Open iT / ServiceNow MCP Pilot

Open iT / ServiceNow MCP Pilot

This MCP server provides a read-only tool to find products without entitlement records using deterministic mock data, supporting publisher filtering and result limits. It is a pilot scaffold for Open iT and ServiceNow SAM Pro integration.

Category
访问服务器

README

Open iT / ServiceNow MCP Pilot

This repository contains a deliberately small remote MCP server scaffold for an Open iT / ServiceNow SAM Pro pilot. It exposes one read-only tool over Streamable HTTP and uses deterministic mock inventory data; it does not call Open iT or ServiceNow APIs.

What it exposes

  • MCP endpoint: /api/mcp
  • Public health endpoint: /api/health
  • Tool: find_products_without_entitlements

The MCP endpoint follows the Microsoft Learn MCP pattern: clients use Streamable HTTP, while a normal browser GET receives HTTP 405 Method Not Allowed and a short explanation. The endpoint is stateless and returns JSON MCP responses, which keeps it suitable for horizontally scaled or serverless hosting later. api/index.py exposes the same ASGI application as a future Vercel entry point; no deployment is included.

Run locally

Python 3.11 or newer is required.

python -m venv .venv
.\.venv\Scripts\Activate.ps1
python -m pip install -e ".[dev]"
$env:OPENIT_MCP_API_KEY = "local-dev-key"
$env:MCP_BIND_HOST = "127.0.0.1"
$env:PORT = "8000"
$env:MCP_BASE_URL = "http://127.0.0.1:8000"
openit-mcp

For bash/zsh, activate with source .venv/bin/activate and configure the key with:

export OPENIT_MCP_API_KEY="local-dev-key"
export MCP_BIND_HOST="127.0.0.1"
export PORT="8000"
export MCP_BASE_URL="http://127.0.0.1:8000"

MCP_BIND_HOST and PORT are used only by the local openit-mcp Uvicorn launcher. MCP_BASE_URL is used only by external clients such as examples/invoke.py; the server itself routes internally with relative paths and never calls itself through an absolute URL.

The server intentionally returns 503 from MCP POST and DELETE requests when OPENIT_MCP_API_KEY is unset. Clients should send the key as a bearer token:

Authorization: Bearer local-dev-key

For ServiceNow compatibility, the server also accepts the raw key in Authorization as well as X-API-Key: local-dev-key. The health endpoint does not require authentication.

Check health:

Invoke-RestMethod "$env:MCP_BASE_URL/api/health"

In a second terminal with the same virtual environment and API key, run the included MCP client example:

python examples/invoke.py

You can also connect an MCP Inspector or other Streamable HTTP client to $MCP_BASE_URL/api/mcp and configure the Authorization header shown above.

Opening the MCP URL directly in a browser returns:

HTTP 405 Method Not Allowed
This is an MCP server endpoint and cannot be accessed directly via a browser. Please use a streamable HTTP MCP client.

Tool contract

find_products_without_entitlements accepts:

Input Type Required Behavior
publisher string No Exact, case-insensitive publisher filter
limit integer No Defaults to 20; allowed range is 1 to 100

It returns structured JSON in this shape:

{
  "count": 1,
  "items": [
    {
      "product_name": "Open iT Analyzer Pro",
      "publisher": "Open iT",
      "reason": "No entitlement record found"
    }
  ],
  "explanation": "These products currently do not have matching entitlement records in the mock dataset.",
  "generated_at": "2026-08-05T12:00:00Z"
}

Results are sorted by publisher and product name before limit is applied.

Tests

pytest

The tests verify the published tool list, structured output, publisher filtering, deterministic limiting, browser 405 behavior, real HTTP MCP initialization/list/call requests, the public health endpoint, and fail-closed API key behavior.

Future hosted configuration

Loopback addresses are local-only: inside Vercel they refer to the function instance, not the public deployment or another service. The network-base address ending in .0 at the start of the IPv4 loopback block is not an application host and must not be used. Hosted URLs must come from deployment environment variables, while same-app routes should remain relative.

Vercel imports the ASGI app from api/index.py; it does not execute the local Uvicorn launcher, so MCP_BIND_HOST and PORT are not deployment assumptions. Configure these server environment variables before hosting:

OPENIT_MCP_API_KEY=<production-secret>
# Recommended when using a stable custom domain:
OPENIT_MCP_ALLOWED_HOSTS=openit-mcp.example.com,openit-mcp.example.com:*

The server automatically adds VERCEL_URL, VERCEL_BRANCH_URL, and VERCEL_PROJECT_PRODUCTION_URL to its MCP host allowlist when Vercel exposes those system variables. An explicit OPENIT_MCP_ALLOWED_HOSTS remains recommended for a stable custom domain.

Set MCP_BASE_URL=https://openit-mcp.example.com only if a hosted client or job runs examples/invoke.py; the MCP server routes /api/mcp and /api/health without it. Keep the API key in Vercel's secret environment configuration and use HTTPS. Environment changes apply only to new deployments, so redeploy after changing them.

Connect from ServiceNow AI Agent Studio

Use the following values after deploying to Vercel:

Field Value
Name Open iT SAM Pilot
Authentication type API Key
MCP server URL https://<your-stable-vercel-host>/api/mcp
API key The raw value of OPENIT_MCP_API_KEY

Do not add a Bearer prefix in the ServiceNow API Key field. The server accepts ServiceNow's raw Authorization value. A browser request to the URL still returns the intentional 405; tool discovery uses authenticated MCP POST requests.

Before ServiceNow integration

This pilot still needs a real Open iT data adapter, agreement on the product/entitlement matching rules and response fields, ServiceNow remote MCP connection configuration, production authentication (preferably OAuth 2.1 rather than a shared key), HTTPS hosting, logging/monitoring, secret rotation, and end-to-end validation from AI Agent Studio.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选