Skip to content
Français

createSlackSource

import { createSlackSource } from "@elie-laloum/outpost";

Create a Slack trigger source for slash commands and interactive payloads. It verifies X-Slack-Signature over v0:timestamp:body within a timestamp window and uses trigger_id as delivery, rejecting requests without one; kind is command or the interaction type, and actor is slack:<user id>. It replies 200 with an empty body; the Events API is not supported.

Complete example and detailed rules.

  • optionsRequired
    SlackRequestOptions
    Slack app signing secret and timestamp window.
  • options.signingSecretRequired
    TriggerSecret
    Slack app signing secret verifying X-Slack-Signature, or a callback returning every currently accepted secret (old and new during a rotation). An empty string throws at creation; a callback that fails or returns nothing denies requests.
  • options.toleranceMsOptional
    number | undefined
    Accepted clock difference for the request timestamp, in milliseconds; defaults to 300000 (5 minutes). A value that is not a positive integer throws at creation.

TriggerSource

export declare function createSlackSource(
  options: SlackRequestOptions,
): TriggerSource;