best-practices-mcp
This server lets you search ServiceNow's public best-practices library at mynow.servicenow.com without any authentication, exposing two tools:
servicenow_search — Search across Knowledge articles, Best Practices, Developer Portal docs, Now Community posts, and other indexed content using natural-language or keyword queries.
Filter by content type: Narrow results using the
contentTypeparameter (e.g.,kb_knowledge,sn_communities_post).Auto-detect content type from query: Natural-language cues (e.g., "stream connect best practices") are automatically detected and routed to the appropriate filter, with the cue phrase removed from the actual search text.
Paginate results: Use
offsetandlimit(1–50) to navigate large result sets;hasMoreindicates additional pages.Graceful fallback: If a content type filter yields no results despite matches existing, the server falls back to unfiltered results and signals this via
contentTypeFilterDegraded/notefields.Discover content types organically: Responses include
table,contentTypeLabel, and acontentTypeFilterslist with live counts.
servicenow_list_content_types — Retrieve valid content-type identifiers paired with human-readable labels to use as contentType filter values without guessing.
Results are cached for up to 6 hours; use the
refreshflag to force a fresh sweep and bypass the cache.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@best-practices-mcpsearch for IT incident management best practices"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
best-practices-mcp
MCP server exposing a servicenow_search tool that searches mynow.servicenow.com —
ServiceNow's public best-practices library/landing page — across content types (Best
Practices, Product Documentation, Developer Portal docs, Now Community posts, and more).
No authentication required
mynow.servicenow.com is a public site — there's no login, token, or API key needed. It's
not a traditional SSO-protected ServiceNow instance; it's a public-facing Now Experience app
running in "Genius Search" / guest-session mode.
There's also no public, documented REST API for its search — it's reverse-engineered from a
Playwright network capture of the site's own search UI (see scripts/probe.ts and
src/servicenow/search.ts for the confirmed request/response shape). The flow:
GETany page on the site → returns a guest session cookie plus a CSRF token embedded in the HTML aswindow.g_ck.POST /api/now/v1/batch, wrapping a GraphQL call to the site's Genius Search data broker, using that cookie + token.Parse
result[0].executionResult.output.data.GlideSearch_Query.searchfor results, facets, and total hit count.
This was confirmed with a cold, browser-free curl round-trip (no Playwright, no reused session) — genuinely unauthenticated, not just working because of a live browser session.
If search ever stops working, the site's frontend likely changed one of the fixed config
IDs in src/servicenow/search.ts (SEARCH_DEFINITION_SYS_ID, SEARCH_CONTEXT_CONFIG_ID,
SEARCH_EVAM_CONFIG_ID). Re-discover them with a fresh Playwright capture filtered to
xhr/fetch traffic (write to a file, grep it — never dump raw capture output into a
conversation) rather than guessing. Then re-run npm run probe to confirm.
Related MCP server: ServiceNow MCP Server
Development
npm install
npm run dev # run the server directly with tsx (stdio transport)
npm run build # compile to dist/
npm start # run compiled dist/index.js
npm run probe -- "some query" # verify the live search flow still worksTesting with MCP Inspector
npx @modelcontextprotocol/inspector npm run devUsing with Claude Code / Claude Desktop
claude mcp add --scope user best-practices-mcp -- node "C:/dev/best-practices-mcp/dist/index.js"No environment variables are required — SN_INSTANCE_URL defaults to
https://mynow.servicenow.com and only needs overriding if pointing at a different instance.
Pagination
The API returns a fixed 10 rows per request and pages via an opaque
paginationToken (base64 of an internal offset breadcrumb, e.g. offset:0,10). Use offset
to page through the full corpus and limit to control how many rows you get back:
offsetis a row index into the full corpus (offset=10→ second page,offset=20→ third, etc.). It's implemented by constructing a token that jumps directly to that row — the server doesn't validate the breadcrumb, so any offset is random-accessible in a single request.limit(1–50) can exceed the 10-row page size; the server is paged internally (ceil(limit / 10)requests, following the API's own returned token after the initial jump) to gather that many rows.hasMorein the response is true when more results exist beyondoffset + limit(offset + limit < totalResults).
