# Slack slash command

Source: https://immiscible.fly.dev/docs/api/post-slack-commands

`POST /slack/commands`

`/immiscible status`, `/immiscible approvals` and `/immiscible freeze <agent> <reason>`.

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. Slack's v0 signature (`x-slack-signature` and `x-slack-request-timestamp`), five minute window, each signature accepted once.

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/slack/commands" \
  -H "x-slack-signature: $SIGNATURE"
```

Node:

```ts
// signature: computed over the raw body, see the authentication note above
const res = await fetch('https://immiscible.fly.dev/slack/commands', {
  method: 'POST',
  headers: {
    'x-slack-signature': signature,
  },
});
console.log(res.status, await res.text());
```

Python:

```python
import requests

# signature: computed over the raw body, see the authentication note above
res = requests.post(
    "https://immiscible.fly.dev/slack/commands",
    headers={
        "x-slack-signature": signature,
    },
)
print(res.status_code, res.text)
```
