@samantha because your process is dealing with validating security tokens it would make more sense to use a RESTlet because by its very nature accessing RESTlets require authentication. @alien4u is correct that Suitelets are easier to to deploy but you’d “lose” the security feature by making it available without login.