ServiceNow
A ServiceNow instance that answers the Table, CMDB Instance, Aggregate, Service Catalog, Knowledge and Attachment APIs pysnc and pysnow call, plus an MCP server.
Vendor reference: https://developer.servicenow.com/dev.do#!/reference/api/latest/rest/ ↗. Machine-readable: compat/servicenow.json.
Surfaces
| Kind | Path | Notes |
|---|---|---|
| REST | /api/now/table | Table API, also under /api/now/v1/table and /api/now/v2/table |
| REST | /api/now/cmdb | CMDB Instance API, read-only; Aggregate API under /api/now/stats |
| REST | /api/sn_sc/servicecatalog | Service Catalog API |
| REST | /api/sn_km_api/knowledge | Knowledge API |
| REST | /api/now/attachment | Attachment API |
| OAuth | /oauth_token.do | password, refresh_token and client_credentials grants |
| MCP | /mcp | table tools and the servicenow-mcp tool set |
API versions: Table API (unversioned, v1, v2), CMDB Instance API (unversioned, v1)
Supported
- Encoded queries in
sysparm_query(^,^OR,^NQ,LIKE,STARTSWITH,IN,ISEMPTY,BETWEEN,ORDERBY, dot-walks andjavascript:gs.*date helpers) sysparm_fields,sysparm_limit,sysparm_offset,sysparm_display_valueandsysparm_exclude_reference_link, withX-Total-Countand aLinkheader on lists- ServiceNow's
{"result": ...}responses and{"error": {"message", "detail"}, "status": "failure"}errors - Basic and bearer auth, and OAuth token exchange at
/oauth_token.do pysncandpysnowagainst a live server- Aggregate API counts, averages, sums, min and max with
sysparm_group_byandsysparm_having - Users, groups, CMDB, incidents, problems, changes, SLAs, Service Catalog requests, approvals and knowledge articles
Not supported
- Tables outside the documented table list
- CMDB Instance API writes; that API is read-only
Known differences and test guidance
| Scenario | Difference from ServiceNow | In your tests |
|---|---|---|
| Unknown query conditions | Conditions on unknown fields are ignored, as ServiceNow does, so the query returns rows instead of an error. | Do not expect a 400 for a misspelled field in sysparm_query. |
| Writes on a self-run instance | Client writes, through REST and MCP, are refused unless the host enables them. | Enable writes on the instance you run before testing create, update or delete. |
| Attachment size | An uploaded file is kept up to 1 MiB. | Do not test large attachments against the replica. |
| Record ids | sys_ids are deterministic 32-hex values, stable across runs. | Read ids from the API; do not hard-code ids from a real instance. |
| Featured and most-viewed articles | Knowledge articles are ranked by ticket links and sys_view_count. | Do not assert on a specific ranking order. |
Fault injection
| Key | What the client sees |
|---|---|
throttle | 429 {"error": "rate_limited", "message": "Too Many Requests"} with Retry-After |
fail_next | The next N calls fail as throttle does, then clear |
quota_limit | 429 {"error": "quota_exceeded"} once the per-window quota is spent |
error_rate | 500 for the given fraction of calls |
latency_ms | Fixed added latency on every data-plane request |
Applies to every system
- The hosted data plane is read-only: a write is refused with
403 writes_disabled. A SOQL, GraphQL or searchPOSTis a read and is answered. - Faults are injected through
POST /_admin/faultson a simulator you run yourself;POST /_admin/faults/resetclears them. - Rate limits do not happen on their own unless a page says so. Use fault injection to exercise a client's backoff.
- Distributions come from aggregated metadata sketches of data Eon backs up; no customer records; all Era data is simulated.