NetSuite MCP connector
NetSuite is Oracle's cloud-based ERP solution for managing finance, operations, and customer data in one platform. The NetSuite MCP connector allows AI agents to retrieve customer and record information and run SuiteQL queries to analyze business data across a tenant. It also supports creating, updating, and deleting records, enabling agents to keep NetSuite data accurate and current as business needs change.
Authentication type
- OAuth 2.0 Authorization Code - Requires a one-time user login to authorize the agent to access the service on their behalf.
Configuring your NetSuite integration record for the MCP connector
Boomi Connect uses OAuth 2.0 authentication to securely access your NetSuite account's REST web services. This lets Boomi Connect retrieve customer records and query data from your NetSuite account.
To create a NetSuite connector in Boomi Connect, first set up an integration record with OAuth 2.0 enabled in your NetSuite account. Next, gather the resulting client ID, client secret, and account ID from that integration record. Then, use these credentials to configure the connector in Boomi Connect.
Prerequisites
Make sure that you fulfill the following requirements before you start setting up OAuth 2.0 authentication for the NetSuite connector in Boomi Connect.
-
A NetSuite production account with administrator access. This can also be a sandbox account for testing. You need this account to create an integration record. Refer to Integration Management for more information.
-
A dedicated NetSuite user for this integration. You must not use an administrator's personal account.
-
Boomi Connect's callback URL, which you will provide in the NetSuite integration record's Redirect URI field. This callback must follow the pattern
https://{environment-domain}/connector/netsuite/oauth/callback. For example, the URL for a US production environment ishttps://us.bc.boomi.com/connector/netsuite/oauth/callback. -
Access to Boomi Connect's connector configuration interface.
Step 1: Creating an integration record with OAuth 2.0 in NetSuite
-
Log in to a NetSuite production account as an administrator and create a new integration record. Refer to Create Integration Records for Applications to Use OAuth 2.0 for more information.
-
In this record’s Authentication section, select Authorization Code Grant to use a redirection-based authorization code grant flow with OAuth 2.0.
-
For Scope, select REST Web Services only. Do not select RESTlets, SuiteAnalytics Connect, or NetSuite AI Connector Service.
Step 2: Configuring the redirect URI
-
In the integration record’s Authentication section, for Redirect URI, enter the Boomi Connect callback URL,
https://us.bc.boomi.com/connector/netsuite/oauth/callback. -
Save the record.
Step 3: Saving the integration record
-
Copy the Consumer Key and Consumer Secret that NetSuite generates after you save the integration record. You will need to provide these in Boomi Connect.
Examples of Consumer Key and Consumer Secret are1234567890abcdef1234567890abcdef1234567890abcdef1234567890abcdefandabcdef1234567890abcdef1234567890respectively.
Keep these credentials confidential because NetSuite does not display them again. -
Copy your NetSuite account ID, which is visible on the top-right corner of any NetSuite page. Its format is
1234567for a production account, or1234567-sb1for a sandbox account.
Step 4: Creating a user and verifying required permissions
- Open NetSuite's Manage Roles page (Setup > Users/Roles > Manage Roles). Make sure that the access level for your role is FULL for the Log in using OAuth 2.0 Access Tokens and REST Web Services permissions.
Refer to Setting Permissions for information about adding permissions to a role. If your role is missing these permissions, add them.
If you do not already have a dedicated NetSuite user, create one in NetSuite’s Manage Users page (Setup > Users/Roles > Manage Users).
-
Provide First Name, Last Name, and Email for this user.
-
For Role, assign a role that has the Log in using OAuth 2.0 Access Tokens and REST Web Services permissions. If you have an existing user, verify that it has a role with both these permissions.
Refer to NetSuite Users Overview for information about creating a NetSuite user.
Step 5: Configuring a NetSuite connector in Boomi Connect
-
Log in to Boomi Connect and on the left sidebar, click Configs.
-
On the Configs page, click Create Config.
-
On the Create Config form, do the following:
-
Type NetSuite in the Search connectors box.
-
For Config Name, enter a name for your NetSuite connector.
-
For Select Identity Provider, select a provider.
-
For OAuth Client ID and OAuth Client Secret, enter the consumer key and consumer secret you copied earlier after saving the integration record.
-
For Account ID, enter your NetSuite account ID.
-
In Manage Tools, select the tools based on the type of operations you want to perform.
-
Click Save.
-
The NetSuite connector appears as a tile under Recent Configs and is ready to use.
Troubleshooting
The following table describes common NetSuite OAuth2.0 errors, their causes, and how to resolve them.
| Error | Reason | Solution |
|---|---|---|
| Invalid Client ID or Unauthorized Client | The client ID or client secret does not match the integration record, or the integration record is disabled. | In your NetSuite account, go to Setup > Integrations > Manage Integrations. For your integration record, verify that its State is Enabled. Copy the Consumer Key and Consumer Secret again and provide these credentials again in Boomi Connect. Make sure that you do not include any extra spaces. |
| Redirect URI Mismatch | The Redirect URI in NetSuite does not match what Boomi Connect is using. | In your integration record, check that the Redirect URI field’s value matches Boomi Connect's callback URL. Check for a missing path segment, http:// instead of https://, or an inconsistent trailing slash, then update it to match exactly and re-authorize. |
| Insufficient Permissions or Access Denied | The authorizing user's account is missing Log in using OAuth 2.0 Access Tokens or REST Web Services permission. | In NetSuite's Manage Roles page, verify that the user has the correct role assigned with FULL access for both the permissions. |
Security best practices
-
Use a dedicated user for this integration instead of an administrator's personal account.
-
Restrict the user role to only the Log in using OAuth 2.0 Access Tokens and REST Web Services permissions, instead of granting broader access.
-
Rotate the client secret every 90 days.
-
Use
https://only for the redirect URI. Never use anhttp://address. -
Keep the client ID and client secret confidential. Do not share them in Slack, email, or logs.
-
Monitor token usage periodically by checking Setup > Integrations > Manage Integrations in NetSuite.
Uses
Use the NetSuite MCP connector to perform the following actions:
- Retrieve customer records instantly by internal ID for account reviews
- Query customers, transactions, and other records using SuiteQL statements
- List records across any NetSuite record type for reporting
- Update existing NetSuite records to keep data accurate and current
- Delete obsolete or duplicate records to maintain data hygiene
- Pull detailed record information to support reconciliation and audits
- Automate financial reporting by extracting invoice and sales data
- Sync NetSuite data with other business systems in a workflow
Example prompts
Use the following example prompts to invoke NetSuite MCP connector tools from your AI assistant or Boomi Connect workflow:
Show me all open invoices from last month in NetSuite.Get the customer record for account 12345 in NetSuite.List all sales orders created this week in NetSuite.Find customers in NetSuite located in California.Update the billing address for customer 9081 in NetSuite.Delete the duplicate vendor record in NetSuite.Run a query to find all unpaid invoices in NetSuite.Show me the top 10 customers by revenue in NetSuite.Get details for purchase order 4521 in NetSuite.List all inventory items with low stock in NetSuite.
NetSuite MCP connector tools
The NetSuite MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| netsuite_netsuitegetcustomer_invoke | Retrieve a single customer record from NetSuite by internal ID |
| netsuite_netsuitequeryrecords_invoke | Execute a SuiteQL query to retrieve records. |
| listRecords | List records |
| getRecord | Get record |
| updateRecord | Update record |
| deleteRecord | Delete record |
| runSuiteQL | Run SuiteQL query |