You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过SSO实现ServiceNow REST调用?OneIdentity SSO场景咨询

Great question—dealing with SSO and REST APIs can feel tricky at first, but there are two solid paths you can take here depending on your client's setup and security preferences.

Option 1: Use a ServiceNow Local Service Account

Even when SSO (like OneIdentity) is enabled for end users, ServiceNow still supports local user accounts. This is often the quickest way to get your REST calls working without major changes to your existing code:

  • Ask your client to create a dedicated service account in ServiceNow (not tied to any individual user). This account should have only the minimum permissions required to access the specific REST APIs your app needs (follow the principle of least privilege).
  • Ensure this account is exempt from SSO enforcement (ServiceNow lets you configure exceptions for specific users/groups so they can log in with local credentials).
  • You can then use this account's username and password with your existing basic authentication flow for REST calls:
    GET /api/now/table/incident
    Authorization: Basic <base64-encoded username:password>
    Accept: application/json
    
  • Pro tip: Encourage your client to enable strong password policies for this service account and avoid sharing it unnecessarily.
Option 2: Authenticate via OneIdentity SSO Using OAuth 2.0/OpenID Connect

If your client prefers to avoid local service accounts (for better security alignment with their SSO strategy), you can use OAuth 2.0 (specifically OpenID Connect, which OneIdentity supports) to authenticate your REST calls. Here's how to set this up:

Prerequisites

  • Confirm that your client's OneIdentity instance is configured to act as an OpenID Connect (OIDC) identity provider (IdP) for ServiceNow.
  • ServiceNow must have OAuth 2.0 enabled (this is usually on by default, but double-check with the client's admin).

Step-by-Step Implementation

1. Register Your App in OneIdentity

  • Ask the client's OneIdentity admin to register your application as an OIDC client in their OneIdentity portal. Choose the flow based on your use case:
    • For backend/non-interactive calls: Use the Client Credentials flow (no user interaction needed). You'll get a client_id and client_secret.
    • For user-initiated calls (where you need to act on behalf of a specific user): Use the Authorization Code flow. You'll need to specify a redirect URI (where OneIdentity sends the authorization code after user login).
  • Request the appropriate scopes from the client—these should map to the ServiceNow API permissions your app requires (e.g., sn_incident.read for incident read access).

2. Configure ServiceNow to Accept OneIdentity Tokens

  • The client's ServiceNow admin needs to set up an OAuth 2.0 Provider pointing to OneIdentity's OIDC endpoints:
    • Authorization endpoint: Typically https://<oneidentity-domain>/oauth2/authorize
    • Token endpoint: Typically https://<oneidentity-domain>/oauth2/token
    • JWKS endpoint (for validating tokens): https://<oneidentity-domain>/oauth2/jwks
  • They'll also need to configure ServiceNow to trust tokens issued by OneIdentity, mapping claims from the token to ServiceNow user attributes.

3. Make REST Calls with the Access Token

  • For Client Credentials Flow (backend calls):
    1. Send a POST request to OneIdentity's token endpoint to get an access token:
      POST https://<oneidentity-domain>/oauth2/token
      Content-Type: application/x-www-form-urlencoded
      
      grant_type=client_credentials&client_id=<your-client-id>&client_secret=<your-client-secret>&scope=<required-scopes>
      
    2. Extract the access_token from the response.
    3. Include this token in your ServiceNow REST calls using the Bearer authentication scheme:
      GET /api/now/table/incident
      Authorization: Bearer <access-token>
      Accept: application/json
      
  • For Authorization Code Flow (user-initiated calls):
    1. Redirect the user to OneIdentity's authorization endpoint with your client_id, redirect_uri, scope, and response_type=code.
    2. After the user logs in via OneIdentity, you'll receive an authorization code at your redirect URI.
    3. Exchange this code for an access token (and refresh token) by calling OneIdentity's token endpoint with grant_type=authorization_code, client_id, client_secret, code, and redirect_uri.
    4. Use the access token in your ServiceNow API calls as above.

Key Notes

  • Access tokens have a limited lifespan (usually 15-60 minutes), so you'll need to handle token refresh (for Authorization Code Flow, use the refresh token to get a new access token without re-authenticating the user).
  • Ensure all communication is over HTTPS to protect tokens and credentials.
Which Option Should You Choose?
  • Go with Option 1 if you need a quick fix and the client is comfortable maintaining a local service account. It requires minimal changes to your existing code.
  • Go with Option 2 if the client wants to adhere strictly to their SSO security policy, avoid storing user passwords, or if your app needs to act on behalf of individual end users.

内容的提问来源于stack exchange,提问作者Jerry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:59:48