snow-mcp-server

snow-mcp-server

Secure MCP runtime on Google Cloud Run enabling ServiceNow AI Agents to access another ServiceNow instance as the signed-in user via delegated OAuth, with read-only tools for work items and pending approvals.

Category
访问服务器

README

Secure Delegated ServiceNow MCP Runtime

A secure MCP runtime on Google Cloud Run that enables a ServiceNow AI Agent to access another ServiceNow instance as the signed-in user—using delegated OAuth, least-privilege scopes, Dynamic Me filtering, Cloud KMS encryption, and rotating refresh tokens.

Status: Completed · End-to-end validated with ServiceNow Agent Studio<br> Stack: TypeScript · Node.js · MCP · ServiceNow · Cloud Run · Firestore · Cloud KMS<br> Validation: 79 automated tests passing

Architecture

flowchart LR
    A["ServiceNow AI Agent<br/>MCP Client"]
    B["Secure MCP Runtime<br/>Google Cloud Run"]
    C["ServiceNow Resource Instance<br/>Delegated User Context"]
    D[("Firestore<br/>Sessions & Token Hashes")]
    E["Cloud KMS<br/>Encrypted Delegated Tokens"]

    A -->|"OAuth + PKCE<br/>MCP tools"| B
    B -->|"Delegated user bearer<br/>Allowlisted API queries"| C
    B --> D
    B --> E

The MCP bearer authenticates the client to this runtime and is never sent to ServiceNow. A separate delegated bearer represents the signed-in user to the ServiceNow resource instance, where Dynamic Me and ACLs enforce user-level access.

What this project demonstrates

  • Delegated identity across two ServiceNow instances.
  • An enterprise MCP client/server integration with ServiceNow Agent Studio.
  • Separation between the MCP client bearer and the downstream user bearer.
  • Least-privilege tool scopes and server-owned query construction.
  • Secure token storage, rotation, replay detection, and session revocation.
  • Cloud-native deployment and automated validation on Google Cloud.

Demo

The MCP server was authenticated from ServiceNow Agent Studio and exposed to a ServiceNow AI Agent through two read-only tools. The end-to-end flow was validated in the deployed environment:

ServiceNow Agent Studio
→ MCP server on Google Cloud Run
→ delegated end-user OAuth
→ ServiceNow resource instance
→ user-scoped tool results

The AI Agent successfully invokes both tools, and ServiceNow scopes the returned records to the signed-in user.

Implemented tools

get_work_items

  • Accepts status: open (default) or all.
  • Accepts limit: integer from 1 to 100 (default 20).
  • Reads incidents where caller_id or opened_by is the signed-in user.
  • Reads requested items where requested_for or opened_by is the signed-in user.
  • Adds source_table, relationship_to_user, and, for work opened for another person, the display name in other_person.
  • Requires mcp.work_items.read.

get_pending_approvals

  • Accepts limit: integer from 1 to 100 (default 20).
  • Returns only approvals whose state is requested and whose approver is the signed-in user.
  • Requires mcp.approvals.read.

Tool inputs cannot select an ownership mode, table, field, encoded query, approver, user identifier, or Dynamic Me filter ID. Responses contain only allowlisted ServiceNow fields and server-derived relationship metadata. See the architecture for the fixed query plans and trust boundaries.

Security highlights

  • Authorization Code with canonical PKCE S256.
  • Exact OAuth client, redirect URI, scope, and resource binding.
  • Delegated ServiceNow execution as the signed-in user.
  • Cloud KMS encryption with session- and purpose-bound contexts.
  • Opaque MCP refresh tokens stored only as SHA-256 hashes.
  • Atomic refresh-token rotation with replay-family session revocation.
  • Fixed tables, fields, limits, sorts, and Dynamic Me query plans.
  • No arbitrary encoded queries or user identifiers from the AI Agent.
  • HTTPS-only ServiceNow token exchange with redirects disabled.
  • No access tokens, refresh tokens, authorization codes, record content, or query results in logs.

OAuth flow

The MCP-facing flow supports Authorization Code with PKCE S256 and rotating refresh tokens for public clients:

  1. The client calls /oauth/authorize with the canonical MCP resource and an explicit request for one or both supported tool scopes.
  2. The runtime validates the OAuth client, exact redirect URI, resource, scopes, and canonical PKCE challenge, then redirects the browser to ServiceNow.
  3. The callback exchanges the ServiceNow code and stores both delegated tokens encrypted in the MCP session.
  4. The client exchanges the returned MCP authorization code, the same resource, and the PKCE verifier at /oauth/token for an MCP bearer lasting up to 15 minutes and a rotating refresh token.
  5. Each tool call validates the MCP bearer, session, and required tool scope before using the delegated ServiceNow bearer for a fixed query.
  6. The client renews access with grant_type=refresh_token, the same client_id, and the same resource. Each successful use rotates the MCP refresh token; the delegated ServiceNow token is refreshed only when needed.

Plaintext delegated tokens and plaintext MCP refresh tokens are never stored. Refresh-token reuse revokes the session. MCP refresh tokens expire after 30 days of inactivity, and each token family has a maximum lifetime of 90 days. Users authorize again only after expiry, revocation, or an invalid downstream refresh grant.

Configuration

Required environment variables:

Variable Purpose
SNOW_QA_URL HTTPS base URL of the ServiceNow resource instance.
SNOW_QA_DELEGATED_CLIENT_ID Client ID of the delegated ServiceNow OAuth application.
SNOW_QA_DELEGATED_CLIENT_SECRET Client secret of the delegated ServiceNow OAuth application.
SNOW_QA_DYNAMIC_ME_FILTER_ID Sys ID that represent a Dynamic 'Me' Filter.
MCP_TOKEN_KMS_KEY Full Cloud KMS key resource name used to encrypt delegated tokens.
MCP_TOKEN_SIGNING_SECRET Base64-encoded MCP signing secret that decodes to at least 32 bytes.

Optional environment variables:

Variable Default Purpose
MCP_PUBLIC_URL http://localhost:8080 Public origin used for OAuth and MCP endpoint metadata.
SNOW_QA_DELEGATED_SCOPE unset Scope sent to the delegated ServiceNow authorization endpoint.
PORT 8080 HTTP listener port.

The process also needs Google Application Default Credentials with access to the configured KMS key and Firestore database. OAuth clients are stored in oauth_clients; each active registration must allow only the tool scopes it needs.

Local development

Node.js 20 or later is required. After setting the environment and Google credentials:

npm ci
npm run dev

To run the compiled server:

npm run build
npm start

Validation

The automated tests use mocks and do not require live ServiceNow or GCP credentials:

npm run gcp-build

This command runs the TypeScript typecheck, all 79 automated tests, and the production build. For deployment changes, follow the GCP migration checklist.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选