An MCP server that enables running commands against a ServiceNow instance via its REST APIs, including Table, Aggregate, Attachment, Import Set, Batch, CMDB, Service Catalog, Change Management, and Knowledge APIs.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.JIRA_API_TOKENJIRA_EMAILJIRA_SITELOG_LEVELSN_ACTIVE_PROFILE— no default Which profile tools use. Switch at runtime with servicenow_use_instance (persisted to the env file).SN_CODESEARCHSN_DOCS_DIR— no docs/instance Directory the docs package reads/writes Markdown in. Relative paths resolve against the working directory.SN_ENV_FILE— Credentials in an env file (project, ~/.config, or ), updatableSN_HTTP_HOST— no 127.0.0.1 DF-6: bind address for the http transport (loopback by default).SN_HTTP_TOKEN— no — DF-6: when set, http requests must send Authorization: Bearer <token>.SN_INCLUDE_REF_LINKS— no false Reference fields come back without their link URLs by default (token savings). Set true to include them.SN_INSTANCE— dev12345.service-now.comSN_LOG_LEVEL— no info Log verbosity on stderr: error, warn, info, debug.SN_MAX_RETRIES— no 2 Retries for transient failures (429/5xx, network errors). Non-idempotent writes are only retried on connect errors.SN_PACKAGES_DENY— Packages SN_TOOL_PACKAGES / / SN_PACKAGES_READONLY SN_PACKAGES_DENY=change also blocks the Change Management plugin API.SN_PACKAGES_READONLY— no — Comma/space-separated packages whose write tools are not registered; their read tools stay. Per-package complement to the global SN_READONLY.SN_PORT— no 3000 DF-6: TCP port for the http transport.SN_REDACT_FIELDS— no — DF-5: mask these field values before records reach the model (comma/space-separated).SN_REDACT_PII— no false DF-5: also mask email/phone/national-id patterns inside string values.SN_RESULT_PRETTY— no false Tool results are compact JSON by default (pretty-printing ~doubles tokens). Set true for indented output.SN_SCHEMA_CACHE_TTL_SEC— no 300 TTL for the near-static schema reads cache (list_tables, describe_table, get_cmdb_meta). 0 disables caching.SN_TLS_CA— no — Optional CA bundle (PEM) to trust (or SN_TLS_CA_FILE). SN_TLS_REJECT_UNAUTHORIZED=false disables verification (not recommended).SN_TLS_CA_FILE— SN_TLS_CA no — Optional CA bundle (PEM) to trust (or ). SN_TLS_REJECT_UNAUTHORIZED=false disables verification (not recommended).SN_TLS_CLIENT_CERT— Mutual TLS (client cert) none (or layered) / _KEY Cert maps to a user; needs optional undici.SN_TLS_CLIENT_CERT_FILESN_TLS_CLIENT_KEY— no — Private key (PEM) for the client certificate (or SN_TLS_CLIENT_KEY_FILE).SN_TLS_CLIENT_KEY_FILE— SN_TLS_CLIENT_KEY no — Private key (PEM) for the client certificate (or ).SN_TLS_REJECT_UNAUTHORIZED— SN_TLS_CA no — Optional CA bundle (PEM) to trust (or SN_TLS_CA_FILE). =false disables verification (not recommended).SN_TOOL_PACKAGES— Tool packages: load only the tool groups you need viaSN_TRANSPORT— no stdio DF-6: stdio (default) or http (Streamable HTTP for remote/agent clients).SN_WRITE_MODE— apply: true (or set =apply to restore the v1 "execute immediately"XDG_CONFIG_HOME[](https://m8ven.ai/mcp/ivanbbaev-servicenow-mcp-ai-xgihxq)