ServiceNow MCP Gateway Public
FreeNot checkedReference architecture exploring governance patterns for AI systems using the Model Context Protocol (MCP) when interacting with enterprise platforms, with a fo
About
Reference architecture exploring governance patterns for AI systems using the Model Context Protocol (MCP) when interacting with enterprise platforms, with a focus on policy enforcement, auditability, and control-plane design.
README
(Reference Architecture & Personal Technical Exploration)
This repository documents a personal, non-commercial technical exploration of governance patterns for AI systems using the Model Context Protocol (MCP) when interacting with enterprise platforms such as ServiceNow.
The focus of this work is architectural: how to introduce policy enforcement, auditability, and execution control between AI intent and downstream system actions.
Important This repository intentionally contains documentation and reference materials only. It does not provide a public implementation, product, or deployable solution.
What This Is
- A reference architecture for MCP-based AI integrations
- A learning exercise focused on AI governance and control-plane design
- A set of patterns and diagrams illustrating how AI intent can be safely translated into system execution
What This Is Not
- A product, platform, or SaaS offering
- An official ServiceNow integration
- A replacement for the ServiceNow SDK, APIs, or tooling
- A production-ready or supported deployment
Architectural Overview
At a high level, the exploration applies a familiar Control Plane / Data Plane mental model:
Control Plane Defines what actions are allowed, under which conditions, and with what constraints.
Data Plane Handles the execution of approved actions and emits audit-ready signals.
This separation helps make AI-initiated actions:
- explicit
- reviewable
- bounded
without embedding governance logic directly into every integration.
Conceptual Request Flow
- An AI system expresses intent using MCP
- The request is evaluated against declared capabilities and policies
- Approved actions are executed via standard ServiceNow APIs or SDK-based endpoints
- Execution context and outcomes are recorded for traceability
All system names and flows are shown as examples only.
Visual References
This repository includes architecture diagrams and walkthroughs that illustrate these patterns:
- Conceptual Request Lifecycle — from AI intent to ServiceNow execution
- Control Plane vs Data Plane Separation — governance vs execution
- Point-to-Point vs Gateway Pattern — centralized policy enforcement
All visuals are labeled as reference architecture and are provided for learning purposes.
Status
This work is ongoing and intentionally scoped as a personal technical exploration. There is no public roadmap, release plan, or commercialization intent.
🔄 MCP Gateway Flow Cycle
This document outlines the complete request-response lifecycle within the MCP Gateway architecture, detailing how user requests are processed, secured, and executed against ServiceNow.
⚡ The 8-Step Flow
The lifecycle of a single request travels through four distinct zones: User, Client, Gateway, and ServiceNow.
1. User Makes Request
Actor: User
- The user interacts with their AI assistant (Claude, Gemini, etc.) using natural language.
- Example: "Create a P1 incident for the database outage."
2. Request to MCP Client
Actor: AI Agent (MCP Client)
- The AI agent receives the natural language prompt.
- It identifies that external tools are needed to fulfill the request.
- It prepares to communicate with the configured MCP Gateway.
3. Client Requests Tools
Actor: AI Agent → Gateway
- The client connects to the Gateway (via stdio or HTTP) and requests the list of available capabilities (tools).
- Protocol:
tools/list
4. Gateway Returns Tools
Actor: Gateway → AI Agent
- The Policy Engine intercepts the request.
- It evaluates the user's identity and permissions.
- It filters the global capability catalog, returning only the tools this specific user is allowed to see.
5. Tool Invocation
Actor: AI Agent → Gateway
- The AI Agent selects the appropriate tool (e.g.,
create_incident) and extracts parameters from the user's prompt. - It sends a JSON-RPC request to the Gateway.
- Protocol:
tools/call
6. Gateway → ServiceNow
Actor: Gateway → ServiceNow API
- Pre-Execution Check: The Gateway validates the action against the active policy (checking for read-only modes, required approvals, etc.).
- The ServiceNow Connector translates the request into a specific ServiceNow API call (REST or SDK).
- It executes the authenticated request against the ServiceNow instance.
7. ServiceNow Response
Actor: ServiceNow → Gateway
- ServiceNow returns the raw result (e.g., the created incident record).
- Post-Execution: The Gateway receives the data and applies Field Filtering policies to redact sensitive information before passing it back.
8. Result to User
Actor: AI Agent → User
- The Gateway returns the sanitized JSON result to the AI Agent.
- The AI Agent interprets the structured data and generates a natural language response for the user.
- Result: "I've successfully created Incident INC12345. You can view it here..."
🔐 Security Layers Throughout
The Gateway architecture enforces security at every stage of the lifecycle, ensuring a "Defense in Depth" strategy.
| Layer | Location | Description |
|---|---|---|
| Authentication | Client ↔ Gateway | Verifies the identity of the calling AI Agent (OAuth/API Key). |
| Authentication | Gateway ↔ ServiceNow | Manages secure, scoped credentials for backend access. |
| Policy Enforcement | Capability Discovery | Hides unauthorized tools from the user entirely. |
| Policy Enforcement | Execution Request | Validates specific actions (e.g., "Can User A create P1 incidents?"). |
| Audit Logging | Decision Points | Records every ALLOW/DENY decision, input payload, and outcome for compliance. |
| Safety Mechanisms | Global Guardrails | Includes Kill Switch, Read-Only Mode, Rate Limiting, and Approval Workflows. |
Disclaimer
This repository reflects a personal learning exercise and does not represent the views of any employer, client, or vendor. ServiceNow is referenced solely as an example of a downstream enterprise system.
Installing ServiceNow MCP Gateway Public
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/aatrey882/ServiceNow-MCP-Gateway-PublicFAQ
Is ServiceNow MCP Gateway Public MCP free?
Yes, ServiceNow MCP Gateway Public MCP is free — one-click install via Unyly at no cost.
Does ServiceNow MCP Gateway Public need an API key?
No, ServiceNow MCP Gateway Public runs without API keys or environment variables.
Is ServiceNow MCP Gateway Public hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install ServiceNow MCP Gateway Public in Claude Desktop, Claude Code or Cursor?
Open ServiceNow MCP Gateway Public on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
LibreOffice Tools
Enables AI agents to read, write, and edit Office documents via LibreOffice with token-efficient design. Supports multiple formats including DOCX, XLSX, PPTX, a
by passerbyflutterdannote/figma-use
Full Figma control: create shapes, text, components, set styles, auto-layout, variables, export. 80+ tools.
by dannoteLogo.dev
Search and retrieve company logos by brand or domain. Customize size, format, and theme to match your design needs. Accelerate design, prototyping, and content
by NOVA-3951Design Inspiration Server
Searches top design platforms like Dribbble and Behance to provide UI inspiration, color palettes, and layout patterns via the Serper API. It allows users to re
by YonasValentinCompare ServiceNow MCP Gateway Public with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All design MCPs
