To connect an MCP client to a ServiceNow MCP server, create an OAuth inbound integration using OAuth – Authorization code grant, set its token format to JWT, and register the exact redirect URL supplied by the client. Then configure the client with your ServiceNow MCP server URL and OAuth endpoints, authenticate in the browser, and verify that the client discovers the server’s tools. CIMD is an alternative registration method on Australia Patch 1 / Zurich Patch 7 and later.
Before you begin
You need an MCP server on the ServiceNow instance you plan to connect to. It can be the Quickstart Server (sn_mcp_server_default) or a purpose-built server. You also need to know which MCP client will connect: its exact redirect URL is required when registering the OAuth integration, and client settings can differ by product.
- For standard inbound integration setup, you need the
oauth_admin,mi_admin, oradminrole. Creating an MCP server may separately requiresn_mcp_server.adminoradmin. - Get the redirect URL from the MCP client before creating the integration. Do not substitute a URL that merely looks similar.
- Decide which user identity should perform actions through the connection. A human-operated session uses the signed-in user; an autonomous agent should use a dedicated integration user with only the required roles and access.
ServiceNow MCP Server Console uses OAuth 2.0 Authorization Code Grant for this connection. It does not currently support the client-credentials grant for MCP Server Console, nor local or stdio MCP servers; use the supported remote Streamable HTTP transport.
Create a standard OAuth inbound integration
- In the ServiceNow instance, open All > Machine Identity Console > Inbound integrations. You can also start from the OAuth setup banner in MCP Server Console.
- Select New integration.
- Choose OAuth – Authorization code grant.
- Enter a name and paste the MCP client’s exact redirect URL into Redirect URL.
- Decide whether to restrict the integration to selected API scopes. Clearing the restriction makes it broadly scoped, so do not assume that is appropriate for a production connection. Confirm which scopes the chosen tools require and apply your organization’s least-privilege policy.
- Expand Advanced options and set Token Format to JWT.
- Save the integration. Securely retain its generated client ID and client secret for the client configuration.
The redirect URL in the integration is the address to which the client receives the authorization response. It must match the client’s registered value exactly, including scheme, host, path, and any relevant trailing slash. A mismatch commonly interrupts authorization.
#1 Best Overall
Configure the MCP client
In the client’s MCP server configuration, use the values below, replacing placeholders with the hostname and server name for your instance. Client forms use different labels, and some may not ask for every field; where a field is requested, enter the corresponding value.
| Client setting | Value |
|---|---|
| MCP server URL | https://<server-instance>.service-now.com/sncapps/mcp-server/mcp/<server-name> |
| Host | <server-instance>.service-now.com |
| Base URL | /sncapps/mcp-server |
| Scope | mcp_server |
| Authentication | OAuth 2.0 |
| Identity provider | Generic OAuth 2 |
| Authorization URL | https://<server-instance>.service-now.com/oauth_auth.do |
| Token URL | https://<server-instance>.service-now.com/oauth_token.do |
| Token revocation URL | https://<server-instance>.service-now.com/oauth_revoke.do |
| Refresh URL | https://<server-instance>.service-now.com/oauth_auth.do |
| Redirect URL, if requested as the ServiceNow callback | https://<server-instance>.service-now.com/oauth/callback |
| Client ID and client secret | The values generated for the inbound integration |
There are two redirect-related values to keep straight. The integration’s Redirect URL must be the exact redirect supplied by the client. Some client forms also ask for a ServiceNow callback value; in that field use https://<server-instance>.service-now.com/oauth/callback. Follow the client form’s labels rather than pasting one value into both fields without checking what each represents.
Rank #2
For ServiceNow AI Agent Studio, the documented form uses OAuth 2.1, Manual Registration, Authorization Code, and Client Secret Post, followed by the authorization, token, and revocation URLs. Use that client-specific configuration rather than assuming every MCP client exposes the same labels.
Authenticate and check tool discovery
- Save the MCP server connection in the client and select Authenticate.
- Complete the browser-based authorization and approve the consent prompt.
- Return to the client and confirm that the bearer token is accepted and the server’s tool list appears.
- Run a low-risk test that exercises a tool the configured user is allowed to use. For the Quickstart Server, a representative check is asking it to summarize recently closed incidents.
Tool discovery confirms that the client can reach the server and obtain its tools; it does not mean the authenticated identity is authorized to read or change every record. Test a representative permitted operation before relying on the connection in an agent workflow.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Rank #3
Or skip the browser setup
This is a separate tool for taking website screenshots, not a way to configure or authenticate a ServiceNow MCP connection. If your project also needs screenshots of public pages, ScreenshotNeo can return one through a single GET request. Replace the example URL with the page you want to capture.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo API documentation for request options. Before capture it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Those screenshot features do not replace the OAuth steps above.
