Service desks: ServiceNow, Zendesk and Jira
How to connect ServiceNow, Zendesk and Jira Cloud. People read with their own logins and, if an admin turns it on, make single-record changes after confirming them.
Status: in testing. All three are built against each vendor's published API and covered by automated tests against simulated systems; none has been used with a customer's live instance yet. Menu names move between releases: if a step doesn't match what you see, look for the nearest equivalent.
| System | Reads | Changes (off unless an admin turns them on) |
|---|---|---|
| ServiceNow | Any table the person can read: incidents, tasks, problems, changes, requests, knowledge, users and so on | Create or update one record in a table the admin lists, such as incident. Comments and work notes are fields (comments, work_notes). No deletes. |
| Zendesk | Tickets (with comments), users, organizations, groups | Create a ticket, or update one: status, priority, assignee, tags, custom fields, a public reply (comment) or a private note (internal_note). No deletes. |
| Jira Cloud | Issues (with comments and change history) and projects | Create an issue, update its fields, or add a comment. No deletes, and no status changes yet (Jira moves status through workflow transitions). |
Each person signs in with their own login, so ServiceNow, Zendesk and Jira only show and allow what that person could see and do there anyway. SourceLace never uses a shared admin account.
The redirect URL for all three is:
https://sourcelace.onrender.com/connect/callback
ServiceNow
ServiceNow lives at your own address (such as corvanta.service-now.com), so your ServiceNow admin registers SourceLace once in your instance, which gives a Client ID. That ID is not a secret. SourceLace registers as a public client that proves each sign-in with PKCE, so no client secret is created, sent or stored.
Register SourceLace (ServiceNow admin)
- Open All (top left), type
Application Registry, and open System OAuth → Application Registry. - Click New, then Create an OAuth API endpoint for external clients.
- Fill in:
- Name:
SourceLace. - Redirect URL: the redirect URL above.
- Public Client: tick it. This means "no client secret"; ServiceNow then requires PKCE, which SourceLace always uses. If your release has no Public Client box, this connector cannot be used on it yet; tell support the release name.
- PKCE Required: tick it if the box is there.
- Leave Access Token Lifespan (30 minutes) and Refresh Token Lifespan (100 days) as they are. People connect again when the refresh token runs out.
- Name:
- Click Submit, open the new entry again, and copy the Client ID.
Add the source (SourceLace admin)
Kind: ServiceNow (servicenow).
| Option | Type | Default | Example | What it is |
|---|---|---|---|---|
instance |
Text | (required) | corvanta |
The name before .service-now.com (the full address also works). |
client_id |
Text | (required) | 3f2a... |
The Client ID from the Application Registry. |
To allow changes, turn on Allow changes and list the tables, such as incident, change_request.
What people need in ServiceNow
- Read access to the tables they ask about (for example the
itilrole for incidents). ServiceNow's ACLs decide everything. - Listing fields uses the data dictionary (
sys_db_object,sys_dictionary,sys_choice). If someone cannot read those, SourceLace falls back to the fields of one record they can see.
Queries
query (language servicenow_query) takes one JSON object with table, query, fields, display_value and limit:
{"table": "incident", "query": "active=true^priority=1^ORDERBYDESCopened_at",
"fields": ["number", "short_description", "state", "assigned_to"], "limit": 50}
query is ServiceNow's own encoded query, the same text a list's filter gives with Copy query. SourceLace refuses tables that hold the instance's own credentials (such as oauth_credential, or anything ending in _credentials), and refuses javascript: in queries, because it would run script on the instance.
Zendesk
Zendesk also lives at your own address (such as corvanta.zendesk.com), so your Zendesk admin creates an OAuth client for SourceLace. It is a public client: no secret, PKCE on every sign-in.
Create the OAuth client (Zendesk admin)
- Open Admin Center (the four-squares menu → Admin Center).
- Go to Apps and integrations → APIs → OAuth Clients (on some accounts: Zendesk API → OAuth Clients) and click Add OAuth client.
- Fill in:
- Name:
SourceLace. Description: "Read and update tickets as the signed-in person". - Client kind: Public.
- Redirect URLs: the redirect URL above.
- Identifier: keep the suggested one or type
sourcelace. Copy it.
- Name:
- Click Save. If Zendesk shows a secret anyway, you don't need it; don't paste it anywhere.
Add the source (SourceLace admin)
Kind: Zendesk (zendesk).
| Option | Type | Default | Example | What it is |
|---|---|---|---|---|
subdomain |
Text | (required) | corvanta |
The name before .zendesk.com. |
client_id |
Text | (required) | sourcelace |
The OAuth client's Identifier. |
Sign-in asks for the scope read, plus tickets:write when an admin has made tickets writable. After turning changes on or off, people connect Zendesk again so their sign-in matches.
