---
sourceDocument: Australia Asset Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/it-asset-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Asset Management

ft:clusterId :

    - itam

bundleId :

    - itam

workflow :

    - Technology


---

# Integrate with Workday using OAuth 2.0

# Integrate with Workday using OAuth 2.0 {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

Integrate your Software Asset Management application with the Workday application using OAuth 2.0 authentication method to track your software subscriptions.

## Configure permissions in Workday {#ariaid-title2}

To set up the Workday integration successfully, configure permissions in Workday for the OAuth 2.0 authentication method.

### Before you begin

Role required: Users having roles such as Security Admin, Integration Admin, Integration Auditor, who can create Integration System Users and assign required security policies.

### Procedure

1. Register an Integration System User.  
   Note:  
   While filling out account information details, the Do Not Allow UI Sessions check box should be kept cleared to allow login and authentication.
2. Create a security group and assign it to the Integration System User.
   1. In Action, navigate to Security GroupMaintain Domain Permissions for Security Group and provide the following permission:  
      {#req-config-workday-oauth__table_ow2_4wy_pxb__entry__3}

      | Operation | Domain Security Policy | Functional Areas |
      |-|-|-|
      | Get Only | Worker Data: Current Staffing Information | Staffing |
      | View Only | Person Data: Work Address | Contact Information |
      | View Only | Worker Data: Active and Terminated Workers | Staffing |
      | View Only | Workday Accounts | System |
      | View and Modify | WQL for Workday Extend | System |
      | View and Modify | Workday Query Language | System |
      [Table 1. Domain security policy permissions]

      {#req-config-workday-oauth__table_ow2_4wy_pxb}  
      Note:  
      Confirm that the domain security policies are activated for the security group using the active pending security policy changes.
   {#req-config-workday-oauth__substeps_fcw_3wy_pxb}

### Result

The new credentials for this Integration System User would be used to configure the connection in the ServiceNow instance.

## Create Workday OAuth 2.0 credentials {#ariaid-title3}

Create Workday OAuth 2.0 credentials to get access to Workday APIs.

### Before you begin

Role required: Users having roles such as Security Admin, Integration Admin, Integration Auditor, who can create Integration System Users and assign required security policies.

### Procedure

1. Log in to your Workday account.
2. In the search bar, enter <kbd class="ph userinput">register API client</kbd> and select Register API Client.
3. On the Register API Client page, fill in the fields.  
   {#create-workday-oauth-cred__table_wdv_ygz_k3c__entry__2}

   | Field | Description |
   |-|-|
   | Client Name | A unique name for the client application. For example, <kbd class="ph userinput">Workday HR spoke</kbd>. |
   | Client Grant Type | Select Authorization Code Grant. |
   | Access Token Type | The type of access token. Select Bearer. |
   | Redirection URI | URL of your ServiceNow instance. |
   | Non-Expiring Refresh tokens | The option to enable refresh tokens which do not expire. |
   | Scope (Functional Areas) | Scopes required for the client application. |
   | Include Workday Owned Scope | The option to select scopes that are owned by Workday. |
   [Table 2. Register API Client fields]

   {#create-workday-oauth-cred__table_wdv_ygz_k3c}
4. Select OK.  
   The client ID and client secret are generated on the Register API Client page.
5. Copy the values in the Client ID and Client Secret fields and secure them for later use for Workday integration.

## Create a Workday integration profile {#ariaid-title4}

Create a Workday integration profile to track software subscriptions and optimize licensing for your Workday applications.

