Skip to content
Last updated

NetSuite integration

NetSuite is Oracle's cloud ERP suite for finance, operations, and CRM.

It can be connected to Agen.co two ways, matching the Official / In-house filter in the connector picker:

  • Official — Agen.co connects through Oracle's own hosted MCP server for NetSuite (the NetSuite AI Connector Service), so your AI agents get access to NetSuite records and SuiteQL queries through your account's existing role permissions.
  • In-house — Agen.co wraps the NetSuite SuiteTalk REST Web Services API directly through its own integration layer, using an OAuth 2.0 integration record you create in NetSuite.

Pick Official if the built-in MCP tools cover what your agents need. Fall back to In-house if your organization can't meet the Official connector's prerequisites (for example, the MCP Standard Tools SuiteApp, or a signed healthcare BAA that excludes it), or if you need broader API coverage.


Connect via the official MCP server

Prerequisites

  • A NetSuite account with the Server SuiteScript and OAuth 2.0 features enabled, under Setup → Company → Enable Features → SuiteCloud
  • The MCP Standard Tools SuiteApp installed, which requires REST Web Services to be enabled
  • A connecting role with the MCP Server Connection and Log in using OAuth 2.0 Access Tokens permissions — the Administrator role can't be used
  • Not available to healthcare organizations under a signed Business Associate Agreement (BAA)
  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.
  2. In the search bar, type NetSuite and select it from the results.
  3. In the Instance Slug field, enter a slug for this connector instance — it prefixes each imported tool as slug__tool, so a second instance of the same connector needs a slug of its own. Use lowercase kebab-case. You can change it later from the connector's settings.
  4. In NetSuite account ID, enter your account ID (for example, 1234567, or 1234567-sb1 for a sandbox) — found in your NetSuite URL or under Setup → Company → Company Information.
  5. Click Connect.
  6. You're redirected to NetSuite to sign in and approve access. No Client ID or Client Secret needs to be entered manually — NetSuite creates the integration record for Agen.co automatically the first time you connect.
  7. Return to Agen.co and click Add below the list of tools that were added.

Once connected, NetSuite appears under My connectors with tools for reading and writing NetSuite records and running SuiteQL queries through SuiteTalk REST Web Services.

Enabling the NetSuite connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Connect via the NetSuite API

NetSuite is Oracle's cloud ERP suite for finance, operations, and CRM. Integrating NetSuite with Frontegg lets your application read and write NetSuite records and run SuiteQL queries through the SuiteTalk REST Web Services API on behalf of your users — all through Frontegg's integration layer. NetSuite authenticates with OAuth 2.0 (Authorization Code flow), so you create an integration record in NetSuite to obtain a Client ID and Client Secret. Because NetSuite endpoints are per-account, you also provide your NetSuite Account ID.

Prerequisites

  • A NetSuite account with administrator access
  • The REST Web Services and OAuth 2.0 features enabled (see Step 1)

Connect to NetSuite

You create an integration record in NetSuite. It provides the Client ID (Consumer Key) and Client Secret (Consumer Secret) and defines the redirect URI that NetSuite returns users to after they authorize access. You also need your Account ID.

Step 1: Enable the required features

Sign in to NetSuite as an administrator and go to Setup → Company → Enable Features. On the SuiteCloud tab, enable REST Web Services and, under Manage Authentication, OAuth 2.0. Save.

Step 2: Create an integration record

Go to Setup → Integration → Manage Integrations → New. Enter a Name (for example, Frontegg Integration) and set State to Enabled.

Step 3: Configure OAuth 2.0

In the integration record, under OAuth 2.0:

  • Enable Authorization Code Grant.
  • Enable the REST Web Services scope.
  • Set the Redirect URI to your Frontegg Redirect URL: https://YOUR_MCP_GATEWAY_URL/integration-callback

Make sure the Token-Based Authentication options are not required for this app — only OAuth 2.0 is needed.

Step 4: Copy the Client ID and Client Secret

Click Save. NetSuite displays the Client ID (Consumer Key) and Client Secret (Consumer Secret) on the confirmation page.

Copy your credentials now

The Client ID and Client Secret are shown only once, right after you save the integration record. Copy them immediately and store them securely — treat them like a password. If you lose them, reset the credentials on the integration record to generate new ones.

Step 5: Find your Account ID

Your Account ID appears in your NetSuite URL (for example, 1234567 in 1234567.app.netsuite.com) and in Setup → Company → Company Information. Use lowercase, replace any underscore with a hyphen, and append the environment suffix for non-production accounts (for example, 1234567-sb1 for a sandbox). Do not include https:// or .suitetalk.api.netsuite.com.

Configure the Frontegg portal

Once you have your Client ID, Client Secret, and Account ID, configure the integration in the Frontegg portal:

  1. Open the Frontegg portal and navigate to [ENVIRONMENT] → Integrations → NetSuite.
  2. Enter the Client ID and the Client Secret.
  3. Enter your NetSuite Account ID (for example, 1234567).
  4. Click Save.

Frontegg requests the following scope during authorization:

ScopeDescription
rest_webservicesAccess NetSuite records and run SuiteQL queries via SuiteTalk REST Web Services

Keep your credentials secure

Never share or commit your Client Secret to version control.

Additional resources