{"_id":"@abarreraaponte/netsuite-oauth2-client","_rev":"3-c083ab0899ecf98fcccf63797b58c887","name":"@abarreraaponte/netsuite-oauth2-client","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@abarreraaponte/netsuite-oauth2-client","version":"0.1.0","keywords":["client-credentials","jwt","netsuite","oauth2","restlet","suitetalk"],"author":"Alejandro Barrera Aponte","license":"Apache-2.0","_id":"@abarreraaponte/netsuite-oauth2-client@0.1.0","maintainers":[{"name":"abarreraaponte","email":"alebarrera76@gmail.com"}],"dist":{"shasum":"5fcf5800be8f794b6ae6e92b1b9724d97d96f6e3","tarball":"https://registry.npmjs.org/@abarreraaponte/netsuite-oauth2-client/-/netsuite-oauth2-client-0.1.0.tgz","fileCount":21,"integrity":"sha512-EYeb4pvhZ0RIkgzlMAhzjEb0TYbP39A3GT3QpnNIUKI4Je+0XW5pZYOeIhgod7ldfNQsKSfR5/rAh5Lxzxq6TA==","signatures":[{"sig":"MEUCIQCOGh/QavUP5hIqAMPo3loJVQwSjG8hAe/OOA+cGK3/XwIgJwr5mHLkWzxr7OSLZR37NyvHB88O001x1E8BKhSa/hg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":43782},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.mts","exports":{".":{"types":"./dist/index.d.mts","import":"./dist/index.mjs"},"./skill":"./skills/netsuite-oauth2-client/SKILL.md","./oauth2":{"types":"./dist/oauth2.d.mts","import":"./dist/oauth2.mjs"}},"scripts":{"test":"vitest run","build":"tsdown","clean":"rm -rf dist","format":"oxfmt --write .","sample":"tsx --env-file=.env sample.ts","format:check":"oxfmt --check ."},"_npmUser":{"name":"abarreraaponte","email":"alebarrera76@gmail.com"},"devEngines":{"packageManager":{"name":"pnpm","onFail":"download","version":"^11.10.0"}},"description":"High-performance OAuth 2.0 Client Credentials client for Oracle NetSuite, featuring automatic token generation and caching.","directories":{},"_nodeVersion":"26.0.0","dependencies":{"jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.1","oxfmt":"^0.59.0","tsdown":"^0.22.9","vitest":"^4.1.10","typescript":"^7.0.2","@types/jsonwebtoken":"^9.0.6"},"_npmOperationalInternal":{"tmp":"tmp/netsuite-oauth2-client_0.1.0_1784767175594_0.3091996699847066","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@abarreraaponte/netsuite-oauth2-client","version":"0.2.0","keywords":["client-credentials","jwt","netsuite","oauth2","restlet","suitetalk"],"author":"Alejandro Barrera Aponte","license":"Apache-2.0","_id":"@abarreraaponte/netsuite-oauth2-client@0.2.0","maintainers":[{"name":"abarreraaponte","email":"alebarrera76@gmail.com"}],"dist":{"shasum":"ee6ecc1a4aebc477be60820f8aab57bfcda42258","tarball":"https://registry.npmjs.org/@abarreraaponte/netsuite-oauth2-client/-/netsuite-oauth2-client-0.2.0.tgz","fileCount":21,"integrity":"sha512-t62nkNIxwVgmNTEm8cHl+gDb95mK4R19LV5ukSCQ6e1o+3MiYOrk36e0hY7xc8AAY67GXYMrFJb5LrvD1wvb0A==","signatures":[{"sig":"MEUCIQCIlOLf03aKA34sm6A9PZDPcXPK3wOBOAONwkQz+1E6FgIgEC1nuk5cK0yTZAXzFL83mY89djc8yGXlkowKyVPEYcU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abarreraaponte%2fnetsuite-oauth2-client@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":43902},"main":"./dist/index.mjs","type":"module","types":"./dist/index.d.mts","exports":{".":{"types":"./dist/index.d.mts","import":"./dist/index.mjs"},"./skill":"./skills/netsuite-oauth2-client/SKILL.md","./oauth2":{"types":"./dist/oauth2.d.mts","import":"./dist/oauth2.mjs"}},"scripts":{"test":"vitest run","build":"tsdown","clean":"rm -rf dist","format":"oxfmt --write .","sample":"tsx --env-file=.env sample.ts","format:check":"oxfmt --check ."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:28cc0523-a106-48d9-a57a-8faf27d51913"}},"devEngines":{"packageManager":{"name":"pnpm","onFail":"download","version":"^11.10.0"}},"repository":{"url":"git+https://github.com/abarreraaponte/netsuite-oauth2-client.git","type":"git"},"description":"High-performance OAuth 2.0 Client Credentials client for Oracle NetSuite, featuring automatic token generation and caching.