Complete ServiceNow password generator extension
This server-side script returns a 20-character password containing lowercase and uppercase letters, numbers, and symbols. It avoids ambiguous characters and shuffles the required groups with GlideSecureRandomUtil.
var SecureRpaPasswordGenerator = Class.create();
SecureRpaPasswordGenerator.prototype = {
category: 'password_reset.extension.password_generator',
process: function (params) {
return this.generatePassword(20);
},
generatePassword: function (length) {
var lowercase = 'abcdefghijkmnopqrstuvwxyz';
var uppercase = 'ABCDEFGHJKLMNPQRSTUVWXYZ';
var numbers = '23456789';
var symbols = '!@#$%&*+-=?';
var alphabet = lowercase + uppercase + numbers + symbols;
if (length < 4 || length > 128) {
throw new Error('Password length must be from 4 to 128.');
}
var characters = [
this.pick(lowercase),
this.pick(uppercase),
this.pick(numbers),
this.pick(symbols)
];
while (characters.length < length) {
characters.push(this.pick(alphabet));
}
for (var index = characters.length - 1; index > 0; index--) {
var swapIndex = GlideSecureRandomUtil.getSecureRandomIntBound(index + 1);
var temporary = characters[index];
characters[index] = characters[swapIndex];
characters[swapIndex] = temporary;
}
return characters.join('');
},
pick: function (characters) {
var index = GlideSecureRandomUtil.getSecureRandomIntBound(characters.length);
return characters.charAt(index);
},
type: 'SecureRpaPasswordGenerator'
};
Download the same script. An automated test keeps the visible and downloadable versions identical and exercises the policy with a mock of ServiceNow's bounded random API.
What “password generator RPA” means here
Current search results lead to ServiceNow's Password Reset extension workflow. ServiceNow documents RPA as an option for resetting credentials in stores that do not expose a reset API. The password is generated inside the Password Reset process, then the configured flow or RPA robot applies it to the target application.
This guide does not generate a Windows password for an unattended robot account. ServiceNow RPA Hub stores those separately as robot credentials or retrieves them from an external credential vault.
Create the Password Reset extension script
- In ServiceNow, navigate to Password Reset → Extensions → New extension script.
- Name the extension SecureRpaPasswordGenerator, paste the script, and keep it active.
- Preserve the category value
password_reset.extension.password_generator. ServiceNow states that the category line is required. - Associate the extension with the relevant Password Reset process and credential-store configuration in a non-production instance first.
- Run representative resets against a test account, including rejection, retry, delivery, and forced-change behavior.
ServiceNow documents the extension contract as process(params) returning the generated password string. The example does not need to read params, but it keeps that method signature so the platform can invoke it.
Why this script uses GlideSecureRandomUtil
GlideSecureRandomUtil.getSecureRandomIntBound(bound) returns a server-side pseudo-random integer from zero inclusive to the supplied bound exclusive. Every character selection and shuffle swap uses that bounded API.
Do not substitute Math.random(). Older examples often combine a fixed word with a few digits or use client-side random selection. Those patterns are predictable and do not reliably enforce the destination's password policy.
Match the target credential store's policy
The code's character groups are a configurable example, not a universal ServiceNow or Windows password rule. Confirm the target application's minimum length, maximum length, required groups, accepted symbols, history, and forbidden-character rules. Change the four group strings and the length in process() to match that policy.
The script deliberately removes 0, O, 1, lowercase l, and uppercase I. Add them back if the target requires the full alphanumeric range. If symbols are restricted, replace the symbol string with the exact accepted set.
Configure third-party reset delivery for RPA
For a credential store without a reset API, ServiceNow's current procedure keeps Use Flow selected, assigns a password-reset subflow, and sets the delivery mechanism according to whether the flow accepts the password as input. The RPA robot then performs the target-system interaction. Force-change-on-first-login works only when the target credential store supports it.
Use the roles and navigation documented for your ServiceNow release. The current Australia documentation lists password_reset_credential_manager, password_reset_admin, or admin for credential-store configuration.
Keep generated credentials out of logs and notifications
- Do not call
gs.info,gs.log,gs.print, or error logging with the generated password. - Do not place the plaintext value in work notes, email parameters, flow diagnostics, or integration logs.
- Use ServiceNow credential records or a supported external credential vault for robot and application credentials.
- Restrict the extension and reset configuration to the roles that need them, and audit the full reset path in a sub-production instance.
Test before production
The repository test executes the generator 100 times using a bounded cryptographic-random mock and verifies length, every required character group, ambiguous-character exclusions, invalid-length handling, and the absence of password logging calls. In ServiceNow, also test the actual platform invocation, credential-store policy, subflow outputs, robot failure handling, and whether the target accepts every configured symbol.
Sources and release scope
Reviewed October 6, 2026 against ServiceNow's current Australia-release documentation. Verify the same pages for the release running in your instance before deploying.