Connect NetSuite to Claude with OAuth 2.0

Review the NetSuite features and restricted role needed for a Claude MCP connection, authorize the connection, and run a read-only customer query.

The quick answer

Enable or confirm REST Web Services and OAuth 2.0, review a restricted MCP role, authorize Claude as the intended NetSuite user, and test the connection with a read-only query.

The screenshots show sample data. Person and operating-company names are fictional. Use your own records and values when following the steps.

Before you start

Use an administrator or integration owner who can inspect features, roles, SuiteApps, and employee access. Verify the MCP Standard Tools SuiteApp is installed and that the authorizing user has the dedicated restricted role; confirm both before authorizing. Token-Based Authentication isn't automatically required for an OAuth 2.0 connection.

01. Check the SuiteCloud feature settings

On the Enable Features page, select the SuiteCloud section and inspect REST Web Services and OAuth 2.0. The replay shows both feature controls selected, while Token-based Authentication is shown separately. Its presence on the same page doesn't prove that the selected Claude connector requires it.

Review REST Web Services and OAuth 2.0 before starting the external authorization flow.

02. Confirm the tools SuiteApp is installed

Open the MCP Standard Tools listing and check its installation status. This recording shows Installed. Installation alone does not establish a working authenticated connection.

MCP Standard Tools listing with Installed status.

03. Check the restricted MCP role

Review the dedicated role's Setup permissions and confirm the visible entries include Log in using OAuth 2.0 Access Tokens, MCP Server Connection, and REST Web Services. The replay shows the MCP role with each permission at Full level. Keep the role limited to the records and operations the connection actually needs.

Inspect the MCP role permissions before assigning or authorizing the user.

04. Check the authorizing employee’s role

Open the intended employee record and inspect Access → Roles. Confirm the dedicated role is assigned to the same user who will authorize Claude. This example lists MCP.

Employee Access area with the MCP role assigned.

05. Open Claude settings

Open Claude Settings → Connectors and start the NetSuite connection flow available to your account. The recording shows Settings and then the authorization page; the intervening connector selection is not visible.

Start the connector flow from Claude Settings when the NetSuite connector is available.

06. Review the NetSuite authorization request

Review the account and role shown in the NetSuite authorization screen before accepting access. The replay identifies the account context and shows the request is made as role MCP, with access to personal information and permission to perform actions as MCP. A successful login alone isn't proof that Claude can retrieve NetSuite data.

Confirm the account and role before continuing with authorization.

07. Run a read-only customer query

After the authorization flow reports completion, ask Claude to list the customers available through the connection. The replay uses the query "tell me the customers i have in netsuite" and shows Claude retrieving a customer list through the NetSuite integration. Keep the request read-only and compare the returned scope with records the authorizing user can view in NetSuite.

Use a limited customer-list request to test read access.

08. Inspect the returned result

The replay shows Claude returning four active customers and displaying fields such as ID, entity ID, company, email, balance, and last sale. These displayed figures and classifications are retrieved output, not independently verified accounting or master-data conclusions. Review possible duplicate names or email addresses directly in NetSuite before taking any corrective action.

Treat the customer response as a read-access result that still requires NetSuite review.

Check the result

  1. REST Web Services and OAuth 2.0 are visibly enabled or otherwise confirmed as available for the selected connector.
  2. The authorizing employee has the intended restricted role and its permissions match the connection’s required scope.
  3. Claude returns an appropriate read-only customer result without requesting broader permissions.

Common questions

Which NetSuite features should I review before connecting Claude?

Go to Setup > Company > Enable Features > SuiteCloud and check whether REST Web Services and OAuth 2.0 are enabled. Token-Based Authentication is separate and is not automatically required for an OAuth 2.0 connection; confirm its need with the selected connector and account design.

How do I verify that the MCP SuiteApp is available?

Open the SuiteApp Marketplace and search for the MCP Standard Tools SuiteApp. Review its displayed installation status, but do not treat an Installed status as proof that authentication or data retrieval will work; Marketplace visibility, compatibility, licensing, and installation actions vary by account and role.

Which permissions should the restricted MCP role contain?

Review a dedicated, least-privilege role under its Setup permissions. It commonly includes MCP Server Connection, Log in using OAuth 2.0 Access Tokens, and REST Web Services, but permission names, required levels, record access, subsidiary restrictions, and available features differ by account and connector.

How do I confirm that the correct employee can authorize the connection?

Open the employee record’s Access area and confirm that the dedicated MCP role is assigned to the same employee who will authenticate the connection. Assignment only confirms configuration; after authorization, use a limited read-only request, such as listing accessible customers, and compare the result with NetSuite, since connector availability and returned data depend on account, role, and organization settings.

Supporting sources

Supporting documentation.