October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
AI agents

How to Configure OAuth for a ServiceNow MCP Server

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To connect an MCP client to a ServiceNow MCP server, create an OAuth inbound integration using OAuth – Authorization code grant, set its token format to JWT, and register the exact redirect URL supplied by the client. Then configure the client with your ServiceNow MCP server URL and OAuth endpoints, authenticate in the browser, and verify that the client discovers the server’s tools. CIMD is an alternative registration method on Australia Patch 1 / Zurich Patch 7 and later.

Before you begin

You need an MCP server on the ServiceNow instance you plan to connect to. It can be the Quickstart Server (sn_mcp_server_default) or a purpose-built server. You also need to know which MCP client will connect: its exact redirect URL is required when registering the OAuth integration, and client settings can differ by product.

  • For standard inbound integration setup, you need the oauth_admin, mi_admin, or admin role. Creating an MCP server may separately require sn_mcp_server.admin or admin.
  • Get the redirect URL from the MCP client before creating the integration. Do not substitute a URL that merely looks similar.
  • Decide which user identity should perform actions through the connection. A human-operated session uses the signed-in user; an autonomous agent should use a dedicated integration user with only the required roles and access.

ServiceNow MCP Server Console uses OAuth 2.0 Authorization Code Grant for this connection. It does not currently support the client-credentials grant for MCP Server Console, nor local or stdio MCP servers; use the supported remote Streamable HTTP transport.

Create a standard OAuth inbound integration

  1. In the ServiceNow instance, open All > Machine Identity Console > Inbound integrations. You can also start from the OAuth setup banner in MCP Server Console.
  2. Select New integration.
  3. Choose OAuth – Authorization code grant.
  4. Enter a name and paste the MCP client’s exact redirect URL into Redirect URL.
  5. Decide whether to restrict the integration to selected API scopes. Clearing the restriction makes it broadly scoped, so do not assume that is appropriate for a production connection. Confirm which scopes the chosen tools require and apply your organization’s least-privilege policy.
  6. Expand Advanced options and set Token Format to JWT.
  7. Save the integration. Securely retain its generated client ID and client secret for the client configuration.

The redirect URL in the integration is the address to which the client receives the authorization response. It must match the client’s registered value exactly, including scheme, host, path, and any relevant trailing slash. A mismatch commonly interrupts authorization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the MCP client

In the client’s MCP server configuration, use the values below, replacing placeholders with the hostname and server name for your instance. Client forms use different labels, and some may not ask for every field; where a field is requested, enter the corresponding value.

Client setting Value
MCP server URL https://<server-instance>.service-now.com/sncapps/mcp-server/mcp/<server-name>
Host <server-instance>.service-now.com
Base URL /sncapps/mcp-server
Scope mcp_server
Authentication OAuth 2.0
Identity provider Generic OAuth 2
Authorization URL https://<server-instance>.service-now.com/oauth_auth.do
Token URL https://<server-instance>.service-now.com/oauth_token.do
Token revocation URL https://<server-instance>.service-now.com/oauth_revoke.do
Refresh URL https://<server-instance>.service-now.com/oauth_auth.do
Redirect URL, if requested as the ServiceNow callback https://<server-instance>.service-now.com/oauth/callback
Client ID and client secret The values generated for the inbound integration

There are two redirect-related values to keep straight. The integration’s Redirect URL must be the exact redirect supplied by the client. Some client forms also ask for a ServiceNow callback value; in that field use https://<server-instance>.service-now.com/oauth/callback. Follow the client form’s labels rather than pasting one value into both fields without checking what each represents.

For ServiceNow AI Agent Studio, the documented form uses OAuth 2.1, Manual Registration, Authorization Code, and Client Secret Post, followed by the authorization, token, and revocation URLs. Use that client-specific configuration rather than assuming every MCP client exposes the same labels.

Authenticate and check tool discovery

  1. Save the MCP server connection in the client and select Authenticate.
  2. Complete the browser-based authorization and approve the consent prompt.
  3. Return to the client and confirm that the bearer token is accepted and the server’s tool list appears.
  4. Run a low-risk test that exercises a tool the configured user is allowed to use. For the Quickstart Server, a representative check is asking it to summarize recently closed incidents.

Tool discovery confirms that the client can reach the server and obtain its tools; it does not mean the authenticated identity is authorized to read or change every record. Test a representative permitted operation before relying on the connection in an agent workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

This is a separate tool for taking website screenshots, not a way to configure or authenticate a ServiceNow MCP connection. If your project also needs screenshots of public pages, ScreenshotNeo can return one through a single GET request. Replace the example URL with the page you want to capture.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

See the ScreenshotNeo API documentation for request options. Before capture it accepts cookie or consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and response headers identify the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf for AI agents. The Free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Those screenshot features do not replace the OAuth steps above.

