SSO configuration AI agent

  • Release version: Australia
  • Updated August 14, 2026
  • 2 minutes to read
  • This ServiceNow Otto for Setup AI agent guides administrators through secure Single Sign-On (SSO) setup for ServiceNow using SAML or OpenID Connect (OIDC). The agent collects and validates identity provider details, creates authentication configurations, and guides users through review, testing, and activation.

    Workflow

    1. Check whether the SSO plugin is installed and whether an active SSO configuration already exists. If the plugin isn't installed, offer to install it and monitor progress before continuing.
    2. Identify whether the user wants SAML, OIDC, or generic SSO help; if unclear, ask them to choose. If an active configuration already exists, offer to deactivate it instead.
    3. For SAML: request the metadata URL. For OIDC: collect the configuration name, client ID, and well-known configuration URL (client secret is handled separately, outside the conversation).
    4. Create the SAML or OIDC Identity Provider record based on the provided information. Confirm success or display any errors for correction.
    5. Present a link to the newly created record and ask the user to review and correct any fields before continuing.
    6. Guide the user through testing the connection and confirm the test passed.
    7. Ask whether this should be the default login method and apply that setting if so.
    8. Explain ACR as a safety fallback and confirm whether it's been set up before proceeding.
    9. Ask for confirmation, then activate the configuration.
    10. Depending on earlier default/active selections, mark the configuration as primary automatically or ask for confirmation.
    11. Ask the user to test login redirection in a private browser.
    Table 1. Configuration
    Field Description
    Allow third party to access this AI agent

    When enabled, third-party AI agents can use this agent. This value is off (false) by default. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the External discoverable field.

    Allow AI specialists to access this AI agent

    When enabled, AI specialists can use this agent. This value is off (false) by default. When set to true, more configuration options for tools become available so that an AI specialist can map inputs and response templates to tool outputs. This setting is defined in the AI Agent configs [sn_aia_agent_config] table on the Specialist enabled field.

    Manage long-term memory

    When enabled, all previous user interactions are used as context for the LLM. This value is off (false) by default. This setting is defined by the sn_aia.ltm.enable_long_term_memory system property. For more information, see ServiceNow Otto AI agents reference.

    Tools
    Scripts
    Activate SSO Configuration
    Create Login Link For OIDC
    Creation of OIDC using URL
    Creation of SAML record using the metadata URL
    Creation of SAML record using the metadata XML
    Deactivate SSO Configuration
    get activation status
    Get Active SSO Configurations
    Get SSO Setting Link
    Install sso plugin
    Set SSO identity provider as default
    Update SSO Config To Primary
    Update SSO Label
    Generative AI skills
    get knowledge
    Plugin installation and existing configuration check
    Conversational topic
    IADynamicChoicePickerGenerator
    Agent roles (ACLs) sn_ia_config.ia_user
    Data access roles

    Not defined.

    Triggers

    Optional. None defined by default. An admin can specify triggers if desired. For more information, see Add a trigger to an AI agent.

    Channels

    Configure an assistant for Virtual Agent or ServiceNow Otto panel using Assistant Designer.

    Used in agentic workflows

    Default VA Workflow

    Learn more about ServiceNow Otto for Setup at ServiceNow Otto for Setup.