For Agents
Programmatically create authenticated session, refresh session token. Covers 6 operations.
Install Jentic One Beta
Jentic One is a self-hosted execution layer for AI agents. It lets your agent call the Supergood ServiceNow GRC API, or any other public or private API you need. You set the rules, the agent never sees your credentials, and every call is logged.
Two steps, two machines. Install the instance in a safe environment, then register your agent from wherever it runs.
Step 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsupergood.ai%2Fsupergood" | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL "https://jentic.com/install.sh?src=apis&api=%2Fapis%2Fsupergood.ai%2Fsupergood" | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.
What an agent can do with Supergood ServiceNow GRC API.
Create authenticated session
Refresh session token
List risks
Update finding status
GET STARTED
Use for: I need to authenticated session, I want to refresh session token, Search for risks, Find all a control
Not supported: Does not handle payments, communications, or crm - use for developer tools only.
API for connecting with ServiceNow GRC to manage risks, controls, assessments, and audit findings. The API exposes 6 endpoints.
Monitor Supergood ServiceNow GRC API operational status and events
Patterns agents use Supergood ServiceNow GRC API for, with concrete tasks.
★ Developer Tools Operations
Use the Supergood ServiceNow GRC API to perform developer tools operations programmatically. The API provides 6 endpoints covering core functionality including create authenticated session, refresh session token, list risks.
Call POST /sessions to create authenticated session
Automated Assessments Management
Automate assessments operations by combining multiple Supergood ServiceNow GRC API endpoints. Agents can refresh session token and then list risks in a single workflow.
Call POST /sessions/refresh to refresh session token, then verify the result
AI Agent Integration via Jentic
AI agents discover and call Supergood ServiceNow GRC API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle none tokens manually.
Search Jentic for 'create authenticated session', load the operation schema, and execute with Jentic-managed credentials
6 endpoints — api for connecting with servicenow grc to manage risks, controls, assessments, and audit findings.
METHOD
PATH
DESCRIPTION
/sessions
Create authenticated session
/sessions/refresh
Refresh session token
/risks
List risks
/controls
Create a control
/assessments
Create an assessment
/audits/{engagementId}/findings/{findingId}
Update finding status
/sessions
Create authenticated session
/sessions/refresh
Refresh session token
/risks
List risks
/controls
Create a control
/assessments
Create an assessment
/audits/{engagementId}/findings/{findingId}
What agents get from Jentic-routed access to this vendor.
Setup
Wiring the Supergood ServiceNow GRC API by hand means creating a session, refreshing its token, and managing retries yourself against api.supergood.ai. Through Jentic you install once, import the Supergood ServiceNow GRC API from the API Directory, store the session credentials once, and your agent calls it.
Permission scoping
The audit operation puts the engagement and finding ids in the URL path (/audits/{engagementId}/findings/{findingId}), so a rule can pin your agent to one engagement: it can update findings for that engagement and nothing else. You choose the operations it may call, so ones like creating controls or assessments are not included unless you add them.
Credential isolation
Your Supergood ServiceNow GRC API session credentials are stored once, encrypted, by your own Jentic One instance and injected at execution time. They never enter the agent's prompt, logs, or context.
Intent-based discovery
Agents search Jentic by intent such as 'create an authenticated session' or 'list risks', and Jentic returns the matching Supergood ServiceNow GRC API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.
Alternatives and complements available in the Jentic catalogue.
Github
Alternative developer tools API
Choose Github when you need a different approach to developer tools operations
Specific to using Supergood ServiceNow GRC API through Jentic.
What authentication does the Supergood ServiceNow GRC API use?
The Supergood ServiceNow GRC API uses no authentication. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.
Can I create authenticated session with the Supergood ServiceNow GRC API?
Yes. Use the POST /sessions endpoint. The API returns structured JSON responses that agents can parse and act on directly.
What are the rate limits for the Supergood ServiceNow GRC API?
Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.
How do I create authenticated session through Jentic?
Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create authenticated session'. Jentic returns the matching Supergood ServiceNow GRC API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.
How many endpoints does the Supergood ServiceNow GRC API have?
The Supergood ServiceNow GRC API exposes 6 endpoints covering assessments, audits, authentication operations.
Update finding status