@creece I have experience writing RESTlets, but with a restlet I would have to store the oauth keys in the clientscript. which sounds like bad practice. for Suitelets do they accepts requests security from NS client scripts with out storing auth tokens?