---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# OAuth authorization code grant flow

# OAuth authorization code grant flow {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of OAuth authorization code grant flow

The OAuth authorization code grant flow in ServiceNow enables secure user authentication and resource access via an OAuth server, eliminating the need for direct username/password entry by the client application.
This flow is implemented for REST API access and ensures credentials are never exposed to the requesting client.
Show full answer Show less  
ServiceNow instances can act as the OAuth authorization server, issuing tokens for authorization code flow. Users owning the restricted resources must authorize access and can revoke tokens anytime to terminate access.

## Authorization Code Grant Flow Process

* **Step 1:** The client application initiates a GET request through the user agent to request an authorization code. The user must be logged into the ServiceNow instance and manually approve access by interacting with an Allow/Deny UI prompt. The request includes parameters such as authorization URL, token URL, client ID, client secret, and specifies `responsetype=code`.
* **Step 2:** Upon approval, the ServiceNow instance sends an authorization code to the client's specified redirect (callback) URL. This code confirms the user's consent.
* **Step 3:** The client exchanges the authorization code for an access token and refresh token by making a POST request to the ServiceNow token endpoint. The access token authenticates subsequent REST API calls, while the refresh token allows requesting new access tokens.

Tokens can be managed and revoked directly within the ServiceNow instance.

## Practical Application for ServiceNow Customers

* Use this flow to secure REST API access without exposing user credentials to clients.
* Configure the authorization and token URLs, client ID, and secret in your client application to integrate with ServiceNow's OAuth server.
* Ensure users are logged in to approve access requests and maintain control by revoking tokens as needed.
* Use the access token to authenticate API requests and receive JSON data responses from ServiceNow tables, such as the Incident table.

## Integration Support

The authorization code grant flow supports integrations with Multi-SSO SAML 2.0 Update 1, multifactor authentication, and is compatible with ServiceNow's mobile interface.  
Authorization code grant flow allows a user to access a resource by authenticating
directly with an OAuth server that trusts the resource, in contrast with authenticating with
username/password credentials.

This implementation of OAuth authorization code flow allows access to a resource via REST. The
authorization code framework gets the access token through the authorized URL that the user
configures rather than requiring the user to enter a username/password. The username/password are
never exposed to the client that is requesting access to the resource.

## A ServiceNow instance as the authorization server

The OAuth server is typically a third-party authorization server. You can also specify a ServiceNow instance as the
authorization server that issues the tokens for authorization code flow.

The user who owns the restricted resource must authorize access. The user can also revoke the
issued access token at any time to terminate access.

## Authorization code grant flow process

The Authorization code grant flow process consists of these three steps:

In step one, the client application or website initiates a REST API call in the form of a
GET request to the instance via the user agent. Typically, the REST call is initiated when
the end user clicks a button or a link on the client application or website to request an
access token. In the client application, the end user also has to specify the authorization
URL, token URL, client ID, and client secret. For an explanation of these items, see the
field descriptions in this topic: [Use a third-party OAuth
provider](https://www.servicenow.com/docs/access?context=t_UseAThirdPartyOAuthProvider&version=brazil&pubname=brazil-api-reference&ft:locale=en-US). If the client asks for a grant type, the end user must select
Authorization Code.  
Example GET request from the client application to the instance:

    https://myinstance.service-now.com/oauth_auth.do?response_type=code&redirect_uri={the_redirect_url}&client_id={the_client_identifier}

Note:  
The response_type must be code to use the standard OAuth code grant flow.
The end user must manually allow access to the restricted resource on the instance. In the ServiceNow implementation, the end user must be logged into the instance. The instance prompts the end user with a UI page that has Allow and Deny buttons.

The item that the client application is actually requesting the token from is the OAuth
provider application registry record that you created, also known as the authorization
endpoint (see [Use a third-party OAuth
provider](https://www.servicenow.com/docs/access?context=t_UseAThirdPartyOAuthProvider&version=brazil&pubname=brazil-api-reference&ft:locale=en-US)). The auth code is sent from the authorization endpoint to the
client. It does not go to the client directly but to the Redirect URL
that you specify on the authorization endpoint form. This URL is also known as a callback
URL. You can obtain this URL from the client application or website.  
Example response from the instance to the client application, providing an authorization code:

    https/http://{callbackURL}?code={the actual auth code}

Now that the client application has the authorization code, the client uses the code to
request the access token. The authorization code proves that the user has consented in step
1.  
Example POST request from the client application to the ServiceNow instance that provides the auth code and requests the access token:

    https://myinstance.service-now.com/oauth_token.do?grant_type=authorization_code&code={the auth code}&redirect_uri={the_same_redirect_url}&client_id={the_same_client_identifier}&client_secret={client_secret_value}

The endpoint on the instance returns an access token and a refresh token. The refresh token
can be used to request additional access tokens.

You can manage the tokens, including revoking the token, in the instance. See [Manage OAuth tokens](https://www.servicenow.com/docs/03kMjUQPB0qN9Ejnif1zgA "Open OAuth tokens to provide access to restricted resources.").

The client application uses the access token to authenticate to the REST API. After
authenticating the client application, the REST API returns the requested data in a JSON
payload.  
Example GET request for the JSON payload of data for the Incident \[incident\] table:

    https://myinstance.service-now.com/api/now/table/incident?access_token={the_token}

Note:  
The system also supports [OAuth implicit grants](https://www.servicenow.com/docs/s~JcALqkft8FWCseUXrQ~Q "ServiceNow instances support the implicit grant of an access token."), also known as implicit grant code flow.

## Integration support

Authorization code flow supports the following integrations on the instance:

* Multi-SSO
* SAML 2.0 Update 1
* Multifactor authentication
{#c_OAuthAuthorizationCodeFlow__ul_ajz_jky_dw}

The mobile interface is also supported.