### Before you begin

Role required: admin, sam_admin, sam_integrator

Install the latest Workday HR spoke. For more information about the latest version, see the Spoke version section in [Workday HR Spoke](https://www.servicenow.com/docs/access?context=workday-hr-spoke&version=australia&pubname=australia-integrate-applications&ft:locale=en-US).  
Important:  
You must select the Software Asset Management integration with Workday check box for this integration while installing optional features on the [Application Manager](https://www.servicenow.com/docs/access?context=application-manager&version=australia&pubname=australia-platform-administration&ft:locale=en-US) page. For more information about choosing the required SaaS applications, see [Request SaaS License Management](https://servicenow-prod.fluidtopics.net/ltQ10fYPUIpL7abgEH0~7A "Request the Software Asset Management - SaaS License Management plugin (sn_sam_saas_int) so that you can create and manage integrations with your SaaS and Single Sign-on (SSO) applications. You can use these integrations to track license usage and to reclaim unused licenses.").

### About this task

If you're using Software Asset Workspace, the option to create the Workday integration profile in Core UI is inactive.

### Procedure

1. Navigate to the integration profile.

   | Interface | Action |
   | Core UI | 1. Navigate to AllSoftware AssetSaaS LicenseDirect Integration Profiles. 2. Select New. 3. Select Workday Integration Profile. {#create-workday-integration-oauth__ol_ijd_bjk_qtb} |
   | Software Asset Workspace | 1. Navigate to License operationsUser SubscriptionsDirect integration profiles. 2. Select New. 3. Select Workday from the drop-down list. 4. Select Continue. {#create-workday-integration-oauth__ol_wjd_bjk_qtb} |
   |-|-|

   {#create-workday-integration-oauth__choicetable_o3p_z3k_qtb}
2. On the form, fill in the fields.  
   {#create-workday-integration-oauth__table_qnq_djt_ysb__entry__2}

   | Field | Description |
   |-|-|
   | Integration Profile ||
   | Display name | Name of the integration profile. For example, <kbd class="ph userinput">Workday integration</kbd>. |
   | Authentication type | Type of authentication to access Workday APIs. * Basic Auth * OAuth 2.0 {#create-workday-integration-oauth__ul_akh_fjy_k3c} |
   | Status | Status of the integration profile. * If you haven't published the integration profile, this field is automatically set to  Draft. * If you've already published the integration profile, this field is automatically set to  Published. {#create-workday-integration-oauth__ul_b41_23b_2rb} |
   | Profile type | Type of integration profile. This field is automatically set to Workday Subscription. |
   [Table 3. Integration Profile form]

   {#create-workday-integration-oauth__table_qnq_djt_ysb} {#create-workday-integration-oauth__step3}
{#create-workday-integration-oauth__step3}
3. In the Download Subscription Subflow section, verify that the Subflow field is set to Workday Download Subscriptions.  
   Note:  
   The Download subscriptions check box is selected by default and you can't clear it.
4. Select Save.  
   A draft integration profile gets created.

   The Connection \& credential field appears and is automatically set to sn_workday_hr_spke.WorkdayHR.
5. Open the connection \& credential aliases record by selecting the preview icon (![Preview icon.]()) next to the Connection \& Credential field and then selecting Open Record in the record preview.
6. On the Connection \& Credential Aliases form, select the Create New Connection \& Credential related link.
7. In the dialog box, fill in the fields.  
   {#create-workday-integration-oauth__table_ztl_xzp_zyb__entry__2}

   | Field | Description |
   |-|-|
   | Connection Information ||
   | Name | Name of the connection. For example, <kbd class="ph userinput">Workday HR Connection</kbd>. |
   | Connection URL | URL for the connection, <kbd class="ph userinput">https://&lt;workday_host&gt;</kbd>. For example,<kbd class="ph userinput">https://wd2-impl-services1.workday.com</kbd>. |
   | Tenant name | Name of the Workday tenant. |
   | API Version | Version of the Workday API to use for requests. |
   | Credential Information ||
   | Client ID | Client ID that you generated while creating a Workday OAuth credential. For more information, see [Create Workday OAuth 2.0 credentials](https://servicenow-prod.fluidtopics.net/mf~jOMxF1td1lYZQkaRqjg#create-workday-oauth-cred "Create Workday OAuth 2.0 credentials to get access to Workday APIs."). |
   | Client Secret | Client Secret that you retrieved while creating a Workday OAuth credential. |
   | Authorization URL | URL used to authorize the OAuth connection. For example, <kbd class="ph userinput">https://&lt;<var class="keyword varname">auth-domain-name</var>&gt;.workday.com/&lt;<var class="keyword varname">tenant</var>&gt;/authorize</kbd> |
   | Token URL | URL used to generate the OAuth token. For example, <kbd class="ph userinput">https://&lt;<var class="keyword varname">domain-name</var>&gt;.workday.com/ccx/oauth2/&lt;<var class="keyword varname">tenant</var>&gt;/token</kbd> |
   | OAuth Redirect URL | https://\<instance_name\>/oauth_redirect.do, where the instance name is the name of your ServiceNow instance. |
   [Table 4. Create Connection and Credential dialog box]

