NetSuite's secure authentication method for external integrations — uses OAuth 1.0a tokens instead of usernames/passwords, eliminating password rotation and reducing the attack surface for API access.
TBA is NetSuite's recommended authentication for SuiteTalk SOAP, REST APIs, and RESTlets when integrations originate from external systems. The flow issues a token + secret per integration, scoped to a specific role with defined permissions. Tokens don't expire (you revoke them manually), and they bypass MFA, which is why they should be tied to a dedicated 'integration user' role with minimum-necessary permissions.
Setting up TBA tokens for a Python ETL job that pulls invoice data nightly, scoped to a read-only Saved Search-based role.
TBA is the secure default for any production NetSuite integration — passwords-in-code patterns invite credential leaks, while tokens enable per-integration auditing and revocation.
Need help implementing this in your business?
Get Started