ServiceNow IntegrationBLOCK
ServiceNow MCP server: 500+ tools and 26 AI capabilities for any AI (Claude, ChatGPT, Gemini, Cursor, Copilot). Multi-transport (stdio, SSE, HTTP), A2A, dynamic schema discovery, read-only by default. Free and source available. Part of the NowAIKit suite.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/nowaikit) [](docs/TOOLS.md) [](https://modelcontextprotocol.io) [](LICENSE)
Connect Claude, ChatGPT, Gemini, Cursor, Copilot, or any AI, to ServiceNow.
500+ tools across ITSM, ITOM, CMDB, HRSD, CSM, Flow Designer, scripting & portal. Read, build, query and automate any instance in plain English.
New in 4.4 to 4.7: impact analysis (listtableconfig / findfieldreferences / findscriptreferences) to see what depends on a table, field or script before you change it, Local Sync to pull artifacts to local files, and aggregate_report for server-side reports (count plus averages, no truncation).
🚀 Install (2 minutes)
Requires Node.js 20+.
# 1 — install npm install -g nowaikit # 2 — run the wizard: it detects your AI clients and writes their config for you npx nowaikit setup
Restart your AI client (Claude Desktop, Cursor, ...) and start asking. Done.
Prefer a UI? npx nowaikit web for a local dashboard — or use [NowAIKit Cloud](https://cloud.nowaikit.com) (nothing to install).🔌 Manual setup (skip the wizard)
Add this to your client's MCP config (Claude Desktop claude_desktop_config.json, Cursor ~/.cursor/mcp.json, etc.):
{
"mcpServers": {
"nowaikit": {
"command": "npx",
"args": ["-y", "nowaikit"],
"env": {
"SERVICENOW_INSTANCE_URL": "https://yourcompany.see01ed8164e42OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nowaikit -- npx -y [email protected]
Exposed tools (200)
366 read · 207 write · 11 destructive. Blast radius: 11 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
DevOps | read | Pipelines, deployments, DevOps insights. |
NowAIKit | read | The most comprehensive ServiceNow AI toolkit: 500+ tools covering ITSM, CMDB, HRSD, CSM, SecOps, GRC, DevOps, and more. |
Summarizer | read | Summarizes text |
action | read | assess, prepare-cab, check-conflicts, plan-rollback. Default: assess |
add_adhoc_approver | write | Add an ad-hoc approver to an in-flight approval on a record (inserts a sysapproval_approver row). Requires WRITE_ENABLED=true |
add_comment | write | Add a customer-visible comment to any ITSM record (requires WRITE_ENABLED=true) |
add_roster_member | write | Add a member to an on-call roster (cmn_rota_member). Requires WRITE_ENABLED=true |
add_user_to_group | write | Add a user to a group (requires WRITE_ENABLED=true) |
add_work_note | write | Add an internal work note to any ITSM record (requires WRITE_ENABLED=true) |
advance_hr_case | read | Advance an HR case to its next state/stage (sn_hr_core_case). Parity with ServiceNow HRSD |
aggregate_report | read | Server-side aggregate REPORT grouped by a field, in ONE query with no 1000-row truncation. Returns per-group record count PLUS averages/sums/mins/maxes of numeric or duration fields — the right tool for a periodic summary like |
ai_search | read | Semantic AI-powered search across KB, catalog, incidents (ServiceNow AI Search) |
analyze_data_quality | read | Analyse data quality for a table — completeness, duplicates, stale records |
api_name | read | desired API name (e.g. |
app | read | scoped app name or scope prefix e.g. x_myco_app |
app_name | read | application name |
approve_request | read | Approve a pending approval request (requires WRITE_ENABLED=true) |
artifact | read | Paste code, provide a sys_id, or name a business rule/script include/client script/widget/flow action |
artifact_type | read | artifact type to test |
assign_user_criteria | read | Attach a user criteria to a catalog item as available-for (sc_cat_item_user_criteria_mtom). Requires WRITE_ENABLED=true |
batch_request | write | Execute multiple ServiceNow REST API operations in a single HTTP call. |
build-app | read | Build a complete scoped application from scratch — tables, scripts, ACLs, catalog item, tests, and update set packaging |
build-atf-suite | read | AI-generates runnable ATF test suites from business rules, script includes, flows, or any ServiceNow artifact |
build-business-rule | read | Guided business rule creation — understand requirement, check existing rules, generate, review, create, and test |
build-catalog | read | End-to-end catalog item creation — variables, UI policies, client scripts, approval rules, fulfillment workflow |
