servicenow-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SERVICENOW_INSTANCE | Yes | The ServiceNow instance name only (e.g. 'dev12345' for 'dev12345.service-now.com') | |
| SERVICENOW_PASSWORD | Yes | Password for basic auth credentials for a user with access to the incident table | |
| SERVICENOW_USERNAME | Yes | Username for basic auth credentials for a user with access to the incident table |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| create_incidentA | Create a new ServiceNow incident. Args: short_description: Brief summary of the incident (required). description: Full description of the issue. urgency: "1" (High), "2" (Medium), or "3" (Low). impact: "1" (High), "2" (Medium), or "3" (Low). category: Incident category, e.g. "software", "hardware", "network". assignment_group: Name or sys_id of the assignment group. caller_id: Name or sys_id of the user reporting the incident. |
| get_incidentA | Fetch a ServiceNow incident by its number (e.g. INC0010023) or sys_id. |
| update_incidentA | Update fields on an existing incident. Args: number_or_sys_id: Incident number (e.g. INC0010023) or sys_id. fields: Field name -> new value, e.g. {"state": "2", "priority": "1"}. |
| search_incidentsA | Search incidents using a ServiceNow encoded query. Args: query: ServiceNow encoded query string (sysparm_query), e.g. "active=true^priority=1" or "assigned_to.nameLIKEJohn". Leave empty to list the most recent incidents. limit: Max number of records to return (default 10). offset: Number of records to skip, for pagination. |
| add_commentA | Add a customer-visible comment or an internal work note to an incident. Args: number_or_sys_id: Incident number or sys_id. comment: Text to add. work_note: If True, adds as an internal work note instead of a customer-visible comment. |
| resolve_incidentB | Resolve an incident by setting its state to Resolved. Args: number_or_sys_id: Incident number or sys_id. close_notes: Notes describing the resolution. close_code: Resolution code, e.g. "Solved (Permanently)", "Solved (Workaround)". |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| list_my_open_incidents | Prompt template: list open incidents reported by a given caller. Args: caller: The name, username, or sys_id of the person to look up as "me" (the incident's caller_id). The server authenticates as a service account, so it doesn't know who "me" is without this. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Each tool has a clear, distinct purpose covering the full incident lifecycle: get, create, update, search, add comment, and resolve. There is no overlap or ambiguity between them.
Tools follow a verb_noun pattern (e.g., get_incident, create_incident). The only minor deviation is 'add_comment' which is still verb_noun but lacks the 'incident' suffix, though it is clearly contextual.
Six tools is an ideal size for an incident management MCP server. Each tool serves a necessary operation without being too many or too few, keeping the surface focused and manageable.
Core incident operations are covered: create, read, update, search, comment, and resolve. Missing an explicit delete tool, but ServiceNow incidents are typically not deleted; update can handle assignment. Minor gap but still robust.