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"jsonwebtoken":"^9.0.2"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.1","oxfmt":"^0.59.0","tsdown":"^0.22.9","vitest":"^4.1.10","typescript":"^7.0.2","@types/jsonwebtoken":"^9.0.6"},"_npmOperationalInternal":{"tmp":"tmp/netsuite-oauth2-client_0.2.0_1784767496104_0.3452823298792649","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@abarreraaponte/netsuite-oauth2-client","version":"0.3.0","description":"High-performance OAuth 2.0 Client Credentials client for Oracle NetSuite, featuring automatic token generation and caching.","keywords":["client-credentials","jwt","netsuite","oauth2","restlet","suitetalk"],"license":"Apache-2.0","author":"Alejandro Barrera Aponte","repository":{"type":"git","url":"git+https://github.com/abarreraaponte/netsuite-oauth2-client.git"},"type":"module","main":"./dist/index.mjs","types":"./dist/index.d.mts","exports":{".":{"types":"./dist/index.d.mts","import":"./dist/index.mjs"},"./oauth2":{"types":"./dist/oauth2.d.mts","import":"./dist/oauth2.mjs"},"./skill":"./skills/netsuite-oauth2-client/SKILL.md"},"dependencies":{"jsonwebtoken":"^9.0.2"},"devDependencies":{"@types/jsonwebtoken":"^9.0.6","oxfmt":"^0.59.0","tsdown":"^0.22.9","tsx":"^4.19.1","typescript":"^7.0.2","vitest":"^4.1.10"},"devEngines":{"packageManager":{"name":"pnpm","version":"^11.10.0","onFail":"download"}},"scripts":{"build":"tsdown","clean":"rm -rf dist","test":"vitest run","format":"oxfmt --write .","format:check":"oxfmt --check .","sample":"tsx --env-file=.env sample.ts"},"_nodeVersion":"22.23.1","_id":"@abarreraaponte/netsuite-oauth2-client@0.3.0","dist":{"integrity":"sha512-xx1VzTj5qX4/0tgV7mEJKFRSLnpSOj5SxPjJt4Moxrz7su2cuQW0WfTcekYlSmwNjYLXsygZtklrkKr/Rwrg9A==","shasum":"54628b82580ef2daf5a913922f632f4a6214a962","tarball":"https://registry.npmjs.org/@abarreraaponte/netsuite-oauth2-client/-/netsuite-oauth2-client-0.3.0.tgz","fileCount":21,"unpackedSize":50744,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abarreraaponte%2fnetsuite-oauth2-client@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDzDLAZWvUxH1RSpGmBSWqUAI/6tlkA41gs8uU/zL7XgwIgCgoqRVU24YnbFPxNT9V8dCNWsVfwM19FftYyo/ujPuQ="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:28cc0523-a106-48d9-a57a-8faf27d51913"}},"directories":{},"maintainers":[{"name":"abarreraaponte","email":"alebarrera76@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/netsuite-oauth2-client_0.3.0_1784768400221_0.0121236244453371"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-23T00:39:35.423Z","modified":"2026-07-23T01:00:00.877Z","0.1.0":"2026-07-23T00:39:35.720Z","0.2.0":"2026-07-23T00:44:56.231Z","0.3.0":"2026-07-23T01:00:00.350Z"},"author":"Alejandro Barrera Aponte","license":"Apache-2.0","keywords":["client-credentials","jwt","netsuite","oauth2","restlet","suitetalk"],"repository":{"type":"git","url":"git+https://github.com/abarreraaponte/netsuite-oauth2-client.git"},"description":"High-performance OAuth 2.0 Client Credentials client for Oracle NetSuite, featuring automatic token generation and caching.","maintainers":[{"name":"abarreraaponte","email":"alebarrera76@gmail.com"}],"readme":"# @abarreraaponte/netsuite-oauth2-client\n\n> **Legal Disclaimer:** NetSuite is a registered trademark of Oracle Corporation. This project is an independent open-source library and is not affiliated with, sponsored by, or endorsed by Oracle Corporation or NetSuite.\n\n---\n\nHigh-performance, type-safe, and lightweight OAuth 2.0 Client Credentials client for Oracle NetSuite, built specifically for server-to-server (M2M) integrations.\n\n> [!NOTE]\n> This library supports **only** the OAuth 2.0 Client Credentials flow (using private key JWT assertions). Other flows like Authorization Code or Resource Owner Password Credentials are not supported.