Sign up for ScreenshotNeo: 1,000 free screenshots a month, no card required.
Rank #4
Consider CIMD instead of managing a client secret
Client ID Metadata Documents (CIMD) is an optional client-registration route available from Zurich Patch 7 / Australia Patch 1 onward. Rather than creating a conventional inbound integration with a client secret, an administrator registers the client’s HTTPS metadata URL. The client is treated as public and uses Authorization Code with PKCE. Administrator approval remains part of onboarding.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- Open All > System OAuth > CIMD Clients and select New.
- Paste the client’s HTTPS metadata URL and select Fetch Metadata.
- Review the retrieved client values before accepting them.
- Choose Live to refresh metadata automatically, or Static to pin the metadata as registered.
- Create the record. The metadata URL itself serves as the
client_id; configure the client to use Authorization Code with PKCE.
| Registration choice | Release eligibility | Credential model | Registration and metadata | Flow and governance |
|---|---|---|---|---|
| Standard inbound integration | Use the standard setup described above; no additional release floor is specified here. | ServiceNow generates a client ID and client secret. | Administrator creates the integration, enters the exact redirect, and retains the generated credentials. CIMD metadata synchronization does not apply. | Authorization Code Grant. The administrator controls scope and integration access. |
| CIMD | Zurich Patch 7 / Australia Patch 1 and later. | Public client using PKCE rather than a managed client secret. | Administrator fetches and reviews the client’s HTTPS metadata URL; selects Live refresh or Static pinned metadata. | Authorization code plus PKCE. Registration still requires administrator approval. |
Set permissions around the identity that connects
ServiceNow evaluates access under the authenticated human user or the dedicated integration user. The MCP connection does not bypass the platform’s existing authorization model: roles, contextual script checks, row and field controls, and deny-unless-permitted rules remain in force. Give the connection only the permissions its intended tools need, and test with the actual identity that will run the workflow.
Best Value
Some tool types need additional configuration. Custom Now Assist skills may require execute ACLs and role masking. Subflows and Actions require AI ACLs and synchronous execution. If a tool is missing or unavailable, check both its tool-level settings and the identity’s relevant ACLs instead of broadening the integration’s access by default.
Troubleshoot failed authorization or missing tools
| Symptom | Likely check | What to do |
|---|---|---|
| Browser authorization fails or does not return to the client | The registered redirect does not match the client’s redirect URL. | Compare the values character for character, including scheme, hostname, path, and trailing slash. Confirm you entered the client redirect in the inbound integration and used the ServiceNow callback only if the client form separately requests it. |
| Client cannot get a token | OAuth endpoint, client credentials, or token format is wrong. | Check the authorization, token, and revocation endpoint hostnames against the ServiceNow instance; verify the client ID and secret; confirm the integration uses JWT token format. |
| Connection appears authenticated but the tool list is empty or undiscoverable | Connection and Credential records may be absent or incorrect, or the token may not have been requested or may have expired. | Inspect the Connection and Credential records, confirm that a token was obtained and is still valid, then verify the server URL, server name, and scope. ADC routing is also identified as a possible cause of undiscoverable tools; if the configuration checks out, ServiceNow Support may need to investigate. |
| Tools appear, but a tool call is denied | The authenticated user lacks access required by the tool, its ACLs, or the underlying records. | Check the user’s roles, ACLs, row and field permissions, and any tool-specific execute or AI ACL requirements. Grant only the minimum necessary access. |
| Connection setup expects a local process or stdio transport | The connection method is not supported by MCP Server Console. | Use a remote ServiceNow MCP server URL over Streamable HTTP. SSE may be used for streaming responses. |
When diagnosing an issue, change one setting at a time and repeat authorization or discovery so you can identify which mismatch mattered. Avoid copying client secrets into logs or support messages; rotate exposed credentials according to your organization’s policy.
Operational and cost considerations
OAuth setup itself does not establish a performance or reliability guarantee for the MCP server, and no adoption, speed, or success-rate figures are stated here. For a stable integration, keep the server URL and registered redirect under configuration control, monitor whether the chosen client can refresh or renew authorization as expected, and review access when the human owner or integration user changes. Treat the client secret as a credential: limit who can retrieve it and avoid committing it to source control.
Choose standard registration when the client requires a conventional client ID and secret and the integration workflow fits your release. Choose CIMD when your release supports it and the client publishes metadata suitable for administrator review; its Live or Static setting determines whether metadata is automatically refreshed or held pinned. In either model, OAuth authentication is only one layer: the ServiceNow user and tool permissions remain decisive.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




