Required Information
Gather the following from the previous step:https://acme.service-now.com. Must use HTTPS, no trailing slash, no path. FedRAMP / Government Community Cloud customers can also use *.servicenowservices.com instances.Configuring the Integration
Open ServiceNow in the Neo dashboard

The Integrations directory in the Neo Agent dashboard
Sign in to ServiceNow as the service account, then enter your credentials
- Instance URL, e.g.
https://acme.service-now.com - Client ID
- Client Secret

The ServiceNow connect form in the Neo dashboard
Approve in ServiceNow

The OAuth consent screen on your ServiceNow instance
Verify the connection
What Neo provisions behind the scenes
What Neo provisions behind the scenes
- Validates the OAuth refresh token by fetching an access token
- Provisions a Business Rule on the parent
tasktable (named “Neo Agent — Task Webhook”), which fires on every task-family subclass via table inheritance - Creates a System Property (
x_neoagent.callback_url) holding the per-tenant callback URL the Business Rule POSTs to - Sets the integration’s sync state to READY_TO_SYNC
Troubleshooting Connection Issues
If you encounter issues during the connect flow, check the following:Instance URL Rejected
Instance URL Rejected
instance_url must be a service-now.com or servicenowservices.com domain.- Make sure the URL starts with
https://(nothttp://) - The hostname must end with
.service-now.comor.servicenowservices.com(FedRAMP/GovCloud customers) - Do not include a path.
https://acme.service-now.comis correct,https://acme.service-now.com/nowis not - Vanity URLs are not supported here. Use the canonical platform admin URL even if your end users access ServiceNow via a custom hostname
OAuth Callback Failed: invalid_client
OAuth Callback Failed: invalid_client
- Verify the Client ID matches the OAuth Application Registry entry exactly. Copy-paste, do not retype
- Check the Client Secret was copied correctly without extra spaces or newline characters
- Confirm the OAuth application is set to Active in ServiceNow
- If you regenerated the Client Secret in ServiceNow, update it in Neo via the Reconnect button
Popup Closes With No Consent Screen
Popup Closes With No Consent Screen
- The Redirect URL on your OAuth Application Registry entry probably does not match. Verify it is exactly
https://dashboard.neoagent.io/oauth/servicenow/callback - Extra trailing slashes, query parameters, or
http://(instead ofhttps://) cause this. The match must be byte-for-byte
Insufficient Privileges After OAuth Completes
Insufficient Privileges After OAuth Completes
- The user that approved consent does not have the
itilrole, so Neo can authenticate but cannot read tickets - In ServiceNow, open the user record and assign the
itilrole (or your equivalent role with Table API read/write on thetaskfamily) - Click Reconnect in the Neo dashboard to retry
403 When Neo Sends an Email via PSA
403 When Neo Sends an Email via PSA
- Neo’s “Email (sent via PSA)” notification mode calls
/api/now/v1/email, which requires theemail_api_sendrole on the integration user (separate fromitil) - In ServiceNow, open the user record and assign the
email_api_sendrole - No reconnect needed. The next workflow run picks it up, and Neo raises an inbox alert with this exact remediation when it sees the 403
Connected But Webhooks Are Not Arriving
Connected But Webhooks Are Not Arriving
- Check System Definition → Business Rules in ServiceNow for a rule named “Neo Agent — Task Webhook” on the
tasktable. It should exist and be Active - Verify System Definition → System Properties contains
x_neoagent.callback_urlpointing at ahttps://...neoagent.io/callback/servicenow?...URL - If either is missing, click Reconnect in the Neo dashboard. The webhook provisioning step is idempotent, so re-running it is safe and fixes most provisioning failures (including removing the legacy incident-only rule on instances connected before mid-May 2026)
- See Webhook Architecture for the full provisioning flow
Network Connectivity
Network Connectivity
- Confirm your ServiceNow instance is reachable from the public internet over HTTPS
- If you have IP allowlisting enabled in ServiceNow, whitelist Neo Agent’s IP address
- The OAuth round-trip happens in the user’s browser, but the ongoing API calls and webhook deliveries flow between Neo’s backend and your ServiceNow instance directly
What’s Next?
Once connected, every task-family record on your instance (incidents, requests, request items, tasks, change requests, and problems) flows through Neo’s event pipeline. From here you can:- Build workflows: create automated workflows that triage, route, comment, and resolve ServiceNow tickets. Use the Ticket Type filter in the rules-builder to scope a workflow to specific subclasses
- Configure permissions: fine-tune which areas Neo can read versus write in the Neo dashboard’s permission groups
