Explore credentials, connections, and aliases
Summarize
Summary of Explore credentials, connections, and aliases
In the ServiceNow AI Platform, application integrations requireconnections,credentials, andaliasesto securely access external resources. Before running an integration, you must create and configure these elements to enable seamless and secure data exchange.
Show less
The key terms are defined as follows:
- Connection: Integration details such as system endpoints, IP addresses, or database specifics.
- Credential: Authentication information like usernames and passwords needed to establish the connection.
- Alias: A named tag that links to sets of connections and credentials, simplifying integration configurations by reusing these details across environments (e.g., QA, development, production).
Alias Types and Structure
The platform distinguishes between two alias types:
- Credential Alias: Links only to credential data and resolves at runtime.
- Connection and Credential Alias: Links both connection details and credentials, resolving at runtime.
You can create child aliases under a parent alias to manage multiple connections within the same integration. Child aliases inherit properties from parents but maintain their own connection and credential information.
Benefits
- Centralized management of credentials for external services.
- Reuse of connection and credential configurations across multiple platform features.
- Reduced configuration effort and enhanced security.
- Enables non-administrators to utilize predefined connections and credentials safely.
Platform Features Using Connections, Credentials, and Aliases
- Flow Designer
- IntegrationHub (requires separate subscription)
- Cloud Management
- Discovery
- Orchestration
- Service Mapping
Configuration and Setup
Aliases can be set up via two primary methods:
- Connections and Credentials module (to create Connection & Credential aliases).
- Connections dashboard within IntegrationHub (for adding connections).
Chedential Synchronization on MID Servers
The MID Server synchronizes credentials from the ServiceNow instance to speed up access to multiple network devices during integrations like Discovery or Service Mapping. This synchronization occurs via a credentialsreload job and includes any custom fields on credential forms.
To optimize performance, especially with customized credential forms referencing multiple tables, you can adjust system properties to limit included fields and recursion depth during synchronization.
Security and Data Separation
- Scope Protections: You can assign Connection & Credential records to scopes, enforcing access controls and preventing unauthorized interactions across scopes.
- Domain Separation: Supported for Credentials and Connections, allowing segregation of data, processes, and admin tasks into logical domains with controlled user access.
Connection & Credential Configuration Templates
Administrators and users with the flowdesigner role can leverage customizable configuration templates to streamline the setup of spoke integrations with third-party systems, simplifying integration deployment.
All application integrations in the ServiceNow AI Platform use connections, credentials, and aliases to enable applications to access resources.
Before you can execute an application integration in the ServiceNow AI Platform, you must create and configure connection information, corresponding credentials, and add an alias. To understand how ServiceNow defines these terms:
- Connection
- A connection is an integration with a system, such as an IP address or endpoint with protocols. It contains specific details, such as database particulars, when integrating with a database.
- Credential
- A credential is the authentication data required to make the connection, such as an ID and password.
- Alias
- An alias is a naming convention, or tag, that ties to a set of
connections or credentials on your instance. An alias contains the necessary connection
and credential information to make an application integration. Rather than enter that
information every time you integrate, you can use an alias. For example, you can
designate an alias to house your QA, development, and production credentials for the
same application integration. The alias resolves the application integration for each
environment. The ServiceNow AI Platform distinguishes different types of aliases:
- Credential Alias
- This alias associates to credential data only, and resolves during runtime.
- Connection and Credential Alias
- This alias associates to connection information and the credential data required to complete the integration, and resolves during runtime.
Within connection and credential aliases, you can also create additional aliases called child aliases. Child aliases allow you to create multiple connections within the same application integration. When you create a child alias, the alias you created it under becomes a parent alias. While child aliases inherit properties from their parent alias, child aliases carry their own connection and credential information.
Benefits to using Connections, Credentials, and Aliases
- Central location to store and manage credentials to an external service
- Define once and reuse for multiple platform features
- Minimize configuration of other platform features
- Allow non-administrators to use predefined connections and credentials
- Increased security
Features using Connections, Credentials, and Aliases
- Flow Designer
- IntegrationHub
- Cloud Management
- Discovery
- Orchestration
- Service Mapping
- Using the Connections and Credentials module. See Create a Connection & Credential alias.
- In the Connections dashboard of Integration Hub. See Add a connection.Note:Integration Hub requires a separate subscription. For more information, see Request Integration Hub.
Credential synchronization on MID Servers
Each MID Serverin your network synchronized with the instance keeps a copy of every credential that you create. The Management, Instrumentation, and Discovery (MID) Server is a Java application that enables communication and the movement of data between a ServiceNow instance and external applications, data sources, and services. This synchronization speeds up the reading of credentials when applications like Discovery or Service Mapping need to access multiple devices on the network. The MID Servers synchronize when they find a credentials_reload job in the ECC Queue. The reload job instructs the MID Server to make a SOAP call to the instance to get the entire list of credentials in the Credentials [discovery_credentials] table, including all the field values. To learn more, see MID Server.
| Property | Description |
|---|---|
com.snc.credentials_user_fields |
Includes all customized fields in credential sync. Set this property to false
if you do not want to include the fields that you added to credential forms.
|
com.snc.credentials_recursion_depth |
Defines the number of tables to traverse when the credential-sync mechanism
collects fields from reference tables. Lower this number if you are experiencing
performance issues and you have customized credential forms that include reference
fields to tables that also have reference fields.
|