netsuite · netsuite-2026-2 · suitescript
NetSuite 2026.2 for Developers and Admins: The Changes That Touch Your Scripts
The NetSuite 2026.2 changes that reach code: CLI 4.0 output, the SuiteQL sort, SuiteScript 2.1 dates, REST saved search, 2FA and the tool object cutoff.
The deploy job that broke when the CLI started ignoring its flags
Say a team runs a nightly SDF pipeline. It installs the SuiteCloud CLI for Node.js from npm, runs project:deploy --validate against a sandbox, and then a small shell step greps the output for the line that used to mean "deployment finished". Someone bumps the CLI to 4.0 while fixing an unrelated dependency. The next run prints a warning nobody reads, the grep no longer matches anything, and the job is marked failed even though the deployment went through. Or the opposite happens: the grep was written loosely, it still matches, and the team keeps believing --validate is doing something.
Both outcomes come from one paragraph in the 2026.2 release notes. CLI for Node.js 4.0.0 removed local validation. Validation now happens on the server by default, project:validate --server and project:deploy --validate have no effect, and the output of validation, preview and deployment changed. Oracle's own instruction is to update anything that reads or parses that output and to stop relying on its format.[1]
That is what most of 2026.2 looks like from the developer side. Very little fails with an error. Behavior moves underneath code that was written against the old behavior, and the code keeps running. This page goes through the changes in the 2026.2 release notes and the August and September minor releases that reach scripts, integrations and pipelines, and links to the longer write-up where we have one. The features are not in your account until it is upgraded to 2026.2, and the version shows at the bottom of the Home page.[2]
CLI 4.0 moved validation to the server and changed every line of output
The changes in the SuiteCloud SDK section, in the order they are likely to hurt:[1]
- CLI for Node.js 4.0.0: local validation removed, server validation by default,
--serverand--validateignored with a warning. Oracle asks you to remove both options from commands and automation, and to review pipelines that do deployment previews with--dryrun. - Output for validation, preview and deployment changed in the CLI. Output for validation and deployment changed in the VS Code extension 4.0.0 and in the WebStorm plug-in 2026.2. In all three that covers progress messages, summaries, warnings and errors.
- CLI for Node.js 4.1.0 adds
suitecloud config:import, which imports the feature configuration from the account into an account customization project. - SuiteCloud CLI for Java has reached end of support. The final version is 2025.2, and it stays downloadable until 2027.1.
The fix for the pipeline above is to decide pass or fail on the process exit code, not on text, and to pin the CLI version in the pipeline so an upgrade is a commit somebody reviews. If you still run the Java CLI in a build agent, that agent has until 2027.1 before a fresh machine cannot install it.
SuiteQL now sorts generic transactions by date unless you say otherwise
2026.2 changed the default sort for SuiteQL and datasets that read generic transaction data from Transaction.tranDisplayName to Transaction.tranDate.[3] A query without ORDER BY can return the same rows in a different sequence. Nothing errors.
Where this breaks is paging. A REST SuiteQL export that walks the result in pages, or a script that resumes from "the last row I saw", assumed an order the query never asked for. Many transactions share a date, so a date-ordered result has ties, and ties can land on either side of a page boundary. We walked through the failure, and why the fix is an explicit ORDER BY with a unique tiebreaker such as the internal ID, in the SuiteQL default sort article. If you page with REST, why OFFSET is ignored in SuiteQL pagination is the next thing to read.
The same section moves the default export format for lists, saved searches and reports from .xls to .xlsx.[3] Any downstream job that picks up exported files by extension, or opens them with an .xls-only library, needs a look.