Queries and changes
query(languagezendesk_search) takes Zendesk's own search text, such astype:ticket status:open priority:urgent order_by:created sort:desc. Start withtype:ticket,type:userortype:organizationso every row has the same columns. One line, at most 1,000 characters. Zendesk returns at most 1,000 results per search, and new tickets can take a minute to appear in search.get_recordon a ticket can add itscomments.- With
ticketswritable, changes can setsubject,status,priority,type,assignee_id,group_id,requester_id,organization_id,tags,due_at,external_idandcustom_field_<id>, and add either a public reply (comment) or a private note (internal_note). Updates use Zendesk's "safe update", so they are refused if someone else changed the ticket since the preview.
Jira Cloud
Jira Cloud sign-in goes through Atlassian's central login, so SourceLace has one Atlassian app. After someone signs in, SourceLace asks Atlassian which Jira sites their sign-in reaches and uses the one named in the source's site option. Your Jira admin has nothing to register, unless your Atlassian organization restricts which apps people may approve.
Permissions SourceLace asks for: read:jira-work (read projects and issues), read:jira-user (read people's names) and offline_access (stay connected), plus write:jira-work (create and edit issues and comments) only on sources where an admin made issue writable.
Add the source (SourceLace admin)
Kind: Jira Cloud (jira).
| Option | Type | Default | Example | What it is |
|---|---|---|---|---|
site |
Text | (none) | corvanta.atlassian.net |
The Jira site. Optional if people only ever reach one Jira site; needed if they reach several. A bare name such as corvanta means corvanta.atlassian.net. |
To allow changes, turn on Allow changes with the object issue. After turning changes on or off, people connect Jira again.
Each person clicks Connect, signs in with their Atlassian account, and approves the site on Atlassian's consent page.
Queries and changes
query(languagejql) takes plain JQL, such asproject = CORV AND statusCategory != Done ORDER BY updated DESC, or JSON to choose the columns:{"jql": "project = CORV", "fields": ["summary", "status", "customfield_10010"]}. Jira needs at least one condition beforeORDER BY.get_recordon an issue can addcommentsandchangelog.- With
issuewritable: create an issue, update its fields, or add a comment. Descriptions and comments are sent as Jira's rich text, built from plain lines. Status changes and deletes are not offered.
When something goes wrong
| What you see | What to do |
|---|---|
| "... needs the instance option: the name before .service-now.com, such as corvanta." | Fill in instance. |
| "... needs the client_id option: the Client ID of the OAuth app registered in the instance's Application Registry" | Fill in client_id from the Application Registry. |
| "ServiceNow sign-in failed: ..." | ServiceNow's own reason follows. Check the redirect URL and that Public Client is ticked. |
| "... holds credentials and is not available through SourceLace" | That ServiceNow table is never readable through SourceLace. |
| "javascript: runs script on the instance and is not allowed in a query" | Remove javascript: from the encoded query. |
| "ServiceNow: that table or record does not exist, or you cannot see it." | Check the name; the person's ServiceNow roles may not allow it. |
| "SourceLace does not delete ServiceNow records. Change its state instead." | Deletes are not offered; update the state. |
| "... needs the subdomain option: the name before .zendesk.com, such as corvanta." | Fill in subdomain. |
| "... needs the client_id option: the Identifier of the OAuth client created in Zendesk's Admin Center" | Fill in client_id with the OAuth client's Identifier. |
| "Zendesk sign-in failed: ..." | Zendesk's own reason follows. Check the redirect URL and that the client kind is Public. |
| "SourceLace cannot set '...' on a ticket. Use ..." | Only the ticket fields listed above can be changed. |
| "Add either a comment or an internal_note in one change, not both." | Split it into two changes. |
| "Your account reaches several Jira sites (...). An admin sets the site option on ... to choose one." | Set the site option. |
| "Your Atlassian account did not give SourceLace access to .... Connect again and choose that site on Atlassian's consent page." | Connect again and pick the right site. |
| "Your Atlassian account did not give SourceLace access to any Jira site." | The person has no Jira site, or did not approve one. Connect again. |
| "the JQL needs a condition before ORDER BY, such as project = CORV" | Add a condition to the JQL. |
| "Status changes go through a workflow transition, which SourceLace does not offer yet." | Change status in Jira itself. |
| "The jira connector is not available yet." | SourceLace's Atlassian app is not set up on this server yet. Contact support. |