build-client-script | read | Guided client script creation — onChange, onLoad, onSubmit with g_form/g_user best practices and GlideAjax patterns |
build-flow | read | Guided Flow Designer creation — triggers, actions, subflows, error handling, testing |
build-portal | read | Guided Service Portal widget creation — server script, client controller, HTML template, CSS, data brokers |
build-rest-api | read | Guided Scripted REST API endpoint design — authentication, input validation, versioning, error responses |
build-test-plan | read | Generate comprehensive ATF test suites from requirements or existing artifacts — covers all testable ServiceNow components |
build-uib | read | Guided UI Builder component creation — macroponents, data sources, responsive layouts, Next Experience |
bulk_create_records | write | Create many records in one table in a single call, tracking every created sys_id and returning a rollback_token. With rollback_on_error=true, a mid-way failure deletes everything already created so the batch is all-or-nothing. Supports dry_run. Requires WRITE_ENABLED=true. |
bulk_get_properties | read | Retrieve multiple system property values in a single call |
bulk_set_properties | write | Create or update multiple system properties in a single operation. **[Write]** |
categorize_incident | read | Suggest category, assignment group, and priority for an incident by analysing similar resolved incidents (Table API). Predictive Intelligence has no public REST prediction endpoint; for model-based scoring run PI on-record and read the predicted field. |
category | read | catalog category (e.g., Hardware, Software, Access, Services) |
change | read | change number e.g. CHG0012345 or describe the planned change |
change_readiness | read | One-call change readiness check. Returns the change request, its conflict status, approval state, affected CIs, and other active changes that overlap the same CI. Read-only. |
check_hr_eligibility | read | Check an employee\ |
check_table_completeness | read | Analyze data quality and field completeness for a ServiceNow table — |
ci-health | read | CMDB health check for a named CI |
ci_class | read | Limit scan to a specific CI class (e.g. |
ci_name | read | Name or sys_id of the Configuration Item |
clone_artifact | read | Clone a platform artifact to a new name/scope. **[Scripting]** |
close_change_request | read | Close a change request with close code and notes (requires WRITE_ENABLED=true) |
close_csm_case | read | Close a CSM case with resolution details (requires WRITE_ENABLED=true) |
close_hr_case | read | Close an HR case with resolution notes (requires WRITE_ENABLED=true) |
close_incident | read | Close a resolved incident (requires WRITE_ENABLED=true) |
cmdb_find_duplicates | read | Find duplicate CIs by matching on specified fields (in-memory grouping) |
cmdb_find_orphans | read | Find CIs with no relationships in cmdb_rel_ci |
cmdb_find_stale | read | Find CIs not updated within a given number of days that are still operational |
cmdb_find_unmapped_cis | read | Find operational CIs that have relationships but belong to no application service (mapping gaps). Parity with ServiceNow get_unmapped_topology |
cmdb_health_dashboard | read | Get CMDB data quality metrics (completeness of server and network CI data) |
cmdb_impact_analysis | read | Analyze the downstream impact of a Configuration Item change or outage |
cmdb_reconcile | destructive | Act on duplicate, stale, or orphan CIs — merge, retire, or remove (requires CMDB_WRITE_ENABLED). Supports dry_run mode. |
cmdb_services_for_ci | read | Reverse lookup: which application services contain a given CI/server (svc_ci_assoc). Parity with ServiceNow get_all_application_services_for_a_server |
commit_changeset | write | Commit an update set (requires SCRIPTING_ENABLED=true) |
compare_instances | read | Compare two configured ServiceNow instances: record counts for a table (with optional query) and/or a specific system property value. Useful for dev→prod drift detection and governance. |
compare_record_counts | read | Compare record counts across multiple ServiceNow tables or time periods — useful for capacity planning |
complete_catalog_task | read | Close a catalog fulfillment task (sc_task) as complete. Requires WRITE_ENABLED=true |
complete_task | read | Mark a task as complete (requires WRITE_ENABLED=true) |
complete_update_set | write | Mark an Update Set as complete (ready for migration). **[Scripting]** |
component_type | read | page, macroponent, data_resource. Default: macroponent |