\n\n---\n\n## Features\n\n- **ESM-First & Lightweight:** Fully optimized for ESM, zero external bloating dependencies, and compatible with modern runtimes (Node.js, serverless, edge).\n- **Asymmetric JWT Assertion:** Implements robust token assertions using private PEM keys and JSON Web Tokens.\n- **Pluggable Token Caching:** Simple, standard caching interfaces (`TokenStorage`) allowing you to plug in Redis, SQL database, Prisma, or in-memory storages.\n- **AI Agent Compatible:** Clean TypeScript types and docstrings making it perfectly suited for LLM toolchains and autonomous coding agents.\n\n---\n\n## Installation\n\n```bash\npnpm add @abarreraaponte/netsuite-oauth2-client\n# or\nnpm install @abarreraaponte/netsuite-oauth2-client\n```\n\n---\n\n## Usage\n\nConfigure the client by supplying your NetSuite Account ID, Consumer Key, Consumer Secret, Certificate ID, and Private Key:\n\n```typescript\nimport {\n  NetSuiteClientCredentialsClient,\n  type TokenStorage,\n  type TokenData,\n} from \"@abarreraaponte/netsuite-oauth2-client\";\n\n// Implement the TokenStorage interface to cache tokens\nclass MemoryTokenStorage implements TokenStorage {\n  private cache: TokenData | null = null;\n\n  async getToken(): Promise<TokenData | null> {\n    return this.cache;\n  }\n\n  async saveToken(token: TokenData): Promise<void> {\n    this.cache = token;\n  }\n}\n\nconst authClient = new NetSuiteClientCredentialsClient(\n  {\n    accountId: \"123456_SB1\",\n    consumerKey: \"YOUR_CONSUMER_KEY\",\n    consumerSecret: \"YOUR_CONSUMER_SECRET\",\n    certificateId: \"YOUR_CERTIFICATE_ID\",\n    privateKey: `-----BEGIN PRIVATE KEY-----\\n...\\n-----END PRIVATE KEY-----`,\n  },\n  new MemoryTokenStorage(),\n);\n\n// Automatically returns the cached token, or fetches a new one if expired\nconst accessToken = await authClient.getCurrentToken();\n\nconst response = await fetch(\n  \"https://123456-sb1.suitetalk.api.netsuite.com/services/rest/record/v1/metadata-catalog\",\n  {\n    headers: {\n      Authorization: `Bearer ${accessToken}`,\n    },\n  },\n);\n```\n\n---\n\n## Configuration Options\n\nThe `NetSuiteClientCredentialsClient` constructor accepts a configuration object matching the `NetSuiteClientCredentialsConfig` interface:\n\n| Option           | Type     | Required | Description                                                                                                           |\n| ---------------- | -------- | -------- | --------------------------------------------------------------------------------------------------------------------- |\n| `accountId`      | `string` | **Yes**  | Your NetSuite Account ID (e.g. `123456` or sandbox `123456_SB1`). Normalizes internally.                              |\n| `consumerKey`    | `string` | **Yes**  | The client ID / Integration Consumer Key generated in NetSuite.                                                       |\n| `consumerSecret` | `string` | **Yes**  | The client secret / Integration Consumer Secret generated in NetSuite.                                                |\n| `certificateId`  | `string` | **Yes**  | The Certificate ID (`kid`) from the NetSuite Client Credentials Setup mapping.                                        |\n| `privateKey`     | `string` | **Yes**  | The PEM-formatted private key corresponding to your certificate.                                                      |\n| `algorithm`      | `string` | No       | JWT signing algorithm. Options: `\"PS256\"`, `\"PS384\"`, `\"PS512\"`, `\"ES256\"`, `\"ES384\"`, `\"ES512\"`. Default: `\"PS256\"`. |\n\n---\n\n## Generating Keys & Certificates (OpenSSL)\n\nDepending on your security architecture, you can use either **RSA-PSS** (recommended for RSA) or **ECDSA** (Elliptic Curve, offering faster signing and smaller keys) signatures.