   {#create-workday-integration-oauth__table_ztl_xzp_zyb}
8. Select Create and Get OAuth Token.  
   You're redirected to the Workday login page.
9. Log in to the Workday portal using the Integration System User credentials that you registered while configuring permissions in Workday.  
   For more information, see [Configure permissions in Workday](https://servicenow-prod.fluidtopics.net/mf~jOMxF1td1lYZQkaRqjg#req-config-workday-oauth "To set up the Workday integration successfully, configure permissions in Workday for the OAuth 2.0 authentication method.").
10. In the Authorize Workday dialog box, select Allow to allow user permissions for Workday.  
    The OAuth token is generated and you're redirected to your ServiceNow instance.
11. Under the FSE worker calculation tab, activate the worker categories covered by your contract by setting the value of Active to true and entering the FSE percentage.
12. **Optional:** If worker categories are listed in your contract but not available in the FSE worker calculation tab, add a new worker category.
    1. In the FSE worker calculation tab, select New.
    2. On the form, fill in the fields.  
       {#create-workday-integration-oauth__table_kmd_4kg_btb__entry__2}

       | Field | Description |
       |-|-|
       | Worker Category | The worker category listed in your contract. |
       | FSE Percentage | The FSE percentage for the worker category that you added. Full Service Equivalent (FSE) is the method by which the subscriptions are calculated. |
       | Integration profile | The Workday integration profile that you created. |
       | Active | Option to make the worker category active. |
       [Table 5. Workday FSE worker calculation]

       {#create-workday-integration-oauth__table_kmd_4kg_btb}
    3. Select Submit.
    {#create-workday-integration-oauth__substeps_kj2_fb5_ysb}
13. Define the mapping of the newly created worker category.
    1. Select the Worker category tab and select New.
    2. On the form, fill in the fields:  
       {#create-workday-integration-oauth__table_os2_plj_ctb__entry__2}

       | Field | Description |
       |-|-|
       | Worker Type | The type of worker, either Employee or Contingent. |
       | Employee/Contingent worker type | The type of Employee or Contingent worker. |
       | Time Type | Indicates whether the worker is full-time or part-time. |
       | Worker Category | The worker category that you created. |
       | Integration profile | The Workday integration profile that you created. |
       | Active | Option to make the mapping active. |
       [Table 6. Workday worker category]

       {#create-workday-integration-oauth__table_os2_plj_ctb}
    3. Select Submit.
    {#create-workday-integration-oauth__substeps_vpf_llj_ctb}
14. Activate the list of modules that are defined in your contract.
    1. Select the Modules tab.
    2. Open the module record.
    3. Set the Active field to True.
    4. Select Save.
    {#create-workday-integration-oauth__substeps_xgx_nhl_mtb}
15. Verify that there is at least one active record in all the tabs for your contract: FSE worker calculation, Worker category, and Modules, before publishing the connection.
16. On the integration profile form, select Validate Connection to verify the connection and credential details of this integration.
17. After the connection is verified, select Publish.
18. In the Publish Confirmation dialog box, select OK.

