@mindstone/mcp-server-servicenow

ServiceNow ITSM MCP server for Model Context Protocol hosts. Manage incidents, change requests, users, and knowledge base articles in ServiceNow through a standardised MCP interface.
Status
- Version: 0.3.1 Β· npm
- Auth: Basic auth (username + password) or OAuth 2.0 client credentials (
SERVICENOW_PASSWORD)
- Tools: 13 (incidents, change-requests, users, knowledge, service-catalog)
- Surface: cloud-api
- Machine-readable:
STATUS.json
Requirements
One-click install

After clicking the button, your host will prompt you to fill: SERVICENOW_INSTANCE, SERVICENOW_USERNAME, SERVICENOW_PASSWORD, SERVICENOW_CLIENT_SECRET.
Manual config for Claude Desktop / Claude Code / Goose / Continue.dev (ServiceNow)
{
"mcpServers": {
"ServiceNow": {
"command": "npx",
"args": [
"-y",
"@mindstone/mcp-server-servicenow"
],
"env": {
"SERVICENOW_INSTANCE": "",
"SERVICENOW_USERNAME": "",
"SERVICENOW_PASSWORD": "",
"SERVICENOW_CLIENT_SECRET": ""
}
}
}
}
Quick Start
Install & build
cd <path-to-repo>/connectors/servicenow
npm install
npm run build
npx (once published)
npx -y @mindstone/mcp-server-servicenow
Local
Configuration
Environment variables
SERVICENOW_INSTANCE β ServiceNow instance name (e.g. acme for acme.service-now.com)
SERVICENOW_USERNAME β ServiceNow username
SERVICENOW_PASSWORD β ServiceNow password
SERVICENOW_CLIENT_ID β optional OAuth 2.0 client ID (alternative to username/password; see below)
SERVICENOW_CLIENT_SECRET β optional OAuth 2.0 client secret
MCP_HOST_BRIDGE_STATE β optional path to a host bridge state file used for credential management
MINDSTONE_REBEL_BRIDGE_STATE β backwards-compatible alias for MCP_HOST_BRIDGE_STATE
OAuth 2.0 (client credentials)
Instances that enforce MFA/SSO often disable basic auth. As an alternative, the connector supports the OAuth 2.0 client credentials grant:
- On the instance, enable the inbound client credentials grant (system property
glide.oauth.inbound.client.credential.grant_type.enabled = true).
- Create an entry under System OAuth β Application Registry β New β Create an OAuth API endpoint for external clients and note the client ID and secret.
- Set
SERVICENOW_INSTANCE, SERVICENOW_CLIENT_ID, and SERVICENOW_CLIENT_SECRET (leave username/password unset).
Tokens are fetched from the instance's oauth_token.do endpoint and cached until shortly before expiry. When both auth methods are configured, basic auth takes precedence.
Host configuration examples
Claude Desktop / Cursor
{
"mcpServers": {
"ServiceNow": {
"command": "npx",
"args": ["-y", "@mindstone/mcp-server-servicenow"],
"env": {
"SERVICENOW_INSTANCE": "your-instance",
"SERVICENOW_USERNAME": "your-username",
"SERVICENOW_PASSWORD": "your-password"
}
}
}
}
Local development (no npm publish needed)
{
"mcpServers": {
"ServiceNow": {
"command": "node",
"args": ["<path-to-repo>/connectors/servicenow/dist/index.js"],
"env": {
"SERVICENOW_INSTANCE": "your-instance",
"SERVICENOW_USERNAME": "your-username",
"SERVICENOW_PASSWORD": "your-password"
}
}
}
}
Configuration
configure_servicenow β Configure ServiceNow instance credentials
Incidents
list_servicenow_incidents β List or search incidents
get_servicenow_incident β Get a single incident by number or sys_id
create_servicenow_incident β Create a new incident
update_servicenow_incident β Update an existing incident (including appending work_notes / comments journal entries)
Change requests
list_servicenow_change_requests β List or search change requests
get_servicenow_change_request β Get a single change request by number or sys_id
create_servicenow_change_request β Create a new change request
Users
list_servicenow_users β List or search users
Knowledge base
search_servicenow_knowledge β Search knowledge base articles
get_servicenow_knowledge_article β Get a full knowledge base article
Service catalog
list_servicenow_catalog_items β List or search service catalog items
get_servicenow_catalog_item β Get a single catalog item by sys_id
Security
All external text returned by ServiceNow (record descriptions, work notes, user names, article bodies, and any custom fields) is wrapped in <untrusted-content source="servicenow:...">...</untrusted-content> envelopes with close-tag breakout escaping before it reaches the model, so third-party content is treated as data, not instructions. Identifiers (sys_id, number), timestamps, and choice-list display values are left literal so they can be copied into follow-up tool calls.
Licence
FSL-1.1-MIT β Functional Source License, Version 1.1, with MIT future licence. The software converts to MIT licence on 2030-04-08.