# Slack interactions

Source: https://immiscible.fly.dev/docs/api/post-slack-interactions

`POST /slack/interactions`

Approve and Deny buttons, verified by Slack's signature before anything is read.

## Authentication

Issuer signature. No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read. Slack's v0 signature (`x-slack-signature` and `x-slack-request-timestamp`), five minute window, each signature accepted once.

## Request

curl:

```bash
curl -X POST "https://immiscible.fly.dev/slack/interactions" \
  -H "x-slack-signature: $SIGNATURE"
```

Node:

```ts
// signature: computed over the raw body, see the authentication note above
const res = await fetch('https://immiscible.fly.dev/slack/interactions', {
  method: 'POST',
  headers: {
    'x-slack-signature': signature,
  },
});
console.log(res.status, await res.text());
```

Python:

```python
import requests

# signature: computed over the raw body, see the authentication note above
res = requests.post(
    "https://immiscible.fly.dev/slack/interactions",
    headers={
        "x-slack-signature": signature,
    },
)
print(res.status_code, res.text)
```
