OAuth 2.0 credentials
Summarize
Summary of OAuth 2.0 credentials
OAuth 2.0 credentials in ServiceNow enable secure access to user accounts on HTTP services by obtaining OAuth tokens. These credentials are configured within the OAuth 2.0 Credentials form and are essential for integrating third-party OAuth providers securely and efficiently.
Show less
Key Features
- Name: Assign a unique, descriptive name for easy identification of the credential.
- Active: Toggle to specify whether the credential is currently active.
- OAuth Entity Profile: Defines the grant type and scopes used for OAuth authentication.
- Connect to Auth Server via MID Server: Enables connecting ServiceNow to on-premise or cloud OAuth servers behind firewalls through a MID Server. This option is available when certain grant types are selected (Client Credentials, Authorization Code, or Resource Owner Password Credentials).
- Applies to: Specifies whether the credential applies to all MID Servers or specific ones, ensuring that token requests are routed through properly configured MID Servers.
- Order: Determines the sequence in which credentials are attempted during device logon, helping manage credential usage when multiple are available.
- Credential Alias: Links an alias to the OAuth 2.0 credential for easier referencing.
- Integration Type: Defines the OAuth token scope, either System (token based on requester profile) or Personal (user-specific token). Personal type requires the MID Server user to have the oauthadmin role and supports specific grant types.
Important Considerations
- When using MID Server to connect to the Auth Server, ensure selected MID Servers are up, validated, and have REST or ALL capabilities to successfully execute token requests.
- The oauthadmin role is required for MID Server users to set up OAuth integration via MID Server and for managing personal user tokens.
- User-specific information can only be accessed with Personal integration type tokens, which align with user session context when configured in Flow properties.
Practical Use for ServiceNow Customers
By configuring OAuth 2.0 credentials appropriately, customers can securely integrate ServiceNow with external OAuth providers, automate token retrieval through MID Servers when direct access is restricted, and manage both system-wide and user-specific authentication scenarios. This setup supports secure API calls to third-party services and ensures compliance with access control and authentication policies within the ServiceNow platform.
OAuth 2.0 credentials enable ServiceNow to obtain access to user accounts on an HTTP service.
| Field | Input value |
|---|---|
| Name | Enter a unique and descriptive name for this credential. For example, you might call it OAuth2 credential. |
| Active | Specify whether this credential is active. |
| OAuth Entity Profile | An OAuth profile is a combination of a grant type and at least one scope. |
| Connect to Auth Server via MID Server | Connects your ServiceNow instance to an on-premise OAuth server that resides behind a firewall through a MID Server. It can also connect your ServiceNow instance to a cloud-based OAuth server through a MID server. When this option is enabled, the request for an OAuth token is sent through the MID Server. Important:
|
| Applies to |
Specify if the credential record is applicable for all MID Servers, or a specific MID Server. If specific, add the MID servers as necessary. Important:
Ensure that you are aware of these considerations if you have selected the Connect to Auth Server via MID Server check box.
|
| Order |
Order (sequence) in which Discovery tries this credential as it attempts to log on to devices. The smaller the number, the higher in the list this credential appears. Establish credential order when using large numbers of credentials or when security locks out users after three failed login attempts. If all the credentials have the same order number (or none), the instance tries the credentials in a random order. |
| Credential alias | Specify the credential alias that you want to tie to the OAuth 2.0 credential. |
| Integration Type | Indicates the integration type for the credential. Invoke an API of a third-party with an OAuth request that generates an OAuth token that is system or user specific. Following are the integration types:
If this Personal is selected on the OAuth Requestor Profile page, an additional flag called as Personal is displayed. Note:
|