ServiceNow server-side guide

ServiceNow RPA Password Generator

Create a Password Reset extension script for RPA-assisted credential resets using ServiceNow's secure random API and an explicit password policy.

Complete ServiceNow password generator extension

This server-side script returns a 20-character password containing lowercase and uppercase letters, numbers, and symbols. It avoids ambiguous characters and shuffles the required groups with GlideSecureRandomUtil.

SecureRpaPasswordGenerator
var SecureRpaPasswordGenerator = Class.create();

SecureRpaPasswordGenerator.prototype = {
    category: 'password_reset.extension.password_generator',

    process: function (params) {
        return this.generatePassword(20);
    },

    generatePassword: function (length) {
        var lowercase = 'abcdefghijkmnopqrstuvwxyz';
        var uppercase = 'ABCDEFGHJKLMNPQRSTUVWXYZ';
        var numbers = '23456789';
        var symbols = '!@#$%&*+-=?';
        var alphabet = lowercase + uppercase + numbers + symbols;

        if (length < 4 || length > 128) {
            throw new Error('Password length must be from 4 to 128.');
        }

        var characters = [
            this.pick(lowercase),
            this.pick(uppercase),
            this.pick(numbers),
            this.pick(symbols)
        ];

        while (characters.length < length) {
            characters.push(this.pick(alphabet));
        }

        for (var index = characters.length - 1; index > 0; index--) {
            var swapIndex = GlideSecureRandomUtil.getSecureRandomIntBound(index + 1);
            var temporary = characters[index];
            characters[index] = characters[swapIndex];
            characters[swapIndex] = temporary;
        }

        return characters.join('');
    },

    pick: function (characters) {
        var index = GlideSecureRandomUtil.getSecureRandomIntBound(characters.length);
        return characters.charAt(index);
    },

    type: 'SecureRpaPasswordGenerator'
};

Download the same script. An automated test keeps the visible and downloadable versions identical and exercises the policy with a mock of ServiceNow's bounded random API.

What “password generator RPA” means here

Current search results lead to ServiceNow's Password Reset extension workflow. ServiceNow documents RPA as an option for resetting credentials in stores that do not expose a reset API. The password is generated inside the Password Reset process, then the configured flow or RPA robot applies it to the target application.

This guide does not generate a Windows password for an unattended robot account. ServiceNow RPA Hub stores those separately as robot credentials or retrieves them from an external credential vault.

Create the Password Reset extension script

  1. In ServiceNow, navigate to Password Reset → Extensions → New extension script.
  2. Name the extension SecureRpaPasswordGenerator, paste the script, and keep it active.
  3. Preserve the category value password_reset.extension.password_generator. ServiceNow states that the category line is required.
  4. Associate the extension with the relevant Password Reset process and credential-store configuration in a non-production instance first.
  5. Run representative resets against a test account, including rejection, retry, delivery, and forced-change behavior.

ServiceNow documents the extension contract as process(params) returning the generated password string. The example does not need to read params, but it keeps that method signature so the platform can invoke it.

Why this script uses GlideSecureRandomUtil

GlideSecureRandomUtil.getSecureRandomIntBound(bound) returns a server-side pseudo-random integer from zero inclusive to the supplied bound exclusive. Every character selection and shuffle swap uses that bounded API.

Do not substitute Math.random(). Older examples often combine a fixed word with a few digits or use client-side random selection. Those patterns are predictable and do not reliably enforce the destination's password policy.

Match the target credential store's policy

The code's character groups are a configurable example, not a universal ServiceNow or Windows password rule. Confirm the target application's minimum length, maximum length, required groups, accepted symbols, history, and forbidden-character rules. Change the four group strings and the length in process() to match that policy.

The script deliberately removes 0, O, 1, lowercase l, and uppercase I. Add them back if the target requires the full alphanumeric range. If symbols are restricted, replace the symbol string with the exact accepted set.

Configure third-party reset delivery for RPA

For a credential store without a reset API, ServiceNow's current procedure keeps Use Flow selected, assigns a password-reset subflow, and sets the delivery mechanism according to whether the flow accepts the password as input. The RPA robot then performs the target-system interaction. Force-change-on-first-login works only when the target credential store supports it.

Use the roles and navigation documented for your ServiceNow release. The current Australia documentation lists password_reset_credential_manager, password_reset_admin, or admin for credential-store configuration.

Keep generated credentials out of logs and notifications

  • Do not call gs.info, gs.log, gs.print, or error logging with the generated password.
  • Do not place the plaintext value in work notes, email parameters, flow diagnostics, or integration logs.
  • Use ServiceNow credential records or a supported external credential vault for robot and application credentials.
  • Restrict the extension and reset configuration to the roles that need them, and audit the full reset path in a sub-production instance.
The extension returns plaintext because the reset workflow must apply the new password. Limit its lifetime and exposure. Secure randomness cannot compensate for a value copied into logs, email, or long-lived flow variables.

Test before production

The repository test executes the generator 100 times using a bounded cryptographic-random mock and verifies length, every required character group, ambiguous-character exclusions, invalid-length handling, and the absence of password logging calls. In ServiceNow, also test the actual platform invocation, credential-store policy, subflow outputs, robot failure handling, and whether the target accepts every configured symbol.

Sources and release scope

Reviewed October 6, 2026 against ServiceNow's current Australia-release documentation. Verify the same pages for the release running in your instance before deploying.