable **Cross-Subsidiary Record Viewing**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/56b0ec66d040.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=1af2dcfed3b57dc63720e1774e71653a" alt="Setting subsidiary access and cross-subsidiary viewing" width="701" height="240" data-path="images/help/56b0ec66d040.png" />

     *Setting subsidiary access and cross-subsidiary viewing*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/56b0ec66d040.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=1af2dcfed3b57dc63720e1774e71653a" alt="Setting subsidiary access and cross-subsidiary viewing" width="701" height="240" data-path="images/help/56b0ec66d040.png" />

   *Setting subsidiary access and cross-subsidiary viewing*
4. Optionally, restrict the role to **Web Services Only** to prevent login through the NetSuite interface.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/4f638354b470.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=baf2b918bb044713ce3f747643206e1d" alt="Restricting the role to Web Services Only" width="378" height="152" data-path="images/help/4f638354b470.png" />

     *Restricting the role to Web Services Only*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/4f638354b470.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=baf2b918bb044713ce3f747643206e1d" alt="Restricting the role to Web Services Only" width="378" height="152" data-path="images/help/4f638354b470.png" />

   *Restricting the role to Web Services Only*
5. Click **Save**.

#### Assign permissions to the integration role

**Setup permissions** (all Full Access unless noted):

REST Web Services, SOAP Web Services, Login Using Access Tokens, SuiteScript, Accounting Lists, Custom Fields, Custom Item Fields, Custom Body Fields, Custom Column Fields, Custom Transaction Fields, Custom Entity Fields, Custom Record Types, Custom Segments, Custom Lists, Other Lists, Deleted Records, Manage Accounting Periods (View), Financial Institution Records

<Note>
  <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/3404d4cd2ba4.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9267e1ea26d4dba15f023f25cf215daf" alt="Setup permissions tab on the role" width="535" height="89" data-path="images/help/3404d4cd2ba4.png" />

  *Setup permissions tab on the role*
</Note>

**Transaction permissions** (all Full Access):

Invoice, Bills, Customer Payments, Pay Bills, Vendor Credits, Credit Memos, Customer Deposit, Make Journal Entry

<Note>
  <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/0b1cd5b6b1a1.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=d8bbfc20d895b4cec7dc9437920d1bf5" alt="Transactions permissions tab on the role" width="540" height="105" data-path="images/help/0b1cd5b6b1a1.png" />

  *Transactions permissions tab on the role*
</Note>

**Important:** If any transaction permissions are missing, exports may fail even if authentication is successful.

<Note>
  **List permissions:**

  Accounts (Full), Address List in Search (Full), Contacts (Full), Customers (Full), Vendors (Full), Employees (View), Employee Record (View), Expense Categories (Full), Payment Methods (Full), Currency (Full), Items (Full), Perform Search (Full), Custom Record Entries (Full), Classes (Full), Departments (Full), Locations (Full), Subsidiaries (View), Contact-Subsidiary relationship (View), Companies (Full), Tax Records (View), Documents and Files (Full)
</Note>

<img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/b7bb5c62ea8d.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=217913d47b9607050e157abe38f2c8b3" alt="Lists permissions tab on the role" width="528" height="67" data-path="images/help/b7bb5c62ea8d.png" />

*Lists permissions tab on the role*

#### Create a dedicated integration user

1. Navigate to **Lists > Employees**, then select **New** (or choose an existing service account).

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=266ab93acfcaa515a41b7652094feb84" alt="Creating the integration user (Lists > Employees > New)" data-og-width="619" width="619" data-og-height="167" height="167" data-path="images/help/fe308778599d.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=36ab200417907cc53fc426894481a933 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=d33d49a495a1c727426c6be9304af860 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=2249fe5ca061eedc9c1e407c9dd56c62 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=c53d3db90e59ef38aa30bbe7c4b4d471 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=8227e4614158bedd0396defd67f5ac6b 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fe308778599d.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=0bfa707b1dbd9685e39c001567fb9537 2500w" />

   *Creating the integration user (Lists > Employees > New)*
2. Assign the **Alvys Integration Role** under the Roles section.

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/76f919581ee1.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=e685a19e2867021da3b34c0f29b12e86" alt="Assigning the Alvys Integration Role to the user" width="459" height="213" data-path="images/help/76f919581ee1.png" />

   *Assigning the Alvys Integration Role to the user*
3. Click **Save**.

<Note>
  💡 Admin account: used only to enable features, create roles, create integration records, and generate tokens. The dedicated integration user (employee record or service account) is used by Alvys to authenticate via REST/TBA.
</Note>

#### Generate integration credentials

Alvys requires five credentials: Account ID, Consumer Key, Consumer Secret, Token ID, Token Secret.

**Locate your Account ID:** In the NetSuite URL before "[app.netsuite.com](http://app.netsuite.com/)." Example: in `https://123456.app.netsuite.com`, the Account ID is **123456**. Sandbox accounts include a suffix such as "\_SB1."