Sign up for ScreenshotNeo: 1,000 free screenshots a month, no card required.

Consider CIMD instead of managing a client secret

Client ID Metadata Documents (CIMD) is an optional client-registration route available from Zurich Patch 7 / Australia Patch 1 onward. Rather than creating a conventional inbound integration with a client secret, an administrator registers the client’s HTTPS metadata URL. The client is treated as public and uses Authorization Code with PKCE. Administrator approval remains part of onboarding.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open All > System OAuth > CIMD Clients and select New.
  2. Paste the client’s HTTPS metadata URL and select Fetch Metadata.
  3. Review the retrieved client values before accepting them.
  4. Choose Live to refresh metadata automatically, or Static to pin the metadata as registered.
  5. Create the record. The metadata URL itself serves as the client_id; configure the client to use Authorization Code with PKCE.
Registration choice Release eligibility Credential model Registration and metadata Flow and governance
Standard inbound integration Use the standard setup described above; no additional release floor is specified here. ServiceNow generates a client ID and client secret. Administrator creates the integration, enters the exact redirect, and retains the generated credentials. CIMD metadata synchronization does not apply. Authorization Code Grant. The administrator controls scope and integration access.
CIMD Zurich Patch 7 / Australia Patch 1 and later. Public client using PKCE rather than a managed client secret. Administrator fetches and reviews the client’s HTTPS metadata URL; selects Live refresh or Static pinned metadata. Authorization code plus PKCE. Registration still requires administrator approval.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Set permissions around the identity that connects

ServiceNow evaluates access under the authenticated human user or the dedicated integration user. The MCP connection does not bypass the platform’s existing authorization model: roles, contextual script checks, row and field controls, and deny-unless-permitted rules remain in force. Give the connection only the permissions its intended tools need, and test with the actual identity that will run the workflow.

Some tool types need additional configuration. Custom Now Assist skills may require execute ACLs and role masking. Subflows and Actions require AI ACLs and synchronous execution. If a tool is missing or unavailable, check both its tool-level settings and the identity’s relevant ACLs instead of broadening the integration’s access by default.

Troubleshoot failed authorization or missing tools

Symptom Likely check What to do
Browser authorization fails or does not return to the client The registered redirect does not match the client’s redirect URL. Compare the values character for character, including scheme, hostname, path, and trailing slash. Confirm you entered the client redirect in the inbound integration and used the ServiceNow callback only if the client form separately requests it.
Client cannot get a token OAuth endpoint, client credentials, or token format is wrong. Check the authorization, token, and revocation endpoint hostnames against the ServiceNow instance; verify the client ID and secret; confirm the integration uses JWT token format.
Connection appears authenticated but the tool list is empty or undiscoverable Connection and Credential records may be absent or incorrect, or the token may not have been requested or may have expired. Inspect the Connection and Credential records, confirm that a token was obtained and is still valid, then verify the server URL, server name, and scope. ADC routing is also identified as a possible cause of undiscoverable tools; if the configuration checks out, ServiceNow Support may need to investigate.
Tools appear, but a tool call is denied The authenticated user lacks access required by the tool, its ACLs, or the underlying records. Check the user’s roles, ACLs, row and field permissions, and any tool-specific execute or AI ACL requirements. Grant only the minimum necessary access.
Connection setup expects a local process or stdio transport The connection method is not supported by MCP Server Console. Use a remote ServiceNow MCP server URL over Streamable HTTP. SSE may be used for streaming responses.

When diagnosing an issue, change one setting at a time and repeat authorization or discovery so you can identify which mismatch mattered. Avoid copying client secrets into logs or support messages; rotate exposed credentials according to your organization’s policy.

Operational and cost considerations

OAuth setup itself does not establish a performance or reliability guarantee for the MCP server, and no adoption, speed, or success-rate figures are stated here. For a stable integration, keep the server URL and registered redirect under configuration control, monitor whether the chosen client can refresh or renew authorization as expected, and review access when the human owner or integration user changes. Treat the client secret as a credential: limit who can retrieve it and avoid committing it to source control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose standard registration when the client requires a conventional client ID and secret and the integration workflow fits your release. Choose CIMD when your release supports it and the client publishes metadata suitable for administrator review; its Live or Static setting determines whether metadata is automatically refreshed or held pinned. In either model, OAuth authentication is only one layer: the ServiceNow user and tool permissions remain decisive.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.