How Do You Build Custom Integrations Using the ManageEngine ServiceDesk Plus API?
Quick Summary
- Goal: Connect ServiceDesk Plus to monitoring tools, HR systems, chat platforms, or custom apps, so tickets, assets, and data flow without manual work.
- Core technology: The REST API (v3) returns JSON and uses standard HTTP methods.
- Authentication: Technician API keys work for most setups, and OAuth 2.0 applies to cloud deployments.
- Key pattern: Send data in the
input_dataparameter as JSON, and call endpoints such as/api/v3/requests. - Other options: Webhooks, custom functions with Deluge scripting, and third-party connectors reduce the code you write.
- Best habits: Use a dedicated integration account, limit its permissions, handle errors, and test in a staging instance.
- Note: Endpoints, fields, and authentication options vary by edition and build. Check the API documentation inside your own instance.
What Is ManageEngine ServiceDesk Plus and Why Integrate It?
ManageEngine ServiceDesk Plus – ITSM Software is an IT service management platform that handles requests, incidents, problems, changes, assets, and projects. Most companies run many other systems around it, so integrations save time and reduce errors. This article shows you how to build custom integrations with the ServiceDesk Plus REST API.
Which integrations bring the most value?
| Integration idea | Benefit |
|---|---|
| Monitoring alert to ticket | Creates incidents automatically when a system fails |
| HR system to user records | Keeps onboarding and offboarding accurate |
| Chat tool to requests | Lets staff raise and update tickets from chat |
| Asset feed to CMDB | Adds inventory from cloud or security tools |
| Ticket data to BI tools | Feeds dashboards and long-term reports |
Why use the API instead of manual work?
Manual copying wastes technician time and introduces mistakes. In contrast, the API lets other systems create, read, and update records in seconds. As a result, your service desk reacts faster and keeps cleaner data.
What Does the ServiceDesk Plus REST API Offer?
ManageEngine’s documentation states that the ServiceDesk Plus REST APIs let you perform the operations you run in the web client. The communication uses HTTP requests, and responses arrive in JSON format.
Which modules can you reach?
Third-party integration guides show API access to requests, request notes and tasks, assets, CMDB items, software licenses, contracts, purchase orders, vendors, users, technicians, sites, departments, and projects. Coverage varies by version, so browse the in-app API reference for the exact list.
Where do you find the official documentation?
ManageEngine’s help pages direct you to the V3 API documentation inside the application, under the admin area (Admin > General > API in on-premises builds). The cloud edition publishes its API v3 guide on ManageEngine’s website. Always follow the documentation for your edition, because cloud and on-premises calls differ in small but important ways.
Which HTTP methods do you use?
- GET retrieves records and lists.
- POST creates records.
- PUT updates records.
- DELETE removes records.
How Do You Plan a Custom Integration Before You Write Code?
Planning prevents rework and security problems. Spend time on the design first.
Which questions should you answer?
- What triggers the integration? An alert, a schedule, or a user action?
- Which direction does data flow? Into ServiceDesk Plus, out of it, or both ways?
- Which records and fields matter? List the exact fields you need.
- Who owns the integration? Name a technical owner and a business owner.
- What happens on failure? Decide how you retry and how you alert someone.
How do you choose the right approach?
| Approach | Best for | Effort |
|---|---|---|
| Direct REST calls from your code | Custom apps and scripts | Medium to high |
| Webhooks | Event-driven actions from another tool | Low to medium |
| Custom functions (Deluge) | Calls triggered by ServiceDesk Plus workflows | Low to medium |
| Prebuilt connectors | Popular tools with existing connectors | Low |
Start with the simplest option that meets your needs. Then move to custom code only when you must.
How Do You Authenticate Against the ServiceDesk Plus API?
Authentication decides who your integration acts as, so choose carefully.
What is the API key method?
ManageEngine’s cloud API guide explains that the REST API authenticates users with an API key, also called an authtoken. Every user with login permission can generate one, with or without an expiry date, and a technician with the SDAdmin role can generate keys for other users. You send the key in the request header named authtoken. If you disable the user’s login, the related key disappears.
When should you use OAuth?
Cloud deployments also support OAuth 2.0. Integration vendors describe a flow that uses a client ID, client secret, and refresh token, and they recommend OAuth for cloud instances and technician keys for on-premises instances. OAuth offers better control over token lifetimes and scopes.
What extra detail applies to on-premises servers?
Integration guides mention a portal ID value for on-premises API v3 calls, especially when you run multiple portals. ManageEngine’s Deluge documentation also shows the technician key and portal ID inside the parameters. Check your build’s documentation to confirm the required fields.
How should you protect credentials?
- Create a dedicated integration technician account.
- Give the account only the roles it needs.
- Store keys in a secrets manager, not in source code.
- Set expiry dates where possible, and rotate keys regularly.
How Do You Create Your First API Call?
A simple test proves that your connection, authentication, and permissions all work.
How do you send a request to create a ticket?
ManageEngine’s v3 API sends mutation data in a parameter named input_data that contains JSON. The following example illustrates the pattern for an on-premises server. Replace the placeholders with your values.
bash
curl -X POST "https://sdp.example.com/api/v3/requests" \
-H "authtoken: YOUR_API_KEY" \
--data-urlencode 'input_data={"request":{"subject":"Printer offline","description":"Floor 2 printer stopped responding","requester":{"email_id":"user@example.com"},"priority":{"name":"High"}}}'
How do you read the response?
