How Do You Use APIs with ManageEngine ServiceDesk Plus? - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How Do You Use APIs with ManageEngine ServiceDesk Plus?

What Should You Know First?

Here is the short version for developers and admins.

  • ServiceDesk Plus offers a REST API. It lets other applications read and change service desk data over HTTP, and responses come back as JSON.
  • The API covers what the web console covers. ManageEngine‘s Deluge documentation says the REST APIs let you perform all operations that you run through the web client.
  • Authentication differs by edition. On-premises editions use an API key (also called a technician key or authtoken), while the cloud edition uses OAuth 2.0.
  • Requests use a simple pattern. You call a URL such as /api/v3/requests, send your credentials, and pass details in an input_data parameter.
  • Roles still apply. The API can do only what the key owner’s role allows.
  • Treat keys like passwords. Store them securely and limit who can generate them.
  • Test before you automate. Try each call in a test environment first.

The sections below walk through setup, authentication, common calls and safe practices.


What Is ManageEngine ServiceDesk Plus and Why Use Its API?

ManageEngine ServiceDesk Plus – ITSM Software is an IT service management platform. Teams use it for incidents, service requests, problems, changes, assets and a configuration management database. Out of the box, people raise tickets by email, web form or the self-service portal.

What Does the API Add?

The API turns ServiceDesk Plus into a hub that other systems can talk to. ManageEngine’s REST API documentation describes it as a bridge between ServiceDesk Plus and other applications, using HTTP requests. The on-premises help pages add that the API lets you raise requests directly, without logging in to the application, and lets you build your own web form.

Which Tasks Do Teams Automate Most?

Common integration goals include:

  • Creating tickets automatically from monitoring alerts.
  • Syncing users or assets from HR or inventory systems.
  • Pulling request data into dashboards and reports.
  • Updating ticket status from a deployment pipeline.
  • Adding worklogs or notes from external tools.

ManageEngine ServiceDesk Plus – ITSM Software handles the ticket logic, while your scripts handle the connection. Together, they cut manual entry and speed up response.


Which API Version and Edition Should You Use?

Start by checking which edition you run. The API details differ between on-premises and cloud editions, so mixing instructions causes most beginner errors.

What Are the Main Differences?

FeatureOn-premises editionCloud edition
Base URL patternhttp://servername:port/api/v3/<module>https://<domain>/api/v3/<module> or a portal-based path
AuthenticationAPI key (authtoken or technician key)OAuth 2.0 access token
Credential locationHeader or parameterAuthorization header
Access controlRole of the key ownerOAuth scopes plus role
Response formatJSONJSON

A third-party integration guide summarises the split: the cloud edition uses OAuth tokens in the Authorization header, while the on-premises edition uses a static key passed as TECHNICIAN_KEY, and the paths differ between them.

Where Do You Find the Official Documentation?

ManageEngine publishes separate API guides for on-premises and cloud editions. Its help page also notes that the version 3 API documentation sits inside the application. Use the guide that matches your edition and build number, since endpoints and fields change between releases.


How Do You Authenticate with an API Key on the On-Premises Edition?

Key-based authentication is the simplest way to start.

How Do You Generate an API Key?

ManageEngine’s documentation explains that every user with login permission can generate an authtoken, with or without an expiry date. A technician with the SDAdmin role can also generate keys for other users. Follow these steps:

  1. Sign in to ServiceDesk Plus.
  2. Open Admin > Technicians (or Users) and edit the technician.
  3. Find the API key details block.
  4. Click Generate and copy the key.
  5. Store the key in a secrets manager or a protected environment variable.

Some editions also let you generate the key from the user profile menu. Check the menu path in your version.

How Do You Send the Key?

The documentation shows two options. You can send the key in a request header named authtoken, or you can pass it as a TECHNICIAN_KEY parameter. Use the header method wherever possible. Headers stay out of URLs, so the key appears less often in server logs and browser history.

Why Should You Create a Dedicated API User?

