Version: All
Audience: Administrators of all eXtendTech apps

Overview

When NetSuite refreshes a Sandbox account or provisions a Release Preview account from Production, it copies your eXtendTech app (eXtendApp) settings, including subdomains, into the new account as part of the native refresh process.

Those copied settings don't work in the new account. Each account needs its own unique subdomain, and each eXtendApp needs valid authentication with NetSuite before you can use it.

Complete the steps in this article in the Sandbox or Release Preview account after every refresh or provisioning.

Note: These steps change settings only in the account you're logged in to. Confirm you're logged in to the Sandbox or Release Preview account before you begin.

What you'll do

  1. Clear the subdomain values copied from Production.
  2. Identify how each installed eXtendApp authenticates.
  3. Generate new access tokens for the apps that use them.
  4. Validate the OAuth 2.0 client credentials for the apps that use them.
  5. Confirm the new subdomain on each eXtendApp setup page.
  6. Complete the eXtendFiles steps, if you use eXtendFiles.

Prerequisites

  • NetSuite Administrator access in the Sandbox or Release Preview account
  • The entity (employee) and role used for each eXtendApp's authentication
  • The current eXtendTech certificate, only if you need to create new OAuth 2.0 client credentials

Configuration

Step 1: Clear the subdomain values copied from Production

Clear the Production values first so each eXtendApp can pick up a unique subdomain for this account.

  1. Go to SetupCompanyGeneral Preferences.
  2. Select the Custom Preferences subtab.
    Image Placeholder
  3. For each eXtendApp installed in this account, clear the subdomain field and any related fields. Use the table below to find the field for each app.
  4. Click Save.

Note: You'll only see fields for the eXtendApps installed in this account.

Application name
Custom Preferences field name
eXtendAlphaBroder
eXtendAlphaBroder Subdomain
eXtendASI/ESP DE
eXtendTech ASI Order Integration Subdomain
eXtendFiles
eXtendTech Files Approval Subdomain Name
eXtendFloorXL
eXtendFloorXL Subdomain
eXtendFrame
eXtendFloorXL FN Subdomain
eXtendMobile
eXtendMobile Subdomain
eXtendPresentation
eXtendTech Presentation Subdomain
eXtendPS-SE
eXtendPS-SE Sub Domain
eXtendSanMar
eXtendTech SanMar Subdomain
eXtendWebApprovals
eXtendTech Web Approval Sub Domain

Step 2: Identify how each eXtendApp authenticates

Each eXtendApp authenticates with NetSuite in one of two ways, and the two behave differently during a refresh or provisioning.

  • Access tokens don't transfer. NetSuite doesn't copy access tokens from Production, so you need to generate new tokens in the new account.
  • OAuth 2.0 client credentials (M2M) do transfer. The credential records copy over, but they only work when the associated employee still has login access and the matching role.
eXtendApp
Authentication method
eXtendASI/ESP DE (with Order Integration)
OAuth 2.0 client credentials (M2M)
eXtendFiles
OAuth 2.0 client credentials (M2M)
eXtendFrame
OAuth 2.0 client credentials (M2M)
eXtendMobile
OAuth 2.0 client credentials (M2M)
eXtendFloorXL
Access token
eXtendPresentation
Access token
eXtendPS-SE
Access token
eXtendWebApprovals
Access token

eXtendAlphaBroder and eXtendSanMar need only the subdomain steps in Step 1 and Step 5.

Step 3: Generate new access tokens

Applies to eXtendFloorXL, eXtendPresentation, eXtendPS-SE, and eXtendWebApprovals.

  1. Go to SetupCompanyEnable FeaturesSuiteCloud subtab, then confirm Token-based authentication is enabled in the Manage Authentication field group.
  2. Confirm the employee who generates the token has the server user role for the app, such as Your Company Name eXtendFloorXL Server User.
  3. Generate a new access token for each installed app that uses one. See Generating a new Access Token.
    Image Placeholder
  4. Copy the token ID and token secret into the app's setup page, then save the page.

Note: NetSuite shows the token ID and token secret only once. Copy them before you leave the page.

Step 4: Validate the OAuth 2.0 client credentials (M2M)

Applies to eXtendASI/ESP DE (with Order Integration), eXtendFiles, eXtendFrame, and eXtendMobile.

