Hi again @victor10
No worries, since the topic focuses more on technical implementation and general guidance, it would fall into this category. There is no issue if it is posted somewhere else, we will take care of that nonetheless.
Otherwise, let us start talking about the implementation that you mentioned.
I understand you are asking how to register ExpensesBot (a backend agent), manage tokens and credentials, integrate a NetSuite authentication endpoint, and set up the overall architecture for your application.
Solution:
The setup depends on what ExpensesBot is and how you plan to integrate external systems. Here is the recommended architecture:
Registering ExpensesBot:
If ExpensesBot is your backend logic or agent (not an API), register it as a Machine-to-Machine application in the Auth0 Dashboard. Machine-to-Machine applications are designed for backend agents that communicate on behalf of your application to accomplish specific tasks. If ExpensesBot were an API that your application calls to complete tasks, you would register it as an API instead.
Token management and storage:
Auth0 handles token management, provisioning, and exchange automatically. Token expiration and lifetime settings are easily configured in the Dashboard and are included in the tokens themselves, even for Machine-to-Machine applications. If you need to store token credentials separately within your application or in an external store, you can read the token information once Auth0 issues it and store it accordingly for further use. Your backend can also handle authentication on behalf of your users using the appropriate OAuth flow if needed.
Integrating NetSuite as an external identity provider:
If NetSuite is an external identity provider (IdP) that you wish to integrate with Auth0, this is possible by creating an enterprise connection. Users will be able to authenticate against NetSuite and receive proper tokens, with an Auth0 identity automatically created. To complete this integration, you will need to configure Auth0’s public key or certificate on NetSuite’s end.
Complete setup checklist:
Follow these steps to implement the full architecture:
-
Register your application. Register your primary application within Auth0 as either a Single Page Application (SPA) or Regular Web Application, depending on your architecture.
-
Register your API. Register your application’s API as a resource server in Auth0.
-
Register ExpensesBot as a Machine-to-Machine application. Register your backend agent as a Machine-to-Machine application, select your API, and assign the necessary scopes to complete its tasks. You will be able to access and store the token information once the transaction is completed.
-
Create a dedicated user store. Create a user database specific to your application. While you can use the default user store, creating a separate database is recommended for better organization and security.
-
Enable token vault for external credentials. Enable Auth0’s token vault feature to securely store NetSuite tokens and other external credentials.
-
Configure the enterprise connection for NetSuite. If integrating NetSuite as an IdP, create an enterprise connection and configure Auth0’s public key or certificate on NetSuite’s end to enable secure authentication.
-
Note on My Account API. The My Account API is currently in limited early access. You should be able to configure everything without it for the time being if it is not available for your tenant.
If there is anything else I have missed regarding the matter or if I can help with anything else/any other questions.
Kind Regards,
Nik