Overview
When NetSuite refreshes a Sandbox account or provisions a Release Preview account from Production, it copies your eXtendTech app (eXtendApp) settings, including subdomains, into the new account as part of the native refresh process.
Those copied settings don't work in the new account. Each account needs its own unique subdomain, and each eXtendApp needs valid authentication with NetSuite before you can use it.
Complete the steps in this article in the Sandbox or Release Preview account after every refresh or provisioning.
Note: These steps change settings only in the account you're logged in to. Confirm you're logged in to the Sandbox or Release Preview account before you begin.
What you'll do
- Clear the subdomain values copied from Production.
- Identify how each installed eXtendApp authenticates.
- Generate new access tokens for the apps that use them.
- Validate the OAuth 2.0 client credentials for the apps that use them.
- Confirm the new subdomain on each eXtendApp setup page.
- Complete the eXtendFiles steps, if you use eXtendFiles.
Prerequisites
- NetSuite Administrator access in the Sandbox or Release Preview account
- The entity (employee) and role used for each eXtendApp's authentication
- The current eXtendTech certificate, only if you need to create new OAuth 2.0 client credentials
Configuration
Step 1: Clear the subdomain values copied from Production
Clear the Production values first so each eXtendApp can pick up a unique subdomain for this account.
- Go to Setup → Company → General Preferences.
- Select the Custom Preferences subtab.

- For each eXtendApp installed in this account, clear the subdomain field and any related fields. Use the table below to find the field for each app.
- Click Save.
Note: You'll only see fields for the eXtendApps installed in this account.
| Application name | Custom Preferences field name |
|---|---|
| eXtendAlphaBroder | eXtendAlphaBroder Subdomain |
| eXtendASI/ESP DE | eXtendTech ASI Order Integration Subdomain |
| eXtendFiles | eXtendTech Files Approval Subdomain Name |
| eXtendFloorXL | eXtendFloorXL Subdomain |
| eXtendFrame | eXtendFloorXL FN Subdomain |
| eXtendMobile | eXtendMobile Subdomain |
| eXtendPresentation | eXtendTech Presentation Subdomain |
| eXtendPS-SE | eXtendPS-SE Sub Domain |
| eXtendSanMar | eXtendTech SanMar Subdomain |
| eXtendWebApprovals | eXtendTech Web Approval Sub Domain |
Step 2: Identify how each eXtendApp authenticates
Each eXtendApp authenticates with NetSuite in one of two ways, and the two behave differently during a refresh or provisioning.
- Access tokens don't transfer. NetSuite doesn't copy access tokens from Production, so you need to generate new tokens in the new account.
- OAuth 2.0 client credentials (M2M) do transfer. The credential records copy over, but they only work when the associated employee still has login access and the matching role.
| eXtendApp | Authentication method |
|---|---|
| eXtendASI/ESP DE (with Order Integration) | OAuth 2.0 client credentials (M2M) |
| eXtendFiles | OAuth 2.0 client credentials (M2M) |
| eXtendFrame | OAuth 2.0 client credentials (M2M) |
| eXtendMobile | OAuth 2.0 client credentials (M2M) |
| eXtendFloorXL | Access token |
| eXtendPresentation | Access token |
| eXtendPS-SE | Access token |
| eXtendWebApprovals | Access token |
eXtendAlphaBroder and eXtendSanMar need only the subdomain steps in Step 1 and Step 5.
Step 3: Generate new access tokens
Applies to eXtendFloorXL, eXtendPresentation, eXtendPS-SE, and eXtendWebApprovals.
- Go to Setup → Company → Enable Features → SuiteCloud subtab, then confirm Token-based authentication is enabled in the Manage Authentication field group.
- Confirm the employee who generates the token has the server user role for the app, such as Your Company Name eXtendFloorXL Server User.
- Generate a new access token for each installed app that uses one. See Generating a new Access Token.

- Copy the token ID and token secret into the app's setup page, then save the page.
Note: NetSuite shows the token ID and token secret only once. Copy them before you leave the page.
Step 4: Validate the OAuth 2.0 client credentials (M2M)
Applies to eXtendASI/ESP DE (with Order Integration), eXtendFiles, eXtendFrame, and eXtendMobile.
Your OAuth 2.0 Client Credentials (M2M) records copy from Production to the Sandbox or Release Preview account during the refresh or provisioning, so you usually don't need to create new credentials. A copied credential only works when the employee (entity) it was created against meets all of these conditions in the new account:
- The employee has login access in the new account.
- The employee has the same role assigned that the credential was generated against.
- The employee record has been saved in the new account. In rare cases, you need to edit and save the record before the credential works.
Note: These conditions matter most when your company restricts Sandbox login access, or when login access doesn't carry over during the refresh.
To validate the credentials:
- Go to Setup → Integration → Manage Authentication → OAuth 2.0 Client Credentials (M2M) Setup.
- Find the row for each eXtendApp's current certificate record, then note the Entity and Role. Use the table below to match the integration record to the app.
- Open that employee record and confirm login access is granted and the role from step 2 is assigned.
- Grant login access or add the role if either is missing, then save the employee record.
- If both look correct but the app still can't authenticate, click Edit on the employee record and save it without other changes.
- Confirm the Certificate ID and Certificate Type on the app's setup page match the credential you're using.
| SuiteApp | Role | Integration record |
|---|---|---|
| eXtendASI/ESP DE | eXtendASI Server User | eXtendASI Order |
| eXtendFiles | eXtendFiles Server User | eXtendTech Files |
| eXtendFrame | eXtendFn Server User | eXtendFrame Functions |
| eXtendMobile | eXtendMobile Server User | eXtendMobile |
When to create new credentials
Create new OAuth 2.0 client credentials only when valid credentials aren't already present in the account. Don't add duplicate credentials, and don't revoke credentials that work.
NetSuite lets you add a certificate to a specific application and entity combination only once, so confirm the entity and role before you create anything. All eXtendApps use the same eXtendTech certificate, so you can upload the same certificate file for each application. Contact eXtendTech Support if you're unsure whether a certificate needs to be added or updated.
Step 5: Confirm the new subdomain in each eXtendApp
- Open the setup page for each installed eXtendApp.
- Confirm the Subdomain field shows a new value for this account instead of the Production value.
- Click Save.
For eXtendFiles, follow the steps in the next section.
Step 6: Complete the eXtendFiles configuration
- Go to eXtendTech → eXtendFiles → eXtendFiles Configuration, then select eXtendFiles Settings → Authentication & Preferences. If an error occurs and the page fails to load, contact eXtendTech Support.
- Confirm your Sandbox or Release Preview subdomain appears in the Subdomain field, then click Save.
- Go to Storage Settings → General and review your storage configuration. Click Save if the settings are correct, or enter the settings you want and then click Save.

- Reauthenticate your storage if it requires authentication. Box, Dropbox, and Microsoft OneDrive/SharePoint often need to be reauthenticated. See Using eXtendFiles Configuration.
- Regenerate the approval and public upload URLs for this account. See Regenerating eXtendFiles Approval and Public Upload Links in Sandbox Environments.
Note: If you copy the storage information from Production and then select different storage in the Sandbox or Release Preview account, update the eXtendFiles Configuration page to match.