configure_offline_sync | write | Configure which tables/records are available offline in mobile. **[Write]** |
configure_workspace_list | write | Add or update a list view in an agent workspace. **[Write]** |
copy_attachment | read | Copy an existing ServiceNow attachment onto another record, entirely server-side |
coverage | read | Coverage level: basic (happy path), standard (happy + edge cases), comprehensive (all paths + negative). Default: standard |
create-incident | write | Guided incident creation — asks for details then creates the record |
create_acl | write | Create a new ACL rule to control access to a table or field (requires SCRIPTING_ENABLED=true) |
create_agentic_workflow | write | Create an agentic workflow linked to an AI agent (requires NOW_ASSIST_ENABLED + WRITE_ENABLED) |
create_ai_agent | write | Create an AI agent definition with optional auto-generated ACLs (requires NOW_ASSIST_ENABLED + WRITE_ENABLED) |
create_approval_rule | write | Create an approval rule that automatically generates approval requests when a record matches given conditions (requires WRITE_ENABLED=true). |
create_asset | write | Create a new IT asset record. **[Write]** |
create_business_rule | write | Create a new business rule (requires SCRIPTING_ENABLED=true). ServiceNow supports ES2021 async/await in scripts. |
create_business_service | write | Create a business service (cmdb_ci_service). Requires WRITE_ENABLED=true |
create_catalog_category | write | Create a catalog category (sc_category). Requires WRITE_ENABLED=true |
create_catalog_item | write | Create a new service catalog item (requires WRITE_ENABLED=true) |
create_catalog_ui_policy | write | [Write] Create a UI policy for a catalog item form |
create_catalog_variable | write | [Write] Add a form variable to a service catalog item |
create_change_request | write | Create a new change request (requires WRITE_ENABLED=true) |
create_ci_relationship | write | [Write] Create a relationship between two CMDB Configuration Items |
create_client_script | write | Create a new client script (onLoad, onChange, onSubmit, onCellEdit) (requires SCRIPTING_ENABLED=true) |
create_csm_case | write | Create a new Customer Service case (requires WRITE_ENABLED=true) |
create_dashboard | write | Create a new Performance Analytics dashboard (requires WRITE_ENABLED=true) |
create_decision_input | write | Add an input to a decision table (sys_decision_input). Requires WRITE_ENABLED=true |
create_decision_table | write | Create a Decision Builder decision table (sys_decision). Requires WRITE_ENABLED=true |
create_delegation | write | Create an approval/coverage delegation (sys_user_delegate). Requires WRITE_ENABLED=true |
create_demand | write | Create an SPM demand (dmn_demand). Requires WRITE_ENABLED=true. |
create_devops_change | write | Create a change request linked to a DevOps deployment for change governance. **[Write]** |
create_epic | write | Create a new epic (requires WRITE_ENABLED=true) |
create_flow | write | Create a new Flow Designer flow. **[Write]** |
create_flow_action | write | Create a custom Flow Designer action. **[Scripting]** |
create_grc_control | write | Author a compliance control (sn_compliance_control). Requires WRITE_ENABLED=true |
create_grc_issue | write | Raise a GRC issue/finding (sn_grc_issue). Requires WRITE_ENABLED=true |
create_grc_risk | write | Create a new GRC risk entry. **[Write]** |
create_group | write | Create a new assignment group (requires WRITE_ENABLED=true) |
create_hr_case | write | Create a new HR Service Delivery case (requires WRITE_ENABLED=true) |
create_hr_task | write | Create a task within an HR case (requires WRITE_ENABLED=true) |
create_import_set_row | write | Insert a row into an Import Set staging table for later transformation (requires WRITE_ENABLED=true) |
create_incident | write | Create a new incident record (requires WRITE_ENABLED=true) |
create_knowledge_article | write | Create a new knowledge article (requires WRITE_ENABLED=true) |
create_kpi | write | [Write] Create a Key Performance Indicator from ServiceNow data |
create_mobile_app_config | write | Create a new mobile app configuration. **[Write]** |
create_mobile_applet | write | Create a mobile applet in a mobile app. **[Write]** |
create_mobile_layout | write | Create a mobile layout for a specific view. **[Write]** |
create_notification | write | Create a new email notification definition (requires WRITE_ENABLED=true) |
create_now_assist_skill | write | Create a Now Assist skill definition (requires NOW_ASSIST_ENABLED + WRITE_ENABLED) |