**Create the integration record:**

1. Navigate to **Setup > Integrations > Manage Integrations**, then click **New**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9f157622cdd99ec152fa6691d27b7720" alt="Creating a new integration record (Manage Integrations > New)" data-og-width="721" width="721" data-og-height="510" height="510" data-path="images/help/6dc78f6b4a67.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=0afa044183791440f5e7377803b4f90e 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=6ed5d3bce5656f5ec057fbb0ebbcd705 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=64ebdbf0257f8b3557e24b3e21c5ec50 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=50a856caf125abd674fa741083450cc6 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=85ceb7721fef95ae18791157be0ed6dc 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=a0c601e81a4e573332ea95d27a63654f 2500w" />

     *Creating a new integration record (Manage Integrations > New)*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9f157622cdd99ec152fa6691d27b7720" alt="Creating a new integration record (Manage Integrations > New)" data-og-width="721" width="721" data-og-height="510" height="510" data-path="images/help/6dc78f6b4a67.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=0afa044183791440f5e7377803b4f90e 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=6ed5d3bce5656f5ec057fbb0ebbcd705 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=64ebdbf0257f8b3557e24b3e21c5ec50 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=50a856caf125abd674fa741083450cc6 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=85ceb7721fef95ae18791157be0ed6dc 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/6dc78f6b4a67.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=a0c601e81a4e573332ea95d27a63654f 2500w" />

   *Creating a new integration record (Manage Integrations > New)*
2. Enter a descriptive name such as **"Alvys TMS Integration"**.
3. Enable **Token-Based Authentication**.

   <Note>
     <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c4191dad9525.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9bceb21308b8e5a2d5d493d8f44f0ae6" alt="Enabling Token-Based Authentication on the integration" width="347" height="121" data-path="images/help/c4191dad9525.png" />

     *Enabling Token-Based Authentication on the integration*
   </Note>

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/c4191dad9525.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=9bceb21308b8e5a2d5d493d8f44f0ae6" alt="Enabling Token-Based Authentication on the integration" width="347" height="121" data-path="images/help/c4191dad9525.png" />

   *Enabling Token-Based Authentication on the integration*
4. Click **Save**.
5. Copy the **Consumer Key** and **Consumer Secret**.

   <Warning>
     ⚠️ **Important:** The Consumer Key and Consumer Secret are displayed only once. Store them securely.
   </Warning>

   **Generate access tokens:**
6. Go to **Setup > Users/Roles > Access Tokens**, then click **New**.

   <img src="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=b526d348d88d09b6b53bcbe28a1875af" alt="Creating a new access token (Access Tokens > New)" data-og-width="658" width="658" data-og-height="513" height="513" data-path="images/help/fc94a7af5f40.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=280&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=057f2098adcd5c91fc1a1beeb0906cb9 280w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=560&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=4a891924d2cbfcd38dde93edcdbb76d9 560w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=840&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=3606d95b86af2102475d5fbe93220f37 840w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=1100&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=feeff564964c43945c8bfb76f7e34fcd 1100w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=1650&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=6ccb9423d670047ed64cec2bb6283e5d 1650w, https://mintcdn.com/alvys/NbezcQvwUCJbTEUv/images/help/fc94a7af5f40.png?w=2500&fit=max&auto=format&n=NbezcQvwUCJbTEUv&q=85&s=609b9b3a1f48eb53db4989f368d0c6ba 2500w" />

   *Creating a new access token (Access Tokens > New)*
7. Select:

   * **Application Name:** "Alvys TMS Integration"
   * **User:** the dedicated integration user
   * **Role:** the dedicated integration role
8. Click **Save**.
9. Copy the **Token ID** and **Token Secret**.

<Warning>
  ⚠️ **Important:** The Token ID and Token Secret are displayed only once.
</Warning>

#### Confirm a complete Chart of Accounts

All required income, expense, asset, liability, and clearing accounts must exist before exporting transactions. See Oracle documentation: [Creating Accounts](https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_N1440518.html).

1. Log in with a role that has accounting permissions.
2. Go to **Lists > Accounting > Accounts**, then click **New**.
3. Select the account **Type**.
4. Enter the **Account Name**.
5. If using account numbers, enter a number (account numbering must be enabled under **Setup > Accounting > Accounting Preferences**).
6. Optionally assign a parent account or subsidiary (for OneWorld users).
7. Click **Save**.

<Warning>
  ⚠️ **Important:** All required accounts must be created before pushing transactions from Alvys.
</Warning>

#### Configure subsidiaries (OneWorld accounts only)

See Oracle documentation: [Creating Subsidiary Records](https://docs.oracle.com/en/cloud/saas/netsuite/ns-online-help/section_N272471.html).

**To create a subsidiary:**

1. Navigate to **Setup > Company > Subsidiaries**.
2. Click **New**.
3. Enter the **Name** of the subsidiary.
4. Assign a **Base Currency**.
5. Select the **Parent Subsidiary** if applicable.
6. Assign a **Chart of Accounts**.
7. Complete tax settings.
8. Click **Save**.

   **To assign the Alvys Integration Role access to the subsidiary:**
9. Go to **Setup > Users/Roles > Manage Roles** and select the Alvys Integration Role.
10. Click **Edit**.
11. Find the **Subsidiary Access** section.
12. Set access to **All** (recommended) or select only the subsidiaries used in Alvys.
13. Enable **Cross-Subsidiary Record Viewing**.
14. Click **Save**.

