Configure an OAuth JSON web token bearer grant
Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction. It enhances security with signed JWTs and reduces authentication overhead by eliminating repeated login attempts.
Before you begin
Role required: oauth_admin, mi_admin, oauth_admin
The supported algorithms for JSON Web Token (JWT): RS256, RS384, RS512, ES256, ES384, ES512, HS256, HS384, and HS512.
Procedure
Navigate to Machine Identity Console > Inbound integrations > New integration > OAuth - JWT bearer grant.
Update the text fields in the Details form with the appropriate information.
| Field | Description |
|---|---|
| Name | A unique name that identifies the application that you require JWT OAuth access for. |
| Provider name | Enter the name of the service provider you want to integrate with. Example: Microsoft, Google, Zoom, SAP, etc. Note: Provider name is a mandatory field. |
| Client ID | The auto-generated unique ID of the application. The system uses the value of this field to retrieve the public or shared key and validate the JWT. The value of this field should match the value of the issuer and audience claims in the JWT. |
| Client secret | The shared secret string that both the instance and the client application or website use to authorize communications with one another. Leave this field empty to have the instance auto-generate a client secret. To display existing client secrets, select the lock icon. |
| User field | Field in the User (sys_user) table that the system uses to match the value of the subject claim in the JWT. Example: If you add a token that has a subject claim value of user.name@example.com, then you would set the User Field to Email. This field tells the system to search the email field for the user.name@example.com value and use the matching user record in the inbound request. |
| Enable JTI Verification | Select to require a new token every token exchange.Default: Selected. |
| JTI claim | Unique identifier for each token. ServiceNow uses this claim to detect and prevent token replay by verifying that a token is not reused. |
| JWKS URL | The JSON Web key set URL. Its is a collection of public keys in JSON format. Identity providers publish a JWKS at a well-known URL so that client applications and services can retrieve the keys and validate the signatures of JSON Web Tokens \(JWTs\). |
| JWT verifier map | Specify the identity provider, the verification method (such as a JWKS URL or certificate), and the mapping of JWT claims to ServiceNow user fields. Select the Plus icon to add or edit the maps. Provide the following details in the JWT verifier map page:
|
| Comments | Add any notes about this configuration. |
| Active | Select to use for authentication and authorization requests; when unselected, the record is saved but remains inactive and will not process any requests. |
Perform the following steps to add auth scope to the configuration:
Select Create auth scope if you want to define a new scope.
Select a scope from the Auth scope drop-down.
Enter API names in Limit authorization to the following APIs to narrow access.
Use + Add another row to assign additional scopes to your configuration.
Select Allow access only to APIs in selected scope in the Scope validation settings to restricts access to listed scopes only.
Note: You can choose not to select Set Allow access only to APIs in selected scope for broader access permitted by user controls and API policies.
Update the text fields in the Advanced options (optional) form with the appropriate information.
| Field | Description |
|---|---|
| Enforce token restriction | Select to only enable tokens to be used with APIs set to enable the authentication profile. You can set grant access using an API access policy.Default: Unselected. |
| JWKS cache lifespan | The duration \(in minutes\) for which ServiceNow caches the JSON Web Key Set \(JWKS\) from the identity provider. |
| Access token lifespan | The duration \(in seconds\) for which the access token remains valid before it expires. Default value is: 1800 seconds \(30 minutes\). |
| Clock skew | Small differences in the system clocks of servers or devices involved in generating and validating a token can lead to issues when validating time-sensitive claims. Adjust the time above. Default value is: 300 seconds. |
| Token Format | Format of token to generate. Options: - JWT - Opaque Note:
|
Select Save.
A new OAuth JSON Web Token bearer grant is created.