Skip to content

Chat approvals

Slack interactions

POST/slack/interactions

Approve and Deny buttons, verified by Slack’s signature before anything is read.

#Authentication

Issuer signature

No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.

Slack's v0 signature (x-slack-signature and x-slack-request-timestamp), five minute window, each signature accepted once.