ServiceNowCAUTION
Happy Platform MCP v5.1 - Multi-Instance ServiceNow MCP Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Happy MCP Server
Model Context Protocol Server for the ServiceNow® Platform
A metadata-driven MCP server that auto-generates 480+ tools across 160+ tables, with multi-instance support, natural language search, and local script development.
Website | GitHub | npm | Tools | Contributing | Support
Migrating from `servicenow-mcp-server`? The npm package has been renamed tohappy-platform-mcpand the Docker image tonczitzer/happy-platform-mcp. The old names are deprecated but will continue to work temporarily. Update your dependencies: ``bash # npm npm uninstall servicenow-mcp-server && npm install happy-platform-mcp # Docker docker pull nczitzer/happy-platform-mcp:latest``
Support
If you find this project useful, consider supporting its development. Contributions support Happy Technologies LLC.
#
282a23a6175dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add happy-platform-mcp --env SERVICENOW_PASSWORD=${SERVICENOW_PASSWORD} -- npx -y [email protected]Exposed tools (50)
27 read · 23 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
SN-Add-Change-Comment | write | Add a comment to a change request. Accepts change number for better UX. |
SN-Add-Comment | write | Add a comment to an incident. Accepts incident number for better UX. |
SN-Add-Problem-Comment | write | Add a comment to a problem. Accepts problem number for better UX. |
SN-Add-Work-Notes | write | Add work notes to an incident. Accepts incident number for better UX. |
SN-Approve-Change | read | Approve a change request. |
SN-Assign-Change | read | Assign a change request to a user and/or group. |
SN-Assign-Incident | read | Assign an incident to a user and/or group. Resolves user names automatically. |
SN-Batch-Create | write | Create multiple related records in one operation with variable references and transactional support. Reports progress during execution. |
SN-Batch-Update | write | Update multiple records efficiently in a single operation. Reports progress during execution. |
SN-Catalog-Get-Categories | read | List Service Catalog categories so you can browse available form families. Use the returned sys_ids with SN-Catalog-Search-Items to filter forms by category. |
SN-Catalog-Search-Items | read | Search or browse Service Catalog items and record producers. Use this to discover available forms before calling SN-Catalog-Get-Item to get full form details. |
SN-Catalog-Submit | write | Submit a Service Catalog form (catalog item or record producer). Provide the catalog item sys_id and a map of variable names to values. Use SN-Catalog-Get-Item first to discover required variables, their types, and valid choices. Returns the resulting request/task numbers. |
SN-Clone-Update-Set | write | Clone an entire update set with all its sys_update_xml records. Creates a complete copy for backup, testing, or branching development work. Reports progress during cloning operation. |
SN-Close-Incident | read | Close an incident with close notes and code. |
SN-Close-Problem | read | Close a problem with resolution information. |
SN-Create-Activity | write | Create a single workflow activity with embedded JavaScript code. Use this for adding activities to existing workflows. |
SN-Create-Incident | write | Create a new Incident |
SN-Create-Record | write | Create a record in any ServiceNow table by name. WARNING: For catalog_ui_policy_action table, fields ui_policy and catalog_variable cannot be set via REST API - use SN-Execute-Background-Script with setValue() after creation. |
SN-Create-Transition | write | Create a transition between two workflow activities with optional condition |
SN-Discover-Table-Schema | read | Deep schema introspection with ServiceNow-specific metadata including type codes, choice tables, and relationships |
SN-Docs-Families | read | List available ServiceNow documentation families/releases from the official ServiceNowDocs GitHub repository. |
SN-Docs-Get | read | Retrieve a ServiceNow documentation markdown document by family and path. |
SN-Docs-Search | read | Search locally synced ServiceNow documentation using SQLite FTS, with optional vector search when enabled. |
SN-Docs-Status | read | Show local ServiceNow docs cache, FTS index, and optional vector index status. |
SN-Docs-Sync | write | Download and index a ServiceNowDocs family into the local SQLite FTS cache. |
SN-Execute-Background-Script | write | Executes server-side JavaScript by creating a sys_trigger scheduled job that runs in ~1 second and auto-deletes after execution. Use for complex GlideRecord operations the CRUD tools cannot express. The job runs in the scheduler\ |
SN-Explain-Field | read | Get comprehensive explanation of a specific field including type, constraints, and known issues |
SN-Get-Current-Instance | read | Get information about the currently active ServiceNow instance |
SN-Get-Current-Update-Set | write | Get the currently active update set |
SN-Get-Incident | read | Get a Incident by ID |
SN-Get-Record | read | Get a specific record from any ServiceNow table by sys_id |
SN-Get-Table-Schema | read | Get the schema/metadata for any ServiceNow table including required fields, common fields, and field descriptions |
SN-Inspect-Update-Set | write | Inspect update set contents and verify completeness |
SN-List-Available-Tables | read | List all available ServiceNow tables with their descriptions and capabilities |