SuiteScript 2.1 is the standard, and 2028.2 is when the rest stops running
As of 2026.2, SuiteScript 2.1 is the standard version for new and existing scripts. Oracle published the milestones:[4]
| Release | What changes |
|---|---|
| 2026.2 | 2.1 becomes the standard for new and existing scripts |
| 2027.1 | SuiteScript 1.0 enters end-of-life support, critical issues only |
| 2028.1 | 1.0 can no longer be deployed in new accounts; 2.0 and 2.x run as 2.1 by default |
| 2028.2 | All scripts must use 2.1; legacy versions no longer run |
The scope is wider than "old 1.0 code". It includes every script annotated @NApiVersion 2.0 and every script annotated @NApiVersion 2.x. The 2.1 runtime runs server scripts on the Graal engine with ECMAScript 2023 support, where 2.0 targets ECMAScript 5.1.[5] Oracle's advice is to test 2.0 and 2.x server scripts under the company preference that runs them in the 2.1 runtime before you change a single annotation.[4]
The September minor release added a conversion path that keeps the script record. You can replace the file on a 1.0 script record with a 2.1 file of the same script type, through the UI, SDF or SuiteBundler, and NetSuite updates the record's API version to 2.1.[6] The script record stays in place, so you are not rebuilding deployments by hand.
This is the item in the release that deserves a project plan instead of a ticket. Everything else on this page is a change you can fix in an afternoon once you find it. The 2.1 move has a fixed end date, touches every account with history, and the hardest part is not the conversion but knowing which scripts you have. We have three pieces on it:
- What Oracle's migration push and AI skill actually do
- Building the real inventory of non-2.1 scripts, including why the script list says 2.0 when the file says 2.x
- The conversions from the upgrade skill that compile and still change behavior
The dates in one place, together with the authentication deadlines below, are in the 2026.2 to 2028.2 release timeline.
Custom tools on the old tool object can no longer be deployed
If you built custom tools for the NetSuite AI Connector Service, check which SDF object they use. The tool object was replaced by toolset in 2026.1.[14] With the September minor release, custom tools that use tool can no longer be deployed, new or updated, and in 2027.1 they will no longer execute.[6] A tool that works today keeps working until 2027.1. The first time someone needs to change it, the deploy fails.
Related changes in the same window:
- Toolset deployment now validates the custom tool script and its JSON-RPC schema.[7]
- Administrators can activate or deactivate toolsets on the Custom Tools page. Tools in an inactive toolset cannot be discovered or executed through the AI Connector Service. Existing toolsets were set to active.[6]
- A new
agentskillSDF object points at a folder containing SKILL.md. In an account customization project that folder sits under Skills at the File Cabinet root.[7] - Custom records, custom fields and transactions have an AI Description field of up to 280 characters, used by AI features such as the AI Connector Service.[8]
REST picked up saved searches, File Cabinet records and bound parameters
Three REST changes remove reasons teams kept RESTlets or SOAP around.
SuiteQL over REST accepts anonymous bound parameters. The example from the release notes:[9]
POST {{REST_SERVICES}}/query/v1/suiteql
Prefer: transient
{
"q": "SELECT * FROM item WHERE id BETWEEN ? AND ?",
"params": ["-7", "0"]
}
If your integration builds SuiteQL by concatenating values into the string, this is the change to adopt first. The same section adds sequential processing for REST batch operations, which run in the order given in the request. That matters for parent and child records that reference the parent by external ID.
The September minor release added saved search retrieval and execution to REST, both synchronous and asynchronous, and REST access to File Cabinet files and folders through a document service at /services/rest/document/v1/file and /services/rest/document/v1/folder.[6] The saved search endpoint runs the search as saved. A SOAP integration that added criteria at request time does not port over one-to-one, and the REST saved search article covers where that bites.
For SuiteApp publishers, the SuiteApp Control Center REST API adds PATCH to publish or deprecate a version, PUT to upgrade installations, and GET filters by managed-upgrade eligibility and phase. It requires the Release Manager role.[10]
Authentication changes ship now and enforce in 2027.1
The authentication section reads like a 2026.2 item, but most of the deadlines are in 2027.1:[11]
- From September 21, 2026, administrators can require 2FA for all Employee roles. In 2027.1 it is enabled automatically, and administrators can turn it off.
- In 2027.1, NLAuth integrations stop working, except existing IssueToken integrations.
- From 2027.1, no new token-based authentication integrations can be created. End of support for TBA is tentatively 2028.2.
- PKCE becomes required for new OAuth 2.0 authorization code integrations in 2027.1.
- Passkeys are available for login, and in 2026.2 a FIDO2 passkey can serve as the 2FA factor.
