Set up the ServiceNow Remote Instance spoke
Integrate the local and remote ServiceNow instances by creating an OAuth API endpoint in the remote ServiceNow instance to authenticate requests.
Before you begin
- Request an Integration Hub subscription.
Activate the ServiceNow Remote Instance spoke in remote and local ServiceNow instances.
Note: The terms remote instance and local instance are used in these contexts:
- Local instance: This is the ServiceNow instance from which the communication is initiated and established.
- Remote instance: This is the ServiceNow instance with which the local instance communicates.
- Role required: admin.
Note: Admin role is required to only set up the spoke.
To use the spoke, you can either have the admin role or have only the required minimum permissions to access data in the required ServiceNow tables along with the import_transformer role. Do not assign elevated privilege roles to users of this spoke unless needed. This practice ensures controlled access to data.
The integration users must have the flow_operator and other required roles to access the table they want to interact with. Also, they need roles to access the Table [sys_db_object] and Dictionary Entry [sys_dictionary] tables to show dynamic options such as, table names and fields in a table.
Register remote ServiceNow instance as an OAuth provider
Register remote ServiceNow instance as an OAuth provider so that the local ServiceNow instance can request OAuth 2.0 tokens.
Before you begin
- In the remote ServiceNow instance:
- Create an OAuth API endpoint for external clients. In Redirect URL, specify the URL of the local ServiceNow instance in this format:
https://<instance-name>.service-now.com/oauth_redirect.do. For more information, see Create an endpoint for clients to access the instance. - Copy and record the values of Client ID and Client Secret.
- Create an OAuth API endpoint for external clients. In Redirect URL, specify the URL of the local ServiceNow instance in this format:
- Role required: admin
Procedure
Navigate to All > System OAuth > Application Registry.
Open for the record, RemoteSpoke.
On the form, fill these values.
| Field | Description | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Client ID | Client ID created in the remote ServiceNow instance. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Client Secret | Client Secret created in the remote ServiceNow instance. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Authorization URL | URL of the remote ServiceNow instance in this format: `https://| Token URL | URL of the remote ServiceNow instance in this format: `https:// | Redirect URL | URL of the local ServiceNow instance in this format: `https:// | Default Grant Type | Grant type used to establish the token. Select Authorization Code. | Refresh Token Lifespan | Time, in seconds, that the refresh token is valid. The default time is 8,640,0000 seconds. | PKCE required | Option to enable public clients to require PKCE for an authorization.Note: You can use only Authorization Code as the Default Grant type when PKCE is enabled. | Application | Application scope that contains this record. | Accessible from | Application scope that this registry is accessible from. | Active | Option to actively use the application registry. |
Create Credential record for the remote ServiceNow instanceCreate credential record for the remote ServiceNow instance. The ServiceNow Remote Instance spoke connection and credential alias uses these credentials to authorize actions. Before you beginRole required: admin. Note: You must perform this task in a local ServiceNow instance. Procedure
Create Connection record for the remote ServiceNow instanceCreate Connection record for your remote ServiceNow instance. The ServiceNow Remote Instance spoke connection and credential aliases use these connections to perform actions. Before you beginRole required: admin. Note: You must perform this task in a local ServiceNow instance. Procedure
|