SN-List-ChangeRequests | read | List Change Request records with filtering and pagination |
SN-List-CmdbCis | read | List Cmdb Ci records with filtering and pagination |
SN-List-Incidents | read | List Incident records with filtering and pagination |
SN-List-Problems | read | List Problem records with filtering and pagination |
SN-List-SysUserGroups | read | List Sys User Group records with filtering and pagination |
SN-List-SysUsers | read | List Sys User records with filtering and pagination |
SN-List-Update-Sets | write | List available update sets |
SN-Move-Records-To-Update-Set | write | Move sys_update_xml records to a different update set. Supports filtering by sys_ids, time range, or source update set. Extremely useful when records end up in wrong update set (e.g., |
SN-Publish-Workflow | write | Publish a workflow version, setting the start activity and making it active |
SN-Query-Table | read | Query any ServiceNow table by name with flexible filtering |
SN-Resolve-Incident | read | Resolve an incident with resolution notes and code. |
SN-Set-Current-Application | write | Set the current application scope using the UI picker and verify the change in the same session. Reports the previous scope; returns an error if the change cannot be verified. |
SN-Set-Instance | write | Switch to a different ServiceNow instance. Use this at the start of your session to target a specific instance (dev, test, prod, etc.). Lists available instances if no name provided. |
SN-Set-Update-Set | write | Set the current update set through the ServiceNow UI picker and verify, in the same session, that it took effect. If the automated change fails or cannot be verified, a fix script is written to ./scripts for manual execution instead. |
SN-Update-Record | write | Update a record in any ServiceNow table by sys_id |
SN-Validate-Configuration | read | Validate catalog item configuration including variables, UI policies, and business rules |
Trust audit
CAUTIONgrade D · trust 67/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
secret: 'unit-test-non-secret'
password: 'legacy-password-fixture',
password: 'legacy-password-fixture',
password: 'legacy-password-fixture',
password: 'configured-password-fixture',
.gitleaks.toml
.gitleaksignore
exec(sql) {expect(() => new Function(generated)).not.toThrow();
expect(() => new Function(generated)).not.toThrow();
const DEFAULT_CONFIG_PATH = path.resolve(__dirname, '../../config/servicenow-instances.json');
['an invalid table', [{ table: 'incident/../../x', sys_id: hex(1), data: {} }]]'markdown/../../other/x.md',
for (const unsafe of ['../../etc/passwd.md', 'a%2F..%2Fb.md', 'x.md?y', undefined]) {const denied = await client.callTool({ name: 'SN-Docs-Get', arguments: { path: '../../../etc/passwd.md' } });proxy_pass http://127.0.0.1:3000;
`/health` requires the bearer token like every other route. The image's `HEALTHCHECK` (and the one in `docker-compose.yml`) reads `HAPPY_MCP_API_TOKEN` from the container environment at run time and c
Register `http://127.0.0.1:8202/callback` as the public client's redirect URL. Do not set `SERVICENOW_CLIENT_SECRET` for a public client.
Implement `validateNewInstance(instance)` with the approved invariants. Permit `http://127.0.0.1`, `http://localhost`, and `http://[::1]` only for loopback fixtures. Never include the whole submitted
console.log(`🚀 SSE Test Server listening on http://127.0.0.1:${PORT}`);@inquirer/prompts, @napi-rs/keyring, chokidar, dotenv, express, zod, @types/jest, jest
1. **HTTP/SSE:** generate a token (`openssl rand -hex 32`), set `HAPPY_MCP_API_TOKEN` on the server, and send `Authorization: Bearer <token>` from every HTTP client, probe and health check. Set `HAPPY
- Bound the SSE lifecycle: 16 pending and 32 active sessions; 30-second setup, 30-minute idle and 12-hour lifetime limits; 8 MiB JSON bodies; one POST at a time per session with up to 8 queued; 8 conc
- Bind persisted authorization-code refresh tokens to the OAuth identity they were issued for: a versioned `identity-v1-<sha256>` key over the local OS user, canonical instance URL, OAuth client ID, a
- OAuth authorize/token endpoints must share the instance origin unless the operator lists the external IdP origin in `SERVICENOW_OAUTH_TRUSTED_ORIGINS` (comma-separated exact origins). The policy is
Gates applied: no_behavioural_pass.
282a23a6175dfull audit observations/trust-audit/mcp-server/happy-technologies-llc__servicenow-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 282a23a6175d | CAUTION | D | 67 | first audit |
Questions
What is the ServiceNow MCP server?
Happy Platform MCP v5.1 - Multi-Instance ServiceNow MCP Server
What tools does ServiceNow expose?
50 in total: 27 read-only, 23 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ServiceNow safe to connect to an agent?
With care. The audit graded it D (67/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does ServiceNow need?
It reads GH_TOKEN, GITHUB_TOKEN, HAPPY_MCP_API_TOKEN, SERVICENOW_AUTH_TYPE, SERVICENOW_CLIENT_SECRET, SERVICENOW_OAUTH_AUTHORIZE_URL, SERVICENOW_OAUTH_CALLBACK_PATH, SERVICENOW_OAUTH_GRANT_TYPE, SERVICENOW_OAUTH_REDIRECT_PORT, SERVICENOW_OAUTH_SCOPE, SERVICENOW_OAUTH_TOKEN_URL and SERVICENOW_OAUTH_TRUSTED_ORIGINS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ServiceNow run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as happy-platform-mcp at 6.0.2.
How current is this page?
The grade is for one exact copy of the source (282a23a6175d), read on 2026-10-08. The repository is watched and re-audited when it changes.