create_offboarding_case | write | Create an employee offboarding case with exit tasks. **[Write]** |
create_on_call_override | write | Create an on-call coverage override for a date range (cmn_rota_override). Requires WRITE_ENABLED=true |
create_onboarding_case | write | Create an employee onboarding case with all standard tasks. **[Write]** |
create_pa_breakdown | write | Create a Performance Analytics (PA) breakdown on |
create_pa_indicator | write | Create a Performance Analytics (PA) indicator / KPI on |
create_playbook | write | Create a playbook definition with ordered steps that chain tool calls (requires NOW_ASSIST_ENABLED + WRITE_ENABLED) |
create_portal | write | Create a new Service Portal configuration (requires WRITE_ENABLED=true) |
create_portal_page | write | Create a new page inside a Service Portal (requires WRITE_ENABLED=true) |
create_portal_widget | write | Create a new Service Portal widget with template, CSS, and scripts (requires WRITE_ENABLED=true) |
create_problem | write | Create a new problem record (requires WRITE_ENABLED=true) |
create_project | write | Create a SPM project (pm_project). Requires WRITE_ENABLED=true. |
create_record | write | Create a new record in any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the resolved payload without writing. |
create_report | write | Create a new saved report on any table (requires WRITE_ENABLED=true) |
create_rest_message | write | Create a new outbound REST Message definition (requires WRITE_ENABLED=true) |
create_role | write | Create a new role (sys_user_role). Requires WRITE_ENABLED=true |
create_rota_schedule | write | Create an on-call rotation (cmn_rota) for a group. Requires WRITE_ENABLED=true |
create_scheduled_job | write | Create a new scheduled script execution job (requires WRITE_ENABLED=true) |
create_scheduled_report | write | [Write] Schedule a report for recurring email delivery |
create_scoped_app | write | Create a new scoped application in App Studio (requires WRITE_ENABLED=true). |
create_script_include | write | Create a new script include (requires SCRIPTING_ENABLED=true) |
create_scrum_task | write | Create a scrum task (sub-task of a story) (requires WRITE_ENABLED=true) |
create_security_incident | write | Create a Security Operations incident (requires WRITE_ENABLED=true) |
create_service_offering | write | Create a service offering under a business service (service_offering). Requires WRITE_ENABLED=true |
create_sla_definition | write | Create an SLA/OLA definition (contract_sla). Requires WRITE_ENABLED=true |
create_solution_package | write | Create a solution package from selected update sets for distribution. **[Write]** |
create_story | write | Create a new agile story/user story (requires WRITE_ENABLED=true) |
create_story_dependency | write | Link one agile story as dependent on another (m2m_story_dependencies). Requires WRITE_ENABLED=true. |
create_subflow | write | Create a new reusable subflow. **[Write]** |
create_survey | write | Create a survey/assessment definition (asmt_metric_type). Requires WRITE_ENABLED=true |
create_ui_action | write | Create a new UI Action (button or link) on a form (requires SCRIPTING_ENABLED=true) |
create_ui_policy | write | Create a new UI Policy to control field behavior dynamically (requires SCRIPTING_ENABLED=true) |
create_uib_component | write | Create a custom UI Builder component (macroponent). **[Scripting]** |
create_uib_data_broker | write | Create a UI Builder data broker to feed data to a page. **[Scripting]** |
create_uib_page | write | Create a new UI Builder page with route registration. **[Write]** |
create_update_set | write | Create a new Update Set and optionally switch to it. **[Scripting]** |
create_user | write | Create a new user account (requires WRITE_ENABLED=true) |
create_user_criteria | write | Create a user criteria record (user_criteria) for catalog entitlement/audience. Requires WRITE_ENABLED=true |
create_ux_app_route | write | Register a new route (URL path) in a UX app. **[Write]** |
create_ux_experience | write | Create a new UX Experience (app shell) configuration. **[Write]** |
create_va_topic | write | Create a new Virtual Agent conversation topic. **[Write]** |
create_workspace | write | Create a new configurable agent workspace. **[Write]** |
deactivate_user | read | Deactivate (offboard) a user by setting active=false. Requires WRITE_ENABLED=true |
delete_attachment | destructive | Delete an attachment from a record (requires WRITE_ENABLED=true) |
