snow-mcp-server
Secure MCP runtime on Google Cloud Run enabling ServiceNow AI Agents to access another ServiceNow instance as the signed-in user via delegated OAuth, with read-only tools for work items and pending approvals.
README
Secure Delegated ServiceNow MCP Runtime
A secure MCP runtime on Google Cloud Run that enables a ServiceNow AI Agent to access another ServiceNow instance as the signed-in user—using delegated OAuth, least-privilege scopes, Dynamic Me filtering, Cloud KMS encryption, and rotating refresh tokens.
Status: Completed · End-to-end validated with ServiceNow Agent Studio<br> Stack: TypeScript · Node.js · MCP · ServiceNow · Cloud Run · Firestore · Cloud KMS<br> Validation: 79 automated tests passing
Architecture
flowchart LR
A["ServiceNow AI Agent<br/>MCP Client"]
B["Secure MCP Runtime<br/>Google Cloud Run"]
C["ServiceNow Resource Instance<br/>Delegated User Context"]
D[("Firestore<br/>Sessions & Token Hashes")]
E["Cloud KMS<br/>Encrypted Delegated Tokens"]
A -->|"OAuth + PKCE<br/>MCP tools"| B
B -->|"Delegated user bearer<br/>Allowlisted API queries"| C
B --> D
B --> E
The MCP bearer authenticates the client to this runtime and is never sent to ServiceNow. A separate delegated bearer represents the signed-in user to the ServiceNow resource instance, where Dynamic Me and ACLs enforce user-level access.
What this project demonstrates
- Delegated identity across two ServiceNow instances.
- An enterprise MCP client/server integration with ServiceNow Agent Studio.
- Separation between the MCP client bearer and the downstream user bearer.
- Least-privilege tool scopes and server-owned query construction.
- Secure token storage, rotation, replay detection, and session revocation.
- Cloud-native deployment and automated validation on Google Cloud.
Demo
The MCP server was authenticated from ServiceNow Agent Studio and exposed to a ServiceNow AI Agent through two read-only tools. The end-to-end flow was validated in the deployed environment:
ServiceNow Agent Studio
→ MCP server on Google Cloud Run
→ delegated end-user OAuth
→ ServiceNow resource instance
→ user-scoped tool results
The AI Agent successfully invokes both tools, and ServiceNow scopes the returned records to the signed-in user.
Implemented tools
get_work_items
- Accepts
status:open(default) orall. - Accepts
limit: integer from 1 to 100 (default 20). - Reads incidents where
caller_idoropened_byis the signed-in user. - Reads requested items where
requested_fororopened_byis the signed-in user. - Adds
source_table,relationship_to_user, and, for work opened for another person, the display name inother_person. - Requires
mcp.work_items.read.
get_pending_approvals
- Accepts
limit: integer from 1 to 100 (default 20). - Returns only approvals whose state is
requestedand whoseapproveris the signed-in user. - Requires
mcp.approvals.read.
Tool inputs cannot select an ownership mode, table, field, encoded query, approver, user identifier, or Dynamic Me filter ID. Responses contain only allowlisted ServiceNow fields and server-derived relationship metadata. See the architecture for the fixed query plans and trust boundaries.
Security highlights
- Authorization Code with canonical PKCE S256.
- Exact OAuth client, redirect URI, scope, and resource binding.
- Delegated ServiceNow execution as the signed-in user.
- Cloud KMS encryption with session- and purpose-bound contexts.
- Opaque MCP refresh tokens stored only as SHA-256 hashes.
- Atomic refresh-token rotation with replay-family session revocation.
- Fixed tables, fields, limits, sorts, and Dynamic Me query plans.
- No arbitrary encoded queries or user identifiers from the AI Agent.
- HTTPS-only ServiceNow token exchange with redirects disabled.
- No access tokens, refresh tokens, authorization codes, record content, or query results in logs.
OAuth flow
The MCP-facing flow supports Authorization Code with PKCE S256 and rotating refresh tokens for public clients:
- The client calls
/oauth/authorizewith the canonical MCPresourceand an explicit request for one or both supported tool scopes. - The runtime validates the OAuth client, exact redirect URI, resource, scopes, and canonical PKCE challenge, then redirects the browser to ServiceNow.
- The callback exchanges the ServiceNow code and stores both delegated tokens encrypted in the MCP session.
- The client exchanges the returned MCP authorization code, the same
resource, and the PKCE verifier at/oauth/tokenfor an MCP bearer lasting up to 15 minutes and a rotating refresh token. - Each tool call validates the MCP bearer, session, and required tool scope before using the delegated ServiceNow bearer for a fixed query.
- The client renews access with
grant_type=refresh_token, the sameclient_id, and the sameresource. Each successful use rotates the MCP refresh token; the delegated ServiceNow token is refreshed only when needed.
Plaintext delegated tokens and plaintext MCP refresh tokens are never stored. Refresh-token reuse revokes the session. MCP refresh tokens expire after 30 days of inactivity, and each token family has a maximum lifetime of 90 days. Users authorize again only after expiry, revocation, or an invalid downstream refresh grant.
Configuration
Required environment variables:
| Variable | Purpose |
|---|---|
SNOW_QA_URL |
HTTPS base URL of the ServiceNow resource instance. |
SNOW_QA_DELEGATED_CLIENT_ID |
Client ID of the delegated ServiceNow OAuth application. |
SNOW_QA_DELEGATED_CLIENT_SECRET |
Client secret of the delegated ServiceNow OAuth application. |
SNOW_QA_DYNAMIC_ME_FILTER_ID |
Sys ID that represent a Dynamic 'Me' Filter. |
MCP_TOKEN_KMS_KEY |
Full Cloud KMS key resource name used to encrypt delegated tokens. |
MCP_TOKEN_SIGNING_SECRET |
Base64-encoded MCP signing secret that decodes to at least 32 bytes. |
Optional environment variables:
| Variable | Default | Purpose |
|---|---|---|
MCP_PUBLIC_URL |
http://localhost:8080 |
Public origin used for OAuth and MCP endpoint metadata. |
SNOW_QA_DELEGATED_SCOPE |
unset | Scope sent to the delegated ServiceNow authorization endpoint. |
PORT |
8080 |
HTTP listener port. |
The process also needs Google Application Default Credentials with access to the configured KMS key and Firestore database. OAuth clients are stored in oauth_clients; each active registration must allow only the tool scopes it needs.
Local development
Node.js 20 or later is required. After setting the environment and Google credentials:
npm ci
npm run dev
To run the compiled server:
npm run build
npm start
Validation
The automated tests use mocks and do not require live ServiceNow or GCP credentials:
npm run gcp-build
This command runs the TypeScript typecheck, all 79 automated tests, and the production build. For deployment changes, follow the GCP migration checklist.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。