canonical: https://jentic.com/apis/supergood.ai/supergood

# Supergood ServiceNow GRC API

API for connecting with ServiceNow GRC to manage risks, controls, assessments, and audit findings. The API exposes 6 endpoints.

## For AI agents

Programmatically create authenticated session, refresh session token. Covers 6 operations.

## Scope

Does not handle payments, communications, or crm - use for developer tools only.

## Capabilities

- Create authenticated session
- Refresh session token
- List risks
- Update finding status
- Monitor Supergood ServiceNow GRC API operational status and events

## Use cases

### Developer Tools Operations

Use the Supergood ServiceNow GRC API to perform developer tools operations programmatically. The API provides 6 endpoints covering core functionality including create authenticated session, refresh session token, list risks.

Example prompt: Call POST /sessions to create authenticated session

### Automated Assessments Management

Automate assessments operations by combining multiple Supergood ServiceNow GRC API endpoints. Agents can refresh session token and then list risks in a single workflow.

Example prompt: Call POST `/sessions/refresh` to refresh session token, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Supergood ServiceNow GRC API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle none tokens manually.

Example prompt: Search Jentic for 'create authenticated session', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/sessions` | Create authenticated session |
| POST | `/sessions/refresh` | Refresh session token |
| GET | `/risks` | List risks |
| POST | `/controls` | Create a control |
| POST | `/assessments` | Create an assessment |
| PATCH | `/audits/{engagementId}/findings/{findingId}` | Update finding status |

## Key resources

- **Assessments** — Operations related to Assessments
- **Audits** — Operations related to Audits
- **Authentication** — Operations related to Authentication
- **Controls** — Operations related to Controls
- **Risks** — Operations related to Risks

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 65 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 62 / 100
  - Developer Experience & Jentic Compatibility: 61 / 100
  - AI-Readiness & Agent Experience: 43 / 100
  - Agent Usability: 94 / 100
  - Security: 100 / 100
  - AI Discoverability: 100 / 100
- **View full report:** https://jentic.com/apis/supergood.ai/supergood/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the Supergood ServiceNow GRC API by hand means creating a session, refreshing its token, and managing retries yourself against api.supergood.ai. Through Jentic you install once, import the Supergood ServiceNow GRC API from the API Directory, store the session credentials once, and your agent calls it.
- **Permission scoping:** The audit operation puts the engagement and finding ids in the URL path (`/audits/{engagementId}/findings/{findingId}`), so a rule can pin your agent to one engagement: it can update findings for that engagement and nothing else. You choose the operations it may call, so ones like creating controls or assessments are not included unless you add them.
- **Credential handling:** Your Supergood ServiceNow GRC API session credentials are stored once, encrypted, by your own Jentic One instance and injected at execution time. They never enter the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create an authenticated session' or 'list risks', and Jentic returns the matching Supergood ServiceNow GRC API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Github** — Alternative developer tools API
- **Gitlab** — Alternative developer tools API

## FAQ

### What authentication does the Supergood ServiceNow GRC API use?

The Supergood ServiceNow GRC API uses no authentication. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create authenticated session with the Supergood ServiceNow GRC API?

Yes. Use the POST /sessions endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Supergood ServiceNow GRC API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create authenticated session through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create authenticated session'. Jentic returns the matching Supergood ServiceNow GRC API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Supergood ServiceNow GRC API have?

The Supergood ServiceNow GRC API exposes 6 endpoints covering assessments, audits, authentication operations.

### Can I limit what my agent is allowed to do with the Supergood ServiceNow GRC API?

Yes. Jentic One runs self-hosted, so you decide which of the six operations your agent may call and which stored session credentials it may use. Because the audit endpoint carries the engagement and finding ids in its path (PATCH `/audits/{engagementId}/findings/{findingId}`), a rule can pin the agent to a single engagement and let it update only those findings. Operations such as creating controls (POST /controls) or assessments (POST /assessments) stay off limits unless you explicitly allow them.