The API returns JSON that includes a response status and the created record with its ID. Check the status field first, and log the record ID. Then open the ticket in ServiceDesk Plus to confirm that the fields match.
What if the call fails?
| Symptom | Likely cause | Fix |
|---|---|---|
| Authentication error | Wrong or expired key | Regenerate the key, and check the header name |
| Permission error | Integration account lacks roles | Add the required role |
| Validation error | Field name or value invalid | Compare your payload with the API reference |
| Connection error | Firewall, DNS, or certificate | Test the URL and certificate from the calling server |
How Do You Read, Update, and Search Records With the API?
Most integrations do more than create tickets. They also update status, add notes, and search.
How do you list and filter records?
ManageEngine’s v3 API accepts a list_info object inside input_data for list calls. You can set row counts, start index, sort fields, and search criteria. Integration vendors use this approach to page through requests. Keep page sizes moderate, so you avoid slow calls and timeouts.
How do you update a ticket?
Use a PUT call to the request’s endpoint with an input_data payload that contains only the fields you change. For example, add a resolution, change the priority, or assign a technician. Furthermore, use the notes and conversation endpoints when you want to add comments instead of editing fields.
Which best practices improve reliability?
- Page through results instead of pulling everything at once.
- Send only changed fields in updates.
- Use unique identifiers from the source system, so you can match records later.
- Store the ServiceDesk Plus ID in the source system for two-way sync.
- Respect rate and load limits by spacing calls and batching work.
How Do Webhooks and Custom Functions Reduce Coding?
You do not always need a full application. ServiceDesk Plus offers built-in ways to trigger integrations.
How do webhooks work in practice?
Many external tools can send an HTTP POST to a URL when an event happens. Vendor guides show tools that create ServiceDesk Plus requests by posting to the /api/v3/requests endpoint with an authorization header that carries the API key. This approach suits alerting tools and access management systems.
What are custom functions?
ManageEngine‘s Deluge scripting lets you write custom functions that call APIs from within ServiceDesk Plus workflows. According to the documentation, you can call ServiceDesk Plus’s own API or call external applications. API calls run through the technician account whose key you configure in the function. Therefore, use a dedicated account with limited rights.
Which option fits which need?
| Need | Suggested option |
|---|---|
| External tool creates tickets | Webhook or direct API call |
| Ticket event triggers an action elsewhere | Custom function with Deluge |
| Scheduled data sync | Script or integration platform |
| Complex logic with error handling | Custom application |
How Do You Secure and Test Your Integration?
Integrations touch sensitive data, so treat them like production applications.
Which security controls matter most?
- Use HTTPS for every call.
- Limit permissions to the minimum roles.
- Restrict network access to known IP ranges where you can.
- Log every call without storing secrets in logs.
- Rotate keys on a schedule and when staff leave.
- Validate incoming data before you send it on.
How should you test?
Build and test in a staging instance or a test portal, not in production. Prepare test cases for success, validation errors, authentication failures, and timeouts. Additionally, test with realistic volumes, because a script that works for ten tickets may struggle with ten thousand.
What should monitoring include?
Track failed calls, response times, and queue sizes. Send alerts to a shared channel when errors repeat. Then review the integration quarterly, and remove unused connections.
How Do You Maintain and Evolve Integrations Over Time?
Integrations decay when nobody owns them. Plan for change from day one.
What causes integrations to break?
- Upgrades that change fields or endpoints
- Expired keys or tokens
- Changes in the connected tool’s API
- New mandatory fields in request templates
- Password or role changes on the integration account
How do you keep them healthy?
Document each integration with its purpose, owner, endpoints, and credentials location. Subscribe to ManageEngine release notes, and test your integrations after each upgrade. Meanwhile, keep a rollback plan, so you can disable an integration quickly if it misbehaves.
Conclusions: What Should You Remember About Building ServiceDesk Plus Integrations?
Good integrations begin with clear goals, a simple design, and careful security. ManageEngine ServiceDesk Plus – ITSM Software gives you a REST API v3 with JSON responses, API key and OAuth authentication, webhooks, and Deluge custom functions, so you can choose the approach that fits each job.
To recap, define the trigger, data flow, and owner first. Create a dedicated integration account, authenticate with a key or OAuth, and send well-formed input_data payloads. Test in a staging instance, log every call, and monitor failures. Finally, maintain the integration after every upgrade. With these habits, your service desk connects smoothly to the rest of your technology stack.
Frequently Asked Questions
Use the method your edition supports. Technician API keys work widely, especially for on-premises servers, while cloud deployments also support OAuth 2.0 with a client ID, secret, and refresh token. In both cases, use a dedicated integration account with minimal permissions, and store credentials securely.
Often yes. Many tools send webhooks that create requests through the API, and ServiceDesk Plus offers Deluge custom functions for calls triggered by workflows. Prebuilt connectors also exist for popular platforms. Use custom code only when those options do not cover your logic.
Validation errors usually mean that a field name, value, or required item does not match your instance’s configuration. Compare your payload with the API reference in your own build, and check mandatory fields in the request template. Then retry with a minimal payload and add fields step by step.

