如何通过SSO实现ServiceNow REST调用?OneIdentity SSO场景咨询
Great question—dealing with SSO and REST APIs can feel tricky at first, but there are two solid paths you can take here depending on your client's setup and security preferences.
Option 1: Use a ServiceNow Local Service Account
Even when SSO (like OneIdentity) is enabled for end users, ServiceNow still supports local user accounts. This is often the quickest way to get your REST calls working without major changes to your existing code:
- Ask your client to create a dedicated service account in ServiceNow (not tied to any individual user). This account should have only the minimum permissions required to access the specific REST APIs your app needs (follow the principle of least privilege).
- Ensure this account is exempt from SSO enforcement (ServiceNow lets you configure exceptions for specific users/groups so they can log in with local credentials).
- You can then use this account's username and password with your existing basic authentication flow for REST calls:
GET /api/now/table/incident Authorization: Basic <base64-encoded username:password> Accept: application/json - Pro tip: Encourage your client to enable strong password policies for this service account and avoid sharing it unnecessarily.
Option 2: Authenticate via OneIdentity SSO Using OAuth 2.0/OpenID Connect
If your client prefers to avoid local service accounts (for better security alignment with their SSO strategy), you can use OAuth 2.0 (specifically OpenID Connect, which OneIdentity supports) to authenticate your REST calls. Here's how to set this up:
Prerequisites
- Confirm that your client's OneIdentity instance is configured to act as an OpenID Connect (OIDC) identity provider (IdP) for ServiceNow.
- ServiceNow must have OAuth 2.0 enabled (this is usually on by default, but double-check with the client's admin).
Step-by-Step Implementation
1. Register Your App in OneIdentity
- Ask the client's OneIdentity admin to register your application as an OIDC client in their OneIdentity portal. Choose the flow based on your use case:
- For backend/non-interactive calls: Use the
Client Credentialsflow (no user interaction needed). You'll get aclient_idandclient_secret. - For user-initiated calls (where you need to act on behalf of a specific user): Use the
Authorization Codeflow. You'll need to specify a redirect URI (where OneIdentity sends the authorization code after user login).
- For backend/non-interactive calls: Use the
- Request the appropriate scopes from the client—these should map to the ServiceNow API permissions your app requires (e.g.,
sn_incident.readfor incident read access).
2. Configure ServiceNow to Accept OneIdentity Tokens
- The client's ServiceNow admin needs to set up an OAuth 2.0 Provider pointing to OneIdentity's OIDC endpoints:
- Authorization endpoint: Typically
https://<oneidentity-domain>/oauth2/authorize - Token endpoint: Typically
https://<oneidentity-domain>/oauth2/token - JWKS endpoint (for validating tokens):
https://<oneidentity-domain>/oauth2/jwks
- Authorization endpoint: Typically
- They'll also need to configure ServiceNow to trust tokens issued by OneIdentity, mapping claims from the token to ServiceNow user attributes.
3. Make REST Calls with the Access Token
- For Client Credentials Flow (backend calls):
- Send a POST request to OneIdentity's token endpoint to get an access token:
POST https://<oneidentity-domain>/oauth2/token Content-Type: application/x-www-form-urlencoded grant_type=client_credentials&client_id=<your-client-id>&client_secret=<your-client-secret>&scope=<required-scopes> - Extract the
access_tokenfrom the response. - Include this token in your ServiceNow REST calls using the Bearer authentication scheme:
GET /api/now/table/incident Authorization: Bearer <access-token> Accept: application/json
- Send a POST request to OneIdentity's token endpoint to get an access token:
- For Authorization Code Flow (user-initiated calls):
- Redirect the user to OneIdentity's authorization endpoint with your
client_id,redirect_uri,scope, andresponse_type=code. - After the user logs in via OneIdentity, you'll receive an authorization code at your redirect URI.
- Exchange this code for an access token (and refresh token) by calling OneIdentity's token endpoint with
grant_type=authorization_code,client_id,client_secret,code, andredirect_uri. - Use the access token in your ServiceNow API calls as above.
- Redirect the user to OneIdentity's authorization endpoint with your
Key Notes
- Access tokens have a limited lifespan (usually 15-60 minutes), so you'll need to handle token refresh (for Authorization Code Flow, use the refresh token to get a new access token without re-authenticating the user).
- Ensure all communication is over HTTPS to protect tokens and credentials.
Which Option Should You Choose?
- Go with Option 1 if you need a quick fix and the client is comfortable maintaining a local service account. It requires minimal changes to your existing code.
- Go with Option 2 if the client wants to adhere strictly to their SSO security policy, avoid storing user passwords, or if your app needs to act on behalf of individual end users.
内容的提问来源于stack exchange,提问作者Jerry
相关产品推荐
相关产品推荐