### What to do next

After the integration connects, your ServiceNow instance automatically creates software models, reclamation rules, and software subscriptions that are refreshed daily.  
After creating an integration profile, view information about the profile in the Software Asset Workspace by navigating to License operationsUser subscriptionDirect integration profiles. You can select an integration profile to view the following related lists. If all of the following related lists aren't visible for an integration profile in the default view, you can select the custom integration view from the Details tab:

* Software Models
* Unrecognized Subscription Identifiers
* Scheduled Jobs
* Scheduled Job Results
* Software Subscriptions
* Subscription Identifier Exclusion Rule
* Subscription User Exclusion Rule
{#create-workday-integration-oauth__ul_gxp_qfk_rfc}

After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see [Subscription exclusions for SaaS and SSO applications](https://servicenow-prod.fluidtopics.net/kwS~TWLEZdf67e7UjappHg#subscription-exclusions "Define subscription exclusions for your SaaS and SSO applications to optimize your licensing costs by keeping the excluded subscriptions out of license cost calculations.").

If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see [Create a child alias to set up multiple integration profiles](https://servicenow-prod.fluidtopics.net/o5L0ctEzWkFYzYxMhh78ew "Create a child alias to set up multiple integration profiles with unique connections and manage different configurations for each integration profile.").

Review all automatically generated reclamation rules to reclaim user subscriptions. For more information, see [Review a software reclamation rule](https://servicenow-prod.fluidtopics.net/QjHAOC5kmvypyG1Pph5iIQ "Use reclamation rules to cancel user subscriptions that have limited to no activity.").  
Create software entitlements for the automatically generated software models to track used software against owned software.

* For more information on creating software entitlements in the Software Asset Management Core UI, see [Create entitlements in Software Asset Management Core UI](https://servicenow-prod.fluidtopics.net/8ZR9KWQ1FY73pUmBw_wZRQ "Create entitlements in the Software Asset Management Core UI application to record your license details and allocate purchased software rights to users or devices.").
* For more information on creating software entitlements in the Software Asset Workspace, see [Create entitlements in workspace](https://servicenow-prod.fluidtopics.net/ZvL7kERffOGQ6dpBU_744w "Create entitlements in the Software Asset Workspace to enter your license details and allocate purchased software rights to users or devices.").
* For more information on creating software entitlements using the Software Asset Management Playbook, see [Create entitlements using the guided walk-through](https://servicenow-prod.fluidtopics.net/rw30KUYxwGuwCDdFtc0mOg "Use the guided walk-through playbook for a step-by-step process of creating entitlements.").
{#create-workday-integration-oauth__ul_cbz_vhr_sqb}  
Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the [License Workbench](https://servicenow-prod.fluidtopics.net/K_GziLbR~smXeeWp0kcdNw "Review reconciliation results in a simplified workbench view.") (Software Asset Management classic application) or the [License usage view](https://servicenow-prod.fluidtopics.net/Ct5YAvsPFESpnVaeLwu5_w "Use the license usage view as a single plane to understand the license position of all software products, remediate non-compliance, view reconciliation results, view, or add removal candidates, and view Software Asset Management related reports.") (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance.

* For more information on running reconciliation in the Software Asset Management classic application, see [Run software reconciliation in Software Asset Management classic](https://servicenow-prod.fluidtopics.net/Pic766RsbcGCoP1GsB_9RA "Reconciliation is run as a scheduled job (default is weekly), but you can also run reconciliation manually to reconcile software products in your environment on demand.").
* For more information on running reconciliation in the Software Asset Workspace, see [Run software reconciliation in the workspace](https://servicenow-prod.fluidtopics.net/SUHzxdFqMeO8rQemacW3sA "Reconciliation is run as a scheduled job (default is weekly), but you can also run reconciliation manually to reconcile software products in the Software Asset Workspace environment on-demand.").
{#create-workday-integration-oauth__ul_qgf_zhr_sqb}

*[\>]: and then


