Brazil, Australia Patch 6
Standalone Application
A foundational data model providing the table, fields, and access control rules needed to integrate ServiceNow with OpenID Connect (OIDC) identity providers, enabling trusted authentication and identity verification.
- Provider-neutral OIDC framework for capturing and storing key identity provider data, including identity provider issuer, identity provider ID, and assurance level from ID.me, myID, GOV.UK One Login, and other OIDC providers.
- Provenance-based access control — identity provider data is read-only once populated, encrypted, and accessible only to identity admins, caseworkers, and the integration service account.
Initial Release:
This includes
1.Data model
2.ACLs
3.Roles
4.Column Level Encryption
Not applicable for this application version.
System Requirements
- Platform version: Requires ServiceNow platform version 29.6.0 or later within the 29.x family, or any 30.x release (per engines.snc: "^29.6.0 || ^30.0.0" in
package.json).
- Required plugin — Multi-Provider SSO: com.snc.integration.sso.multi.installer must be active on the target instance. This app's OIDC identity-provider integration
is built on top of MPSSO.
- Required plugin — Platform/Field Encryption: the identity_provider_id field on sn_idp_integration_identity is stored using column-level encryption
(sys_platform_encryption_configuration, sys_kmf_crypto_module, etc.), which depends on com.glide.now.platform.encryption being active and licensed. (This has been
a real deployment blocker in practice — Field Encryption Enterprise activation can be license-restricted on some instances.)
- Roles: the app ships its own roles — sn_idp_integration.identity_admin, sn_idp_integration.agent, sn_idp_integration.integration — governing
read/write/create/delete/report-view access to the identity table; no external role dependency beyond standard admin for installation.
- Outbound network access: since this integrates with external OIDC identity providers (ID.me, myID, One Login, etc. per the in-flight OIDC accelerator epic), the
instance needs outbound HTTPS access to the configured provider endpoints (MID Server or direct, depending on instance network posture).