Your OAuth 2.0 Client Credentials (M2M) records copy from Production to the Sandbox or Release Preview account during the refresh or provisioning, so you usually don't need to create new credentials. A copied credential only works when the employee (entity) it was created against meets all of these conditions in the new account:

  • The employee has login access in the new account.
  • The employee has the same role assigned that the credential was generated against.
  • The employee record has been saved in the new account. In rare cases, you need to edit and save the record before the credential works.

Note: These conditions matter most when your company restricts Sandbox login access, or when login access doesn't carry over during the refresh.

To validate the credentials:

  1. Go to SetupIntegrationManage AuthenticationOAuth 2.0 Client Credentials (M2M) Setup.
  2. Find the row for each eXtendApp's current certificate record, then note the Entity and Role. Use the table below to match the integration record to the app.
  3. Open that employee record and confirm login access is granted and the role from step 2 is assigned.
  4. Grant login access or add the role if either is missing, then save the employee record.
  5. If both look correct but the app still can't authenticate, click Edit on the employee record and save it without other changes.
  6. Confirm the Certificate ID and Certificate Type on the app's setup page match the credential you're using.
SuiteApp
Role
Integration record
eXtendASI/ESP DE
eXtendASI Server User
eXtendASI Order
eXtendFiles
eXtendFiles Server User
eXtendTech Files
eXtendFrame
eXtendFn Server User
eXtendFrame Functions
eXtendMobile
eXtendMobile Server User
eXtendMobile

When to create new credentials

Create new OAuth 2.0 client credentials only when valid credentials aren't already present in the account. Don't add duplicate credentials, and don't revoke credentials that work.

NetSuite lets you add a certificate to a specific application and entity combination only once, so confirm the entity and role before you create anything. All eXtendApps use the same eXtendTech certificate, so you can upload the same certificate file for each application. Contact eXtendTech Support if you're unsure whether a certificate needs to be added or updated.

Step 5: Confirm the new subdomain in each eXtendApp

  1. Open the setup page for each installed eXtendApp.
  2. Confirm the Subdomain field shows a new value for this account instead of the Production value.
  3. Click Save.

For eXtendFiles, follow the steps in the next section.

Step 6: Complete the eXtendFiles configuration

  1. Go to eXtendTecheXtendFileseXtendFiles Configuration, then select eXtendFiles SettingsAuthentication & Preferences. If an error occurs and the page fails to load, contact eXtendTech Support.
  2. Confirm your Sandbox or Release Preview subdomain appears in the Subdomain field, then click Save.
  3. Go to Storage SettingsGeneral and review your storage configuration. Click Save if the settings are correct, or enter the settings you want and then click Save.
    Image Placeholder
  4. Reauthenticate your storage if it requires authentication. Box, Dropbox, and Microsoft OneDrive/SharePoint often need to be reauthenticated. See Using eXtendFiles Configuration.
  5. Regenerate the approval and public upload URLs for this account. See Regenerating eXtendFiles Approval and Public Upload Links in Sandbox Environments.

Note: If you copy the storage information from Production and then select different storage in the Sandbox or Release Preview account, update the eXtendFiles Configuration page to match.

Frequently Asked Questions (FAQs)

Q: Do I need to repeat these steps after every Sandbox refresh?
A: Yes. NetSuite copies your Production settings each time, so the new account needs a unique subdomain and valid authentication again.

Q: Do my access tokens copy over from Production?
A: No. NetSuite doesn't copy access tokens during a Sandbox refresh or Release Preview provisioning. Generate new tokens in the new account.

Q: Do my OAuth 2.0 client credentials (M2M) copy over from Production?
A: Yes. The credential records transfer, but they only work when the associated employee has login access and the same role the credential was generated against.

Q: Why do I still see "Invalid Login Attempt" after reconfiguring?
A: The access token or certificate assigned to the app is missing, incorrect, or expired, or the employee lost login access or the required role. See "Invalid Login Attempt" from an eXtendTech Application or Integration.

Q: Does any of this affect my Production account?
A: No. These steps change only the account you're logged in to. Confirm you're in the Sandbox or Release Preview account before you begin.

Q: Who do I contact if something still doesn't work?