slack pack
needs an app installed in your workspace before its first call. The manifest
below carries every scope the pack’s tools declare, so creating the app is one
click and a review rather than a page of scopes ticked by hand.
The links open in a new tab; this page stays where you left it.
1
Create the app
Create the Slack app from this manifestThe link opens Slack’s Create an app dialog with this manifest already in
it. Pick the workspace, Next, check the scopes, Next, Create. If the
link arrives with an empty editor, choose From a manifest yourself and paste
the block above into the JSON tab.The scopes are the pack’s own, read off its tools when this page is generated.
The name is only a default: call the app anything, and that is the name your
workspace sees on the messages it posts.The first eleven scopes read channels and history, post, and react. The other
eight belong to five tools that do more:
manifest.json
reactions_get (reactions:read),
conversations_open (im:write, mpim:write), conversations_create
(channels:manage, groups:write), conversations_invite (the two
*:write.invites) and conversations_join (channels:join). An app that will
never be handed those tools can drop their scopes from the manifest before
Next; a tool whose scope is missing answers missing_scope when called,
not at install.2
Install it
On the app’s page, Install App in the sidebar → Install to your
workspace → Allow.A workspace that restricts apps sends an approval request to its admins
instead, and the token appears once they approve.
3
Copy the bot token
The same page now shows a Bot User OAuth Token beginning The pack reads it on its next call. Rotation is off in the manifest, so this
token does not expire; it stops working only if the app is uninstalled.
xoxb-. That is the
credential:4
Invite the bot to the channels it should read
A bot reads only the channels it is a member of, and a channel it has not been
invited to answers Direct messages to the bot need no invite.
not_in_channel — on the tool call, not at install time. In
each channel, type:5
Verify
verify_slack.py
Searching messages
search_messages is the one tool a bot
token cannot call: Slack answers search.messages only for a user token. To
