Prepare the right account first
Use an NMS2S account that is authorized for the organization and facilities you intend to connect. Confirm that you can sign in to the state application directly before beginning the Waputu setup. If that access is missing, start with the state account administrator or official support resources. A connector cannot resolve an account that does not have the underlying state access.
The CCD maintains links to NMS2S training and account-management resources. Use those materials for the state platform itself. The browser-token procedure described here is the current Waputu implementation; it is not presented as a vendor-endorsed token-issuance method. Keep an authorized operator involved throughout the connection, particularly when a shared computer or more than one organization is involved.
Source: Official CCD NMS2S resources.
Locate the token without copying the whole request
Sign in at https://www.nms2s.org in your own browser. Open the browser developer tools, select Network and reload the authenticated page. Select a state API request and inspect its request details. In the current connector procedure, look for authTokenGUID in the query-string parameters; a form submission may show it in the request payload or form data instead. Copy only the value, not the complete request URL or request body.
Do not export a network capture or share a full request to ask where the token is. Those artifacts can contain account credentials and other sensitive details. If the expected field is absent, return to the current in-app guide rather than guessing a replacement field. The state interface and request format can change, so the written connector guidance should be checked before following an old screenshot.

Enter the value in the protected workspace
Sign in to your own Waputu workspace as an owner or administrator and complete the required MFA step. Open the state-connection settings and paste the token into the connection form. Submit it through that protected flow. Do not put the value into a product field, label QR destination, browser bookmark or issue description. A label QR is public-facing content and has no role in storing a state credential.
The application stores connection credentials encrypted. The visible form clears the token after use, reducing the chance that another operator will encounter it on the screen. Those controls complement careful handling; they do not make it safe to circulate the original token. If you believe the value was exposed, stop sharing the artifact and arrange authorized credential recovery through the appropriate account process.
Verify the facilities that actually connected
After the connection step, review the facilities available to the workspace. Match them to the organization you intended to connect. Do not treat a successful response as evidence that every location has the correct access. A team with several facilities should check each relevant context before making inventory decisions.
Next, inspect the records and their freshness. Connection success, synchronization success and the presence of a particular lot are separate observations. Search for a known identifier and compare the selected facility and expected product. If the record is not there, preserve those details for investigation. This is more useful than reconnecting repeatedly, which can obscure whether the original problem was authorization, timing or the selected location.

Keep setup separate from state business actions
Connecting an account does not itself authorize an operator to create arbitrary inventory. Waputu limits its state business-write workflow to sublot creation, with a review of the actual parent, unit, quantity, children and remainder. Team access and facility permissions still apply after a state connection has been saved.
For the first operational use, choose the intended facility and review a known parent carefully. Do not perform a test split on live regulated inventory simply to check whether the connection works. Read-only verification is suitable for proving access; a real split needs a real business purpose and correct quantities. Likewise, generating or reprinting a label PDF should not be used as a substitute for reviewing the source lot.
Create a useful support handoff
If setup fails, note the workspace, the facility you expected, the time of the attempt and the non-sensitive error shown. Describe whether direct state sign-in works and whether any facilities or records appeared. These observations help distinguish an account-access problem from a local connection or read problem without exposing the credential itself.
For a team handoff, record who owns the connection and who can administer it. Keep recovery instructions somewhere the authorized team can find them, but store secrets only in the intended secure system. Review access when responsibilities change. A good setup is more than one successful paste: it leaves the organization with a clear owner, a verified facility context and a repeatable way to investigate future connection issues.