The item to check now is any automation that signs in to the UI as an employee with only a password. Once 2FA covers all employee roles, that sign-in needs a second factor it does not have. Separating the authentication migration from the API migration, and what 2027.1 blocks versus what still runs, is in the SOAP, TBA and OAuth 2027.1 article.
Event Subscriber went quiet, and the AI APIs changed twice
In August, Oracle's help center documented Event Subscriber scripts: server scripts that run asynchronously after a supported record event such as create, update or delete, for follow-up work that does not need to finish before the record save completes. On October 1, 2026 that help page returns 404, and neither the 2026.2 release notes nor the August and September minor release notes list the script type. Confirm it exists in your account before you design around it. How it differs from user event scripts, as documented in August, is in the Event Subscriber article.
The AI-facing SuiteScript APIs changed in both minor releases:
runtime.isNextActive()reports whether NetSuite Next is active for the user running the script, in client and server scripts.[7] What it does not tell you about role access is in the NetSuite Next access article.ociConfigis no longer supported in N/llm, N/documentCapture and N/task. Passing it raises no error, and the values are ignored.[7] Code that passed its own OCI configuration now runs without it, and nothing fails to tell you.llm.getRemainingUsage()replaces the deprecated free-usage functions, which still work by calling it.[7]- For the GPT OSS model,
options.modelParameters.reasoningEfforttakesllm.ReasoningEffort.LOW,MEDIUMorHIGH, defaultMEDIUM. Oracle notes that higher effort increases token use and therefore AI Unit usage. The same model now acceptsoptions.responseFormatwith a JSON schema.[6]
What AI Units cost and how the pool is shared is in the AI Units pricing article.
Smaller changes that will show up as tickets
- Units Type records can now be imported through CSV Import, under Accounting, with Multiple Units of Measure enabled.[12]
- Advanced Record Customization at Customization > Advanced Record Customization lets an administrator override record definitions at account level, starting with AI Description. Where an override exists, changes made elsewhere, including by partner SuiteApps, are not applied.[8] If an AI description shipped by a SuiteApp does not show up, check for an override before you open a case.
- Usage records in SuiteBilling do not support user event scripts.[13] Where deduplication has to live as a result is in the usage billing article.
- Intelligent Close Manager takes user-defined close tasks on a Custom tab in its portlet.[7] More in the close manager article.
Where this list stops being enough
A release note tells you what changed in NetSuite. It does not tell you which of your scripts depend on the old behavior, and that is the part that takes the time. The SuiteQL sort change only matters for queries without ORDER BY that page or resume. The tool cutoff only matters if you built tools before 2026.1. The 2.1 timeline matters for everyone, but its size depends on how many 2.0 and 2.x scripts you have, and the script list understates that.
Some of what is listed here is also phased. The August minor release notes say NetSuite Next availability rolls out in phases, and Oracle ships minor releases monthly within 2026.2, so a feature present in one account can be missing in another on the same version.[7] Test in a sandbox that has actually received the release before you plan around a feature.
For the finding part, MokuBot is an AI agent for NetSuite that works from a side panel in your account under your permissions. It runs SuiteQL and reads SuiteScript, so the list of 2.0 and 2.x scripts and the hunt for paged queries without ORDER BY can happen inside the account instead of in an export. If you would rather have someone do the 2.1 or authentication work with you, write to sales@mokuhub.com.
Sources
- NetSuite 2026.2 Release Notes: SuiteCloud SDK
- NetSuite 2026.2 Release Notes
- NetSuite 2026.2 Release Notes: SuiteAnalytics
- NetSuite 2026.2 Release Notes: SuiteScript
- SuiteScript 2.1
- NetSuite 2026.2 September Minor Release
- NetSuite 2026.2 August Minor Release
- NetSuite 2026.2 Release Notes: SuiteBuilder
- NetSuite 2026.2 Release Notes: SuiteTalk Web Services
- NetSuite 2026.2 Release Notes: SuiteApp Distribution
- NetSuite 2026.2 Release Notes: Authentication
- NetSuite 2026.2 Release Notes: CSV Import
- Creating Usage Records
- SDF XML Reference: toolset