Because the offset jump relies on the reverse-engineered token format, npm run probe exercises
offset paging end-to-end — if the encoding ever changes, re-discover it from a fresh capture (see
below) rather than guessing.
Downloading documents
Search itself needs no auth, but the actual file behind a file-backed result (presentations,
workbooks, docs) is gated behind a real ServiceNow ID / Okta SSO login — confirmed live via
Playwright (see scripts/probe-headed-login.ts).
servicenow_login(MCP tool) ornpm run login(standalone script) — both open a real, visible browser window and save the resulting session to.auth/servicenow-storage-state.json(gitignored — this is a live credential) once you complete the ServiceNow ID / Okta login by hand. The MCP tool returns immediately — a headed browser waiting minutes on human SSO/MFA input has no business blocking a tool-call response — so pollservicenow_login_statusto see when the capture finishes (or failed) and whether a session file currently exists on disk.servicenow_download_document(MCP tool) — pass aservicenow_searchresult'surl. Two mechanisms depending on content type, both starting from the same cookie-replayed<table>.do?...&XMLrecord fetch (confirmed to accept cookie replay outside the browser):Most content types (e.g. marketing decks,
u_dotcom_gsdr): no browser needed at all — the record's own fields carry the real file location directly (often a separate public CDN, no ServiceNow auth needed for that hop).Best Practices Library assets (
u_x_snc_accel_asset_file_gsdr— this project's primary target content type): the record's ownx_snc_nl_data_extr_file_contentfield carries the full extracted text of the underlying file (confirmed for both.docxand.pptxsources) — this is preferred, since it's what an agent actually wants and needs no browser at all. The response also includessourceUrl(the human-facing asset page) for anyone who wants the original formatted file — just open it in your own browser and complete your own login, no need to go through this tool. Only when that field is empty does this fall back to the real file's binary bytes, which live behind a separate API (api.servicenow.com/bpl/v1/attachment/<id>) gated by a real Okta OAuth Bearer token minted client-side at click time. A short-lived headless browser (reusing the captured session, no new login) drives the actual download click to mint that token, then a plain fetch uses it to pull the file bytes — seescripts/probe-bpl-token-capture.tsfor how this was confirmed. If the session is missing or has expired, either path returns a clear error telling you to callservicenow_loginagain — no path ever launches a browser other than the brief, automated one used to mint a Best Practices Library token.
Known limitations
contentTypefilters client-side by matching the result's owntableor content-type label — there's no separate discovery tool for valid values yet. An unfiltered search's results carry their owntable/contentTypeLabel, which is enough to learn valid filters organically;contentTypeFiltersin the response also lists all available content types with live counts for the current query.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-qualityDmaintenanceProvides AI assistants with read access to ServiceNow instances to aid in building and debugging applications. It enables users to query tables, retrieve specific records, and inspect table schemas using standard ServiceNow encoded query strings.Last updated
- Alicense-qualityDmaintenanceEnables authenticated interaction with ServiceNow via its REST API using per-user OAuth 2.0 tokens. It provides tools for managing incidents, tasks, knowledge articles, and service catalog requests while maintaining user-specific permissions.Last updated294MIT
- Alicense-qualityCmaintenanceEnables querying the Consumer Financial Protection Bureau (CFPB) complaint database to retrieve consumer complaint data without authentication.Last updated12MIT
- Alicense-qualityBmaintenanceEnables AI assistants and development tools to interact with ServiceNow instances through a standardized interface, supporting comprehensive API coverage for incident, change, CMDB, and more.Last updatedMIT
Related MCP Connectors
Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.
Search PayU docs, browse the payment integration catalog, and fetch production-ready code.
Citable retrieval across papers, books, patents, Wikipedia, and live social sources.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/wiz0floyd/best-practices-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server