\n\nGenerate your private key and self-signed certificate using the corresponding OpenSSL commands:\n\n| Algorithm | Key Type        | Private Key Generation                                                                 | Self-Signed Certificate (Public)                                         |\n| --------- | --------------- | -------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |\n| **PS256** | RSA (2048-bit)  | `openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:2048`        | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n| **PS384** | RSA (3072-bit)  | `openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:3072`        | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n| **PS512** | RSA (4096-bit)  | `openssl genpkey -algorithm RSA -out private.pem -pkeyopt rsa_keygen_bits:4096`        | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n| **ES256** | EC (prime256v1) | `openssl genpkey -algorithm EC -out private.pem -pkeyopt ec_paramgen_curve:prime256v1` | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n| **ES384** | EC (secp384r1)  | `openssl genpkey -algorithm EC -out private.pem -pkeyopt ec_paramgen_curve:secp384r1`  | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n| **ES512** | EC (secp521r1)  | `openssl genpkey -algorithm EC -out private.pem -pkeyopt ec_paramgen_curve:secp521r1`  | `openssl req -new -x509 -key private.pem -out certificate.pem -days 365` |\n\n### Setting Up in NetSuite:\n\n1. Upload the generated `certificate.pem` to your NetSuite mapping settings under **Setup > Integration > OAuth 2.0 Client Credentials Setup**.\n2. Copy the resulting **Certificate ID** mapping.\n3. Load the `private.pem` content (private key) in your backend environment variables to initialize the client.\n\n---\n\n## Local Sample Script\n\nTo test the integration locally without setting up a pnpm workspace:\n\n1. Copy the example env file at the root:\n   ```bash\n   cp .env.example .env\n   ```\n2. Fill in the required NetSuite credentials in `.env`.\n3. Run the sample script:\n   ```bash\n   pnpm run sample\n   # or\n   npm run sample\n   ```\n\n---\n\n## Caching Implementations\n\n### Redis Cache Storage\n\n```typescript\nimport { createClient } from \"redis\";\nimport type { TokenStorage, TokenData } from \"@abarreraaponte/netsuite-oauth2-client\";\n\nclass RedisTokenStorage implements TokenStorage {\n  private client = createClient();\n  private key = \"netsuite:oauth_token\";\n\n  async getToken(): Promise<TokenData | null> {\n    const data = await this.client.get(this.key);\n    if (!data) return null;\n    return JSON.parse(data);\n  }\n\n  async saveToken(token: TokenData): Promise<void> {\n    const ttlSeconds = Math.max(1, Math.floor((token.expiresAt - Date.now()) / 1000));\n    await this.client.setEx(this.key, ttlSeconds, JSON.stringify(token));\n  }\n}\n```\n\n### Prisma SQL Cache Storage\n\n```typescript\nimport { PrismaClient } from \"@prisma/client\";\nimport type { TokenStorage, TokenData } from \"@abarreraaponte/netsuite-oauth2-client\";\n\nclass PrismaTokenStorage implements TokenStorage {\n  private prisma = new PrismaClient();\n\n  async getToken(): Promise<TokenData | null> {\n    const record = await this.prisma.netSuiteToken.findFirst({\n      orderBy: { expiresAt: \"desc\" },\n    });\n    if (!record) return null;\n    return {\n      accessToken: record.accessToken,\n      expiresAt: Number(record.expiresAt),\n    };\n  }\n\n  async saveToken(token: TokenData): Promise<void> {\n    await this.prisma.netSuiteToken.create({\n      data: {\n        accessToken: token.accessToken,\n        expiresAt: token.expiresAt,\n      },\n    });\n  }\n}\n```\n\n---\n\n## License\n\nThis package is open-source software licensed under the [Apache-2.0 License](./LICENSE).\n","readmeFilename":""}