> ## Documentation Index
> Fetch the complete documentation index at: https://docs.app.strix.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a ServiceNow instance

> Connects a ServiceNow instance with an OAuth client (Client Credentials grant, recommended) or with the username and password of a dedicated integration user. Strix verifies the credentials against the instance before it stores them encrypted. The OAuth Application User or the integration user needs the itil role so it can read and write the selected record table and read assignment groups. Only organization admins can connect integrations (parity with the dashboard).



## OpenAPI

````yaml /openapi.json post /integrations/servicenow/connect
openapi: 3.1.0
info:
  title: Strix API
  version: 1.0.0
  description: >-
    Public REST API for the Strix autonomous penetration testing platform.
    Manage scans, vulnerabilities, assets, schedules, API tokens, and webhooks.
servers:
  - url: /api/v1
    description: Strix v1 API
security:
  - BearerAuth: []
tags:
  - name: Scans
    description: Launch, monitor, and manage security scans.
  - name: Vulnerabilities
    description: View and triage discovered vulnerabilities.
  - name: Assets
    description: Domains and repositories registered for scanning.
  - name: Schedules
    description: Recurring scan schedules (Pro plan).
  - name: Tokens
    description: Manage API tokens for authentication.
  - name: Webhooks
    description: Configure webhook subscriptions for real-time event notifications.
  - name: Organization
    description: Workspace configuration for the authenticated organization.
  - name: Members
    description: Manage organization members and roles.
  - name: Invitations
    description: List and revoke organization invitations.
  - name: PR Reviews
    description: Automated security review of pull requests.
  - name: Connectors
    description: Network connectors for scanning internal/private targets.
  - name: Knowledge
    description: >-
      Organization knowledge base: documents, policies, and repo profiles that
      steer the agent.
  - name: Uploads
    description: Upload source/code/documentation archives for whitebox scans.
  - name: Integrations
    description: Third-party integrations (GitLab, Bitbucket, ticketing).
  - name: Chat
    description: Conversational agent sessions.
  - name: Analytics
    description: Aggregate dashboard analytics.
  - name: Test Users
    description: >-
      Per-domain test accounts (with optional MFA) the agent authenticates as
      during scans.
  - name: License
    description: Self-hosted license state, entitlements, and aggregate usage.
  - name: Supply Chain
    description: >-
      SBOM inventory, supply-chain findings, scans, and policy for connected
      repositories.
  - name: CLI
    description: >-
      Device authorization endpoints that let the Strix CLI and coding agents
      sign in and receive an API token.
  - name: Billing
    description: Credit balance, agent-payable top-ups, and automatic top-up settings.
  - name: Workspaces
    description: List, create, and switch workspaces.
paths:
  /integrations/servicenow/connect:
    post:
      tags:
        - Integrations
      summary: Connect a ServiceNow instance
      description: >-
        Connects a ServiceNow instance with an OAuth client (Client Credentials
        grant, recommended) or with the username and password of a dedicated
        integration user. Strix verifies the credentials against the instance
        before it stores them encrypted. The OAuth Application User or the
        integration user needs the itil role so it can read and write the
        selected record table and read assignment groups. Only organization
        admins can connect integrations (parity with the dashboard).
      operationId: connectServicenow
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConnectServiceNowRequest'
      responses:
        '200':
          description: Connected.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectServiceNowResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '422':
          $ref: '#/components/responses/ValidationError'
        '500':
          $ref: '#/components/responses/InternalError'
        '502':
          $ref: '#/components/responses/BadGateway'
      security:
        - BearerAuth:
            - integrations:write
components:
  schemas:
    ConnectServiceNowRequest:
      type: object
      description: >-
        Connect a ServiceNow instance. Send client_id and client_secret for
        auth_method oauth_client_credentials, or username and password for
        auth_method basic. When auth_method is omitted, Strix uses basic if
        username is present and client_id is not, otherwise
        oauth_client_credentials.
      required:
        - instance_url
      properties:
        instance_url:
          type: string
          format: uri
          description: >-
            URL or hostname of the ServiceNow instance, for example
            https://acme.service-now.com or acme.service-now.com. Strix uses
            HTTPS. Other schemes are rejected.
        auth_method:
          type: string
          enum:
            - oauth_client_credentials
            - basic
          default: oauth_client_credentials
          description: >-
            How Strix authenticates to the instance. oauth_client_credentials
            uses an OAuth API endpoint from the Application Registry with the
            Client Credentials grant and an OAuth Application User. basic uses
            the username and password of a dedicated integration user.
        client_id:
          type: string
          description: >-