Do not use a personal administrator account for integrations. Instead, create a dedicated technician with a narrow custom role, for example one that can add and view requests but cannot delete anything. If the key leaks, the damage stays limited. It also keeps your audit logs clear, because you can tell integration activity from human activity.


How Do You Authenticate with OAuth 2.0 on the Cloud Edition?

The cloud edition follows a standard OAuth approach.

How Does the Access Token Flow Work?

ManageEngine’s cloud API guide says you include the access token in the Authorization header of every request. The header takes the form Authorization: Zoho-oauthtoken <token>. A third-party guide describes the flow: you generate an authorization code, exchange it for an access token and a refresh token through the Zoho accounts token endpoint, and then refresh the token when it expires.

What Are Scopes?

Scopes limit what your application can do. ManageEngine’s OAuth page explains that scopes control which type of resource the client can reach. For example, one scope creates request records, and another views them. The listed scope naming follows the pattern SDPOnDemand.requests.CREATE. Request only the scopes you need.

Which Headers Does the Cloud API Expect?

The cloud documentation shows an Accept header with the value application/vnd.manageengine.sdp.v3+json alongside the Authorization header. Include both in every call, or the server may reject or misread your request.


How Do You Structure an API Request?

Once authentication works, you need to understand the request format. The v3 API follows a consistent pattern.

What Is the URL Pattern?

ManageEngine’s REST API help page gives the on-premises pattern as http://<servername>:<port>/api/v3/<module>. Replace the module with the resource you want, such as requests, assets or technicians.

What Is the input_data Parameter?

Most calls send their details in a parameter called input_data, which holds a JSON object. Two details cause frequent mistakes:

  • Encoding. ManageEngine’s cloud docs note that URI components in input_data need encoding when you pass them as a request parameter.
  • Body format. A third-party guide warns that the body should use form encoding with an input_data key that contains a JSON string, not a raw JSON body with a JSON content type.

Which HTTP Methods Do You Use?

MethodTypical purpose
GETRead a record or list records
POSTCreate a record
PUTUpdate a record
DELETERemove a record

How Do You Read and Create Requests with the API?

Requests are the core object, so start there. The examples below use the on-premises pattern. Replace the server name, port and key with your own values, and confirm the exact syntax in your edition’s guide.

How Do You List Open Requests?

ManageEngine‘s Deluge documentation shows a search example: the input_data holds a list_info object with a row count and a search_criteria that filters on status.name equal to “Open”. A curl call in that style looks like this:

bash

curl -G "http://servername:8080/api/v3/requests" \
  -H "authtoken: YOUR_API_KEY" \
  --data-urlencode 'input_data={"list_info":{"row_count":"50","search_criteria":{"field":"status.name","condition":"is","value":"Open"}}}'

The response returns a JSON list of matching requests, and you can page through results by changing the start index in list_info.

How Do You Create a Request?

The same documentation shows a minimal create call with a subject. Real tickets need more fields, so add a description, requester and priority as your workflow requires:

bash

curl -X POST "http://servername:8080/api/v3/requests" \
  -H "authtoken: YOUR_API_KEY" \
  --data-urlencode 'input_data={"request":{"subject":"Disk space alert on SRV-01","description":"Free space fell below 10 percent.","requester":{"name":"Monitoring Bot"}}}'

How Do You Call the API from Python?

python

import json, requests

BASE = "http://servername:8080/api/v3/requests"
HEADERS = {"authtoken": "YOUR_API_KEY"}

payload = {"request": {"subject": "Test ticket from Python"}}
resp = requests.post(BASE, headers=HEADERS,
                     data={"input_data": json.dumps(payload)}, timeout=30)
resp.raise_for_status()
print(resp.json())

The data argument sends form-encoded content, which matches the guidance above.

What Should You Check in the Response?

Read the response status and the status block in the JSON. A successful create returns the new request record, including its ID. Log that ID in your integration, so you can update the ticket later.


What Other Operations Does the API Support?

The API goes well beyond creating tickets.

Which Operations Exist on a Request?

ManageEngine’s help page lists operations on a specific request, including conversations, attachments, resolutions, pickup and assignment, replies and notifications. Other modules cover problems, changes, assets, users and more.

