Guidance for a Token broker pattern implementation

Hello and thank you in advance for any assistance

I am new to auth0, and I am currently doing the following implementation as in the following:

Actors:

  • ExpenseBot (NetSuite client)
  • Auth/Token Store
  • NetSuite Auth Endpoint

Workflow:

  1. ExpenseBot → Auth/Token Store: getAccessToken()

  2. Auth/Token Store:

    • Check cached token and its expiry time

3a) If cached token is still valid:
Auth/Token Store → ExpenseBot: return cached token (still valid)

3b) If cached token is expired:
Auth/Token Store → NetSuite Auth Endpoint: POST /oauth2/token (refresh token)

  1. NetSuite Auth Endpoint → Auth/Token Store:

    • returns new access_token (+ expires_in)
  2. Auth/Token Store:

    • persist new token in secure store
  3. Auth/Token Store → ExpenseBot:

    • return new auth token

To explain the case, basically we have a backend agent that processes information that later needs to be submited into netsuite, in the middle we want to implement oauth0 to handle the token management, as shown in the picture.

I am not exactly sure what steps I need to follow to achieve this. Currently after going through the docs I have this in mind:

create we app
define api
possibly a user identity?
Create a NetSuite OAuth2 Connection + Enable Token Vault
Enable My Account API

complement with the backend implementation for token interaction with oauth0

these are the steps that I am considering at the moment. would like to get some guidance to success with the use of auth0 best practices for this workflow.

Thanks again!

Hi @victor10

Welcome to the Auth0 Community!

I have moved your post to the Dev to Dev Hub category since it is better suited here then the Get Help one, I will reply shortly with some implementation guidance regarding the matter!

Kind Regards,
Nik

1 Like

Hi @nik.baleca

Awesome! Thank you for moving the post I will keep in mind for future ocassions.

Thank you in advance for your support!

Gratefully,
Victor

Hi again @victor10

No worries, since the topic focuses more on technical implementation and general guidance, it would fall into this category. There is no issue if it is posted somewhere else, we will take care of that nonetheless.

Otherwise, let us start talking about the implementation that you mentioned.

I understand you are asking how to register ExpensesBot (a backend agent), manage tokens and credentials, integrate a NetSuite authentication endpoint, and set up the overall architecture for your application.

Solution:

The setup depends on what ExpensesBot is and how you plan to integrate external systems. Here is the recommended architecture:

Registering ExpensesBot:

If ExpensesBot is your backend logic or agent (not an API), register it as a Machine-to-Machine application in the Auth0 Dashboard. Machine-to-Machine applications are designed for backend agents that communicate on behalf of your application to accomplish specific tasks. If ExpensesBot were an API that your application calls to complete tasks, you would register it as an API instead.

Token management and storage:

Auth0 handles token management, provisioning, and exchange automatically. Token expiration and lifetime settings are easily configured in the Dashboard and are included in the tokens themselves, even for Machine-to-Machine applications. If you need to store token credentials separately within your application or in an external store, you can read the token information once Auth0 issues it and store it accordingly for further use. Your backend can also handle authentication on behalf of your users using the appropriate OAuth flow if needed.

Integrating NetSuite as an external identity provider:

If NetSuite is an external identity provider (IdP) that you wish to integrate with Auth0, this is possible by creating an enterprise connection. Users will be able to authenticate against NetSuite and receive proper tokens, with an Auth0 identity automatically created. To complete this integration, you will need to configure Auth0’s public key or certificate on NetSuite’s end.

Complete setup checklist:

Follow these steps to implement the full architecture:

  1. Register your application. Register your primary application within Auth0 as either a Single Page Application (SPA) or Regular Web Application, depending on your architecture.

  2. Register your API. Register your application’s API as a resource server in Auth0.

  3. Register ExpensesBot as a Machine-to-Machine application. Register your backend agent as a Machine-to-Machine application, select your API, and assign the necessary scopes to complete its tasks. You will be able to access and store the token information once the transaction is completed.

  4. Create a dedicated user store. Create a user database specific to your application. While you can use the default user store, creating a separate database is recommended for better organization and security.

  5. Enable token vault for external credentials. Enable Auth0’s token vault feature to securely store NetSuite tokens and other external credentials.

  6. Configure the enterprise connection for NetSuite. If integrating NetSuite as an IdP, create an enterprise connection and configure Auth0’s public key or certificate on NetSuite’s end to enable secure authentication.

  7. Note on My Account API. The My Account API is currently in limited early access. You should be able to configure everything without it for the time being if it is not available for your tenant.

If there is anything else I have missed regarding the matter or if I can help with anything else/any other questions.

Kind Regards,
Nik