OAuth setup for Apple Messages for Business
Summarize
Summary of OAuth setup for Apple Messages for Business
This guide explains how to integrate your Identity Provider (IdP) with Apple Messages for Business using OAuth2 authentication and connect it to your ServiceNow® instance. This setup enables secure authentication and seamless user data retrieval between Apple Messages for Business and ServiceNow.
Show less
Apple Messages for Business Configuration
- Log in to your Apple Messages for Business account on the Apple Messages for Business site.
- Navigate to the Integrated OAuth2 Authentication section.
- Enter the OAuth2 details from your IdP, including:
- Authorization URL
- Token URL
- Client ID
- Refer to Apple’s documentation for detailed OAuth2 configuration instructions on their platform.
ServiceNow® Instance OAuth Setup
- Create an OAuth Application Registry record: Configure it to use a third-party OAuth provider with the Authorization code grant type and add the Token URL.
- Define OAuth Entity Scopes: Add records specifying the OAuth scopes needed. For multiple scopes, add separate records and corresponding Entity Profile Scope records.
- Set up Connection and Credential Aliases: Create a connection alias to link to the HTTP connection record used for API calls.
- Create an HTTP(s) Connection record: Select HTTP(s) Connection type, associate it with the connection alias, and set the connection URL to your IdP’s user information API endpoint.
- Build a Profile Parser Action: Use Workflow Studio to create the action that parses user profile information from the IdP response, tailored for Apple Messages for Business integration.
- Create a Provider Application Authentication record: Link this to your provider app, OAuth entity profile, HTTP connection, and profile response parser action to complete the authentication setup.
Key Outcomes
Implementing this OAuth setup allows your ServiceNow instance to securely authenticate users via Apple Messages for Business, retrieve user profile data from your IdP, and maintain seamless communication between the platforms. This integration ensures compliance with OAuth2 standards while enabling efficient user management within your ServiceNow workflows.
Integrate your Identity Provider (IdP) with Apple Messages for Business using OAuth2 authentication.
Connect Apple Messages for Business to your ServiceNow® instance
Complete the following steps on the Apple Messages for Business site to connect your Apple Messages for Business account to your ServiceNow® instance.
- Go to the Apple Messages for Business page (register.apple.com) and log in to your Messages for Business account.
- Go to the Integrated OAuth2 Authentication section.
- Add the Authorization URL from your Identity Provider (IdP) to the OAuth URL field.
- Add the Token URL from your IdP to the Token URL field.
- Add the Client ID from your IdP to the Client Identifier field.
- Refer to the Apple documentation for further instructions on configuring OAuth2 authentication on your Apple Messages for Business account.
Set up OAuth on your ServiceNow® instance
- Go to your ServiceNow® instance to set up OAuth.
- Create a new record in the Application
Registries (oauth_entity) table using these instructions: Use a third-party OAuth provider.
- Use the grant type Authorization code.
- Add the Token URL.
- Create a new record in the OAuth Entity Scopes (oauth_entity_scope) table using these instructions: Specify an OAuth scope. If you have multiple scopes, then add a new record for each scope, and create a corresponding Entity Profile Scope record for each scope.
- Create a new record in the Connection and Credential Aliases (sys_alias) table using these instructions: Create a Connection & Credential alias. This connection alias is used for fetching the http connection record which you create in the next step.
- Create a new record in the HTTP(s) Connection (http_connection) table using these instructions: Create an HTTP(s) connection.
- Type of connection - Select HTTP(s) Connection
Set the Connection alias to the sys_alias record created in previous step.
- Set the connection url to fetch the user information API as per your IdP. (For example: https://<your-idp-app>.com/api/v1/users)
- Create a Profile Parser Action using Workflow Studio. See the code snippets shown here for an example: Create a profile parser action for Apple Messages for Business. See Building actions for more details.
- Create a new record in the Provider Application Authentications (sys_cs_provider_app_authentication) table using these instructions:
- Set the Provider Channel Identity to your provider app (sys_cs_provider_application)
- Set the OAuth Entity Profile to the oauth_entity_profile record created with your OAuth Provider (oauth_entity) record.
Set the Profile API Connection to the http_connection record created previously.
- Set the Profile Response Parser Action to the sys_hub_action_type_definition record that you have defined.