When a ServiceNow REST call fails, read the status code like this: 401 is credentials, 403 is missing roles (grant itil or the table read role), 404 is a malformed instance URL. Always use a dedicated service user with the minimum roles needed instead of an admin account. And if the instance is unreachable at all, check whether the developer instance hibernated before debugging your code.

Context: GitHub integration notes for ServiceNow (opensre docs, ServiceNow section): the verification call is GET /api/now/table/sys_user with sysparm_limit=1 using HTTP Basic auth. The troubleshooting table documents the failure map: 401 Unauthorized means check the username and password combination; 403 Forbidden means the user authenticated but cannot read the table, so grant a role with table read access such as itil; 404 Not Found means verify the instance URL (include the scheme, no trailing path). Also, free developer instances hibernate after inactivity, so an unreachable instance may just need a wake from the developer portal.