ServiceNow Incident Sync - Payload truncation on CXone Webhook

Hi all,

Got a weird one here. The CXone webhook is sending incident updates to ServiceNow, but some of the larger text fields are getting sliced mid-sentence (400). It’s only happening on incidents with long descriptions. Took like 3 hrs to realize it isn’t a ServiceNow side limit.

The flow looks like this:

[CXone Event] → [Webhook] → [ServiceNow API /api/now/table/incident] → [Incident Updated]

The request is hitting the endpoint but the body arrives mangled. It’s like the buffer is just giving up.

{
 "error": {
 "message": "Invalid input: The request body is incomplete or malformed",
 "status": "failure"
 },
 "code": 400
}

Tried swapping the content-type and adjusting the timeout in the CXone configuration (400). Also tried reducing the payload size by stripping out non-essential fields, which actually worked for a bit (200), but then it started dropping characters again on a 15kb payload.

The logs show the outgoing request from CXone is full, but the incoming log in ServiceNow is truncated. It’s driving me nuts.

Payload truncation usually happens because the webhook is hitting a character limit on the outbound string. The fix is to move the long description into a separate JSON object or use a base64 encoding if the receiver supports it.

{
 "incident_id": "12345",
 "description": "truncated_text_here",
 "full_payload": "base64_encoded_string"
}

Check the outbound event settings in the CXone Studio script to ensure the variable isn’t being capped before the POST.

1 Like