            Client ID of the OAuth API endpoint. Required for auth_method
            oauth_client_credentials.
        client_secret:
          type: string
          format: password
          description: >-
            Client secret of the OAuth API endpoint. Required for auth_method
            oauth_client_credentials. Strix stores it encrypted and never
            returns it.
        username:
          type: string
          description: >-
            User name of the ServiceNow integration user. Required for
            auth_method basic.
        password:
          type: string
          format: password
          description: >-
            Password of the ServiceNow integration user. Required for
            auth_method basic. Strix stores it encrypted and never returns it.
        record_type:
          type: string
          enum:
            - incident
            - task
          default: incident
          description: >-
            ServiceNow table that Strix writes vulnerability records to.
            Defaults to incident, which the itil role can create on a standard
            instance. The task table needs a create ACL that requires the itil
            role. A ServiceNow admin must add that ACL before Strix can create
            Task records. You can change the record type later in the ServiceNow
            integration settings or by connecting again. A change of record type
            clears the existing ticket links.
    ConnectServiceNowResponse:
      type: object
      required:
        - success
        - provider
        - instance_url
        - auth_method
        - record_type
      properties:
        success:
          type: boolean
        provider:
          type: string
          enum:
            - servicenow
        instance_url:
          type: string
          description: Normalized instance URL that Strix stored.
        auth_method:
          type: string
          enum:
            - oauth_client_credentials
            - basic
          description: Authentication method that Strix stored.
        record_type:
          type: string
          enum:
            - incident
            - task
          description: ServiceNow table that Strix writes vulnerability records to.
    ErrorResponse:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable explanation of the error.
        code:
          type: string
          description: >-
            Stable machine-readable error code. `insufficient_scope` means the
            token does not hold the scope that this endpoint requires.
        required_scope:
          $ref: '#/components/schemas/ApiV1Scope'
          description: >-
            Scope that the caller must add to the token. Returned with the
            `insufficient_scope` code.
        docs:
          type: string
          format: uri
          description: Documentation page that explains how to resolve the error.
        hint:
          type: string
          description: >-
            One instruction that resolves the error. For `insufficient_scope`, a
            CLI session gets the `strix cloud session scopes set full` or `strix
            cloud login --scope-profile full` command, and an API token gets the
            settings page where the user creates a token with the scope. When
            the owner's role cannot hold the scope, the hint asks for a role
            change instead.
      required:
        - detail
    ApiV1Scope:
      type: string
      enum:
        - scans:read
        - scans:write
        - vulnerabilities:read
        - vulnerabilities:write
        - dependencies:read
        - schedules:read
        - schedules:write
        - assets:read
        - assets:write
        - organizations:read
        - organizations:write
        - members:read
        - members:write
        - invitations:read
        - invitations:write
        - webhooks:read
        - webhooks:write
        - tokens:write
        - audit:read
        - pr_reviews:read
        - pr_reviews:write
        - connectors:read
        - connectors:write
        - knowledge:read
        - knowledge:write
        - uploads:write
        - integrations:read
        - integrations:write
        - chat:read
        - chat:write
        - scans:message
        - analytics:read
        - llm:read
        - llm:write
        - test_users:read
        - test_users:write
        - license:read
        - supply_chain:read
        - supply_chain:write
        - billing:read
        - billing:write
  responses:
    BadRequest:
      description: Bad request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid API token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Forbidden:
      description: >-
        Insufficient permissions or missing scope. A missing scope returns the
        `insufficient_scope` code, the `required_scope` field, and a `hint` with
        the command or page that grants the scope, so a client can request the
        correct scope and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    ValidationError:
      description: Request failed validation (e.g. malformed value or unsupported enum).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    InternalError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    BadGateway:
      description: Bad gateway.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token obtained from the Tokens endpoint or CLI device login. Include
        as `Authorization: Bearer <token>`. Requests made with a managed CLI
        session also include `X-Strix-Workspace: <organization_id>` to pin a
        process to the workspace it started in; recovery endpoints report the
        current workspace after a concurrent switch.

````