Configure access to Zscaler Internet Access APIs
Configure access to the Zscaler Internet Access server to authenticate the secure connection between the ServiceNow AI Platform instance and the Zscaler server.
Before you begin
Role required: Zscaler Internet Access admin
- Service Admin Role:
Create the API key using a role with Service Admin privileges.
This configuration provides full functionality and is recommended for environments without strict role-segregation requirements.
- Least-Privilege Role (Supported):
For users who require reduced privilege, ServiceNow supports a least-privilege configuration.
Create a custom role with the following permissions:- Security: Custom
- Malware Protection, Sandbox, & Advanced Threat Protection: Full
When configured with these permissions, the integration runs as expected.
About this task
After Zscaler enables your API subscription for your organization's cloud service, it is available in the Zscaler Internet Access API key management page with the base URL. Your organization can only have one API key or token. Delete the existing key or token before you add a new one.
${Cloud_Name}/api/v1. Check the Zscaler cloud name that was provisioned for your organization and use
it to replace {Cloud_Name} in the base URI. Some examples of the
base URL are:- example.zscalerbeta.net
- example.zscalerone.net
- example.zscalertwo.net
- example.zscaler.net
- example.zscloud.net