Can You Add Worklogs and Tasks?

Yes. ManageEngine’s knowledge base includes sample APIs for adding a worklog to a request and for creating a service request that includes predefined tasks. Find the relevant IDs, such as task template and service category IDs, in the admin console, then reference them in your call.

How Do Callbacks and Deluge Fit In?

The REST API help page mentions a callback URL: if you do not provide one, ServiceDesk Plus performs no extra operation after the call. For logic inside the platform, Deluge scripting lets you write custom functions that call the API or third-party services. A ManageEngine page explains that Deluge lets you make API calls from ServiceDesk Plus to other applications, using the same v3 syntax.

Which Resources Do Teams Reach for?

ResourceExample use
RequestsAuto-create tickets from monitoring
RequestersSync employees from HR
TechniciansProvision agents with roles
AssetsImport inventory data
ChangesLink deployments to change records
WorklogsLog time from external tools

How Do You Keep API Use Secure and Reliable?

An integration that works on day one can still fail or leak on day ninety. Build safety in from the start.

How Do You Protect Keys and Tokens?

Follow these practices:

  • Store keys in a secrets manager, not in source code.
  • Use HTTPS for every call, especially outside your internal network.
  • Give each integration its own technician account and role.
  • Set an expiry date on keys where your edition allows it.
  • Rotate keys on a schedule and immediately after staff changes.
  • Delete keys you no longer use.

The NIST guidance on access control in SP 800-53 supports least privilege, and that principle applies directly to API accounts.

How Do You Make Integrations Resilient?

Handle errors deliberately. Set timeouts, retry transient failures with a delay and stop on authentication errors. Keep request volumes reasonable, and page through large lists instead of pulling everything at once. Log each call’s outcome, so you can trace problems later.

How Do You Test Safely?

Use a test instance or a sandbox copy of your data. Confirm each call against the documentation, and start with read-only operations before you write or delete anything. Then roll out to production in stages.


What Common API Errors Should You Expect?

SymptomLikely causeFix
Authentication errorWrong key, expired key or missing headerRegenerate the key and recheck the header name
Permission errorThe role lacks the operationAdjust the technician’s role
Empty or invalid responseWrong content type or encodingSend input_data as encoded form data
Not foundWrong URL or module nameCompare with the documentation for your edition
Cloud token rejectedExpired access tokenUse the refresh token to obtain a new one
Validation errorRequired fields missingCheck mandatory fields in the request template

What Are the Key Takeaways?

Using APIs with ServiceDesk Plus follows a clear path. Identify your edition, create a dedicated API user, authenticate with an API key or OAuth token, and send well-formed calls to the v3 endpoints with an input_data payload. Start with simple reads, move to creating requests, and then extend into worklogs, assets and changes.

ManageEngine ServiceDesk Plus – ITSM Software gives you the endpoints, roles and documentation to connect your service desk with monitoring, HR, deployment and reporting tools. Yet a reliable integration also needs secure key handling, tight permissions, error handling and testing.

Because endpoints, headers and authentication methods vary by edition and version, confirm every detail in ManageEngine’s current API documentation before you go live. Build one small integration first, measure the time it saves and then expand.


What Questions Do Developers Ask Most About the ServiceDesk Plus API?

Do I Need a Special License to Use the API?

ManageEngine’s documentation ties API access to a user with login permission, since that user generates the key. Licensing for technicians still applies to those accounts. Check your license terms, and confirm with ManageEngine if you plan many integration accounts.

Why Does My Create Request Call Fail Even Though My Key Works?

Check the body format first. Guidance from ManageEngine and third-party guides stresses sending input_data as a form-encoded parameter that contains a JSON string. Then confirm that your role can create requests and that you included every mandatory field.

Can I Use the API from Inside ServiceDesk Plus?

Yes. ManageEngine‘s Deluge scripting lets you write custom functions that call the ServiceDesk Plus API or third-party services from within the application. Use it for automations that react to events, for example custom actions triggered by a workflow.