### Result

Your NetSuite environment is ready to connect to Alvys. You have enabled required features, created a dedicated role with the required permissions, created a dedicated integration user, generated all five credentials, confirmed your Chart of Accounts, and (if using OneWorld) configured subsidiary access.

Proceed to enter these credentials in **Management > Integrations**.

### Troubleshooting

#### Integration fails to authenticate

**Step 1:** Confirm that REST Web Services, SOAP Web Services, Token-Based Authentication, and SuiteScript are all enabled under **Setup > Company > Enable Features > SuiteCloud**.

**Step 2:** Confirm the integration record has Token-Based Authentication enabled under **Setup > Integrations > Manage Integrations**.

**Step 3:** Confirm the Consumer Key, Consumer Secret, Token ID, and Token Secret were copied correctly. If any value was lost, regenerate the credentials.

**Step 4:** Confirm the token was created with the correct Application Name, User, and Role.

#### Transaction exports fail after successful authentication

**Step 1:** Confirm the integration role includes all required Transaction permissions with Full access.

**Step 2:** Confirm all required Setup and List permissions are present.

**Step 3:** Confirm role permissions have not been modified since the token was generated.

**Step 4:** Confirm all required accounts exist in the Chart of Accounts.

#### Transactions fail for a specific subsidiary

**Step 1:** Confirm the Alvys Integration Role has access to that subsidiary under **Setup > Users/Roles > Manage Roles > \[Alvys Integration Role] > Subsidiary Restrictions**.

**Step 2:** Confirm **Cross-Subsidiary Record Viewing** is enabled.

**Step 3:** Confirm the subsidiary has a Base Currency and Chart of Accounts assigned.

#### Token was lost after creation

Delete the existing integration record or access token and repeat the credential generation step. Update Alvys with the new credentials.

<Warning>
  ⚠️ Common causes of integration failures: required features not enabled, token created under the wrong role, missing transaction or list permissions, subsidiary not assigned to the role, role permissions modified after token generation, or required accounts not created in NetSuite. Any of these will cause authentication or export failures.
</Warning>

## FAQs

**Q: What level of NetSuite access is required to set up the Alvys integration?**

**A:** An Administrator-level account is required only during setup. The integration itself uses a dedicated integration user.

**Q: Can I use my personal Administrator login for the live integration?**

**A:** No. A dedicated integration user and role must be created to separate API access from human accounts.

**Q: Which NetSuite features must be enabled for Alvys to connect?**

**A:** REST Web Services, SOAP Web Services, Token-Based Authentication (TBA), and SuiteScript must all be enabled. OAuth 2.0 is not required.

**Q: What happens if required NetSuite features are not enabled?**

**A:** Missing features can cause authentication failures or prevent transaction data from being exported correctly.

**Q: What permissions are required for the integration role?**

**A:** The role requires permissions across Setup, Transaction, and List categories, including full access to Web Services, SuiteScript, accounting lists, customers, vendors, items, and all relevant transaction types.

**Q: Should the integration role be restricted to Web Services only?**

**A:** Yes. This enhances security by preventing login through the NetSuite interface.

**Q: How do I create the integration user?**

**A:** Create a new employee record (or use a service account) and assign the dedicated integration role.

**Q: What credentials does Alvys require to connect to NetSuite?**

**A:** Account ID (Realm ID), Consumer Key, Consumer Secret, Token ID, and Token Secret.

**Q: Where can I find my NetSuite Account ID / Realm ID?**

**A:** The Account ID is in the NetSuite URL before "[app.netsuite.com](http://app.netsuite.com/)." Sandbox accounts include a suffix such as "\_SB1."

**Q: Can tokens be regenerated if lost?**

**A:** Yes, but you must regenerate them in NetSuite. Each value is shown only once at time of creation.

**Q: Are all Chart of Accounts and subsidiaries required before exporting transactions?**

**A:** Yes. All required accounts must exist and subsidiaries must be fully configured before exporting.

**Q: What are common causes of integration failures?**

**A:** Required features not enabled, tokens created under the wrong role, missing transaction or list permissions, subsidiaries not assigned to the role, role permissions modified after token generation, or required accounts not created in NetSuite.

**Q: Is SuiteScript required for the integration?**

**A:** Yes. SuiteScript must be enabled to allow NetSuite's REST and SOAP Web Services to function properly.

**Q: Can I limit the integration role to selected subsidiaries?**

**A:** Yes, but all subsidiaries used in Alvys must be included; otherwise, transaction exports to those subsidiaries will fail.

**Q: Does the integration support OAuth 2.0 authentication?**

**A:** No. Alvys uses only Token-Based Authentication (TBA) via SuiteTalk REST Web Services.

### Go Deeper

* [NetSuite: Authentication and Settings Configuration in Alvys](/help/integrations/netsuite-authentication-and-settings-configuration-in-alvys)
* [NetSuite Integration Collection](/help/integrations/netsuite-integration-collection)
