ServiceNow Scripted REST APIs (2026): 12 – Web Service ACLs
Secretary of Simplification
·
Aug 12, 2026
·
video
Our API works, and it's now the only way into the Vehicle table – but by default almost any integration user in the instance can call it. In this video we create a dedicated access control of type REST Endpoint and put the whole web service behind our own integration role. *You'll learn:* - What the Scripted REST External Default access control does, and why it's too permissive for production - How to create a REST Endpoint access control and reference it in the Default ACLs field of your web service - Why an account's identity type has to be set to Machine before it can call an API, and how browser access is unaffected *Chapters:* - 0:00 Introduction - 0:53 Concept - 1:53 Demo - 3:05 Test - 3:46 Outro *GitHub:* https://github.com/jnichols-servicenow/SN2026-Vehicles-API *Links:* - ServiceNow docs – Access control rules – https://www.servicenow.com/docs/r/platform-security/access-control/access-control-rules.html - Postman – https://www.postman.com/ *Series navigation:* - Previous: 11 – Table settings - Next: 13 – Machine Identity Access - Full playlist: https://www.youtube.com/playlist?list=PLrhqGp3sUzhvp1sfgP8OZjXRxKOP\_cyBU
https://www.youtube.com/watch?v=Wf4E8oZkknI