Discussions
Stay up-to-date with the latest news from NetSuite. You’ll be in the know about how to connect with peers and take your business to new heights at our virtual, in-person, on demand events, and much more.
Now is the time to ask your NetSuite-savvy friends and colleagues to join the NetSuite Support Community! Refer now! Click here to watch and learn more!
Stay in the Know
Be sure you're subscribed to NetSuite communication to stay in the know about monthly happenings, updates and announcements. Subscribe
Be sure you're subscribed to NetSuite communication to stay in the know about monthly happenings, updates and announcements. Subscribe
Please note that on Friday, March 20, 2026, at 8:00 PM Pacific time, our Case Management System will undergo a scheduled maintenance for approximately 4 hours. During this time, case creation via SuiteAnswers will be unavailable and inbound calls will be routed to Customer Service.
Security Concerns with RESTlets
Let's get the positive things out of the way first. RESTlets are great from the point of view of they're a web standard. Yay!
Now for the bad news.
RESTlets require a full set of NetSuite credentials to be forwarded to NetSuite in plain text with every request. "But HTTPS!" I hear the masses cry; that's all well and good until you consider the need to store those credentials somewhere (again, in plain text) to be sent with each of those requests. :h_a_w:
I'm not altogether comfortable with putting a full set of NetSuite login credentials into a database, or flat file, or some other means of storage that has to be accessible (by necessity) by my applications that I want to integrate using REST.
0