delete_record | destructive | Delete a record from any ServiceNow table (requires WRITE_ENABLED=true). Pass dry_run=true to preview the record that would be deleted without deleting it. |
delete_story_dependency | destructive | Remove a story dependency link by its m2m_story_dependencies sys_id. Requires WRITE_ENABLED=true. |
delete_system_property | destructive | Delete a system property by name. **[Write]** |
delete_uib_page | destructive | Delete a UI Builder page. **[Write]** |
deploy-updateset | write | Preview and commit an update set |
description | read | what the app does |
discover_table | read | Discover a ServiceNow table schema and register dynamic CRUD tools for it. |
docs-app | read | Auto-generate comprehensive documentation for a scoped application — tables, scripts, flows, ACLs, catalog items, and architecture |
docs-release | write | Generate release notes from update set contents — summarize all changes, categorize by type, highlight breaking changes |
docs-runbook | read | Generate operational runbook for a service, application, or CI — incident response steps, health checks, escalation paths |
docs-script | read | Generate detailed documentation for a specific script — JSDoc, explanation, usage examples, dependencies |
ensure_active_update_set | write | Ensure an active Update Set exists; create one automatically if none is in progress. **[Scripting]** |
execute_background_script | write | Execute a background script on the instance (server-side JavaScript). **[Scripting]** |
execute_playbook | write | Execute a playbook step by step, passing results forward through context (requires NOW_ASSIST_ENABLED). Supports dry_run. |
execute_script | write | Execute a server-side script on the ServiceNow instance (Background Script). |
export_properties | read | Export system properties matching a query to a JSON object (useful for environment snapshots) |
export_report_data | read | Export raw table data as structured JSON for use in external reports |
export_update_set | write | Get the XML export payload for an Update Set (as used in migration). **[Scripting]** |
fetch_servicenow_doc | read | Fetch the full readable text of a specific ServiceNow documentation page. Pass either the |
field | read | field name for onChange scripts |
find_artifact | read | Search for platform artifacts by name, type, or scope (business rules, scripts, widgets, etc.) |
find_property_usage | read | Find scripts that read a system property (sys_properties) by name, plus the property record itself. Use it before changing or removing a property. Matches are substring (LIKE) hits — candidates to review, not definitive. |
find_update_sets | write | List the update sets that contain changes to an artifact (by name), so you know what is in-flight or already captured for promotion before you touch it. |
fire_event | read | Fire a custom ServiceNow event for a specific record (requires WRITE_ENABLED=true) |
fluent_build | read | Build a ServiceNow fluent/now-sdk project. Runs |
fluent_cicd | write | Run ServiceNow CI/CD operations via the SDK ( |
fluent_explain | write | Run |
fluent_init | read | Initialize a new ServiceNow fluent/now-sdk project. Runs |
fluent_query | read | GlideQuery-style fluent query builder. Supports select, where, aggregate (COUNT/AVG/SUM/MIN/MAX), |
fluent_sdk_query | write | Run |
fluent_validate | read | Validate a ServiceNow fluent/now-sdk project. Runs |
fluent_version | read | Report the installed |
focus | read | Review focus: security, performance, best-practices, upgrade-safety, or all (default: all) |
fulfillment_type | read | flow, workflow, approval_only. Default: flow |
generate_case_activity_response | read | Draft an agent reply for a CSM case activity stream via the Now Assist activity-response skill when available, else return the case context to draft from. Parity with ServiceNow CSM |
generate_csm_resolution_notes | read | Generate CSM resolution notes via the Now Assist resolution-notes skill when available, else return the case + work notes to summarize. Parity with ServiceNow CSM |
get_acl | read | Get full details of an ACL rule including its script and role requirements (requires SCRIPTING_ENABLED=true) |
get_ai_agent | read | Get an AI agent definition and its related ACLs |
get_ai_agent_execution | read | Get an AI Agent execution plan with its steps/tool calls (sn_aia_execution_plan + _step) |
get_approval_history | read | Get the approval progression/history for any record (sysapproval_approver rows, ordered) |
get_asset | read | Get full details of an IT asset including financial and lifecycle data |
get_atf_failure_insight | read | Get ATF Failure Insight data — metadata changes between last successful and failed run (role changes, field value changes) |
get_atf_suite | read | Get details of a test suite including test count |
get_atf_suite_result | write | Get the results of a test suite run |
get_atf_test | read | Get details of a specific test case |
get_attachment_metadata | read | Get metadata (name, type, size) of a specific attachment by its sys_id |
get_business_rule | read | Get full details and script body of a business rule (requires SCRIPTING_ENABLED=true) |
get_case_sentiment | read | Assess customer sentiment on a CSM case via the Now Assist sentiment skill when available, else return the case + customer comments for sentiment analysis. Parity with ServiceNow CSM |
get_catalog_item | read | Get full details of a catalog item including its variables |
get_change_request | read | Get full details of a change request by number (CHG...) or sys_id |
Trust audit
BLOCKgrade F · trust 50/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
'- No `eval()` or dynamic script execution.',
'- No `eval()` or dynamic script execution.',
'- **Injection risks** — `eval()`, `GlideEvaluator` with untrusted input, SQL-like string concatenation in queries',
'- Inline Script steps with `eval()`, `GlideEvaluator`, or `Packages.java.*`',
'- `eval()` or `GlideEvaluator` with user-controlled input',
icon.icns
console.log(chalk.green(` ✓ Stored token for ${chalk.bold(stored.snUser)}`) + expiredNote);console.log(chalk.yellow(`No token found for ${instanceUrl}`));Impact: Any authenticated user can call these server-side functions; DataExporter could be used for data exfiltration
if (origin.startsWith(`http://localhost:${PORT}`) || origin.startsWith(`http://127.0.0.1:${PORT}`)) return true;if (origin.startsWith('http://localhost:5173') || origin.startsWith('http://127.0.0.1:5173')) return true;const u = new URL(req.url || '/', `http://127.0.0.1:${port}`);cmdb_reconcile, delete_attachment, delete_record, delete_story_dependency, delete_system_property, delete_uib_page, http_methods, list_acls, remove_user_from_group, revoke_role, rollback_changes
.env.basic.example
.env.oauth.example
.env.basic.example
.env.oauth.example
const OUTPUT_DIR = resolve(import.meta.dirname, '../../../website-nowaikit/assets/reports');
const pkgDir = fileURLToPath(new URL('../../../', import.meta.url)).replace(/[\\/]$/, '');import { buildAgentCard } from '../../src/a2a/agent-card.js';import { VERSION } from '../../src/utils/version.js';import { detectClients } from '../../src/cli/detect-clients.js';# Listening on http://127.0.0.1:3100
expect(card.url).toBe('http://0.0.0.0:8080');electron-store, electron-updater, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently, electron, electron-builder
Gates applied: no_behavioural_pass.
e01ed8164e42full audit observations/trust-audit/mcp-server/aartiq__servicenow-integration.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | e01ed8164e42 | BLOCK | F | 50 | first audit |
Questions
What is the ServiceNow Integration MCP server?
ServiceNow MCP server: 500+ tools and 26 AI capabilities for any AI (Claude, ChatGPT, Gemini, Cursor, Copilot). Multi-transport (stdio, SSE, HTTP), A2A, dynamic schema discovery, read-only by default. Free and source available. Part of the NowAIKit suite.
What tools does ServiceNow Integration expose?
200 in total: 366 read-only, 207 that write, and 11 that can delete or overwrite (cmdb_reconcile, delete_attachment, delete_record, delete_story_dependency, delete_system_property). Every one is listed on this page with its risk.
Is ServiceNow Integration safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (50/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 11 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does ServiceNow Integration need?
It reads DELEGATED_AUTH, GEMINI_API_KEY, NOWAIKIT_API_KEY, NOWAIKIT_DELEGATED_SECRET, NOWAIKIT_OAUTH_PORT, OPENAI_API_KEY, SERVICENOW_AUTH_METHOD, SERVICENOW_BASIC_PASSWORD, SERVICENOW_BEARER_TOKEN, SERVICENOW_CLIENT_SECRET, SERVICENOW_OAUTH_CLIENT_ID and SERVICENOW_OAUTH_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ServiceNow Integration run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nowaikit at 4.21.0.
How current is this page?
The grade is for one exact copy of the source (e01ed8164e42), read on 2026-10-06. The repository is watched and re-audited when it changes.