I stand corrected sorry: (from NS article) For a RESTlet called from a client hosted by NetSuite, you do not need to pass authentication information in the HTTP request. A check for all valid NetSuite session cookies occurs, and this existing session is reused.