If your NetSuite account has been humming along for years, you may have customizations quietly running in the background β automated approvals, custom records, integrations with your shipping or CRM systems. Many of these were built on SuiteScript 1.0, NetSuite’s original scripting language. Oracle has made its direction clear: 1.0 is on the way out, and the practical deadlines are now on the calendar. Here’s what that actually means for your business.
What Oracle has officially said
Oracle isn’t mincing words. In its official documentation on transitioning away from 1.0, it states that SuiteScript 1.0 scripts continue to be supported, “however, SuiteScript 1.0 functionality is no longer being updated, and no new feature development or enhancement work is being done for SuiteScript 1.0.”
In plain terms: your existing scripts keep working, but 1.0 is frozen. It won’t gain new capabilities, it won’t be improved, and Oracle actively encourages moving everything to the modern SuiteScript 2.x (versions 2.0 and 2.1). Any new or substantially revised customization, per Oracle, should be built on 2.x.
“Deprecated” is not the same as “turned off”
This is the single most important distinction β and the one that lulls businesses into inaction.
Deprecated means Oracle has officially discouraged using something and stopped investing in it. It still runs. Nothing breaks tomorrow. Turned off means it stops working entirely.
SuiteScript 1.0 is in the first category today. Your scripts execute normally, which is exactly why the risk is easy to ignore. But deprecation is the warning shot before retirement. The clock is ticking quietly in the background: every release that 1.0 sits frozen, the gap between your customizations and the supported platform widens, and the pool of developers who remember how 1.0 works shrinks.
The two hard deadlines you need on your calendar
Here’s where the abstract becomes concrete. Many older SuiteScript 1.0 integrations authenticate using older methods β specifically the NLAuth header and Token-Based Authentication (TBA). Oracle has now published firm dates for retiring TBA, and these are the deadlines that will actually break things:
- NetSuite 2027.1 β no new TBA integrations. Oracle’s documentation confirms that as of 2027.1, you can no longer create new integrations using TBA for SOAP web services, REST web services, and RESTlets (the small scripts that let outside systems talk to NetSuite). Existing ones keep running β for now.
- NetSuite 2028.1 (tentative) β existing integrations stop. Oracle states that support will later end for existing TBA integrations, tentatively in 2028.1, excluding SuiteAnalytics Connect. When that happens, any RESTlet, SOAP or REST integration, or third-party connector (think Celigo, Boomi, MuleSoft, Informatica) still using TBA will simply fail to authenticate. The replacement Oracle points to is OAuth 2.0.
If a connection your business depends on suddenly can’t log in, that’s not a cosmetic issue β that’s orders not flowing, data not syncing, and finance teams reconciling by hand.
Why this matters even without an in-house developer
It’s tempting to file this under “IT will handle it.” But most small and mid-sized NetSuite users don’t have a developer on payroll β the customizations were built years ago by a consultant who has since moved on. That’s precisely the risk. Nobody currently on your team may know which scripts exist, what they touch, or how they authenticate.
When a deadline arrives and something breaks, you don’t want to be starting from zero, scrambling to find someone who understands legacy 1.0 code under time pressure and at premium emergency rates. The businesses that come through this smoothly are the ones that mapped their exposure early, while there was time to plan calmly.
What to do now: start your inventory
You don’t need to rewrite anything today. You need to know what you have. Start building an inventory:
- Which SuiteScript 1.0 scripts are still active in your account?
- Which integrations authenticate with TBA or NLAuth rather than OAuth 2.0?
- Which third-party connectors touch NetSuite, and are they OAuth 2.0-ready?
- Who owns each one, and what business process breaks if it stops?
That single document turns a vague future threat into a concrete, prioritized to-do list β and gives you years, not weeks, to act.
Not sure where to start? We’ll map it for you β free.
The NetSuite Pro offers a complimentary audit consultation to identify your SuiteScript 1.0 scripts and TBA-dependent integrations, and to build you a clear migration roadmap ahead of the 2027.1 and 2028.1 deadlines. Book your free audit consultation today β and turn a looming deadline into a non-event.
Discover more from The NetSuite Pro
Subscribe to get the latest posts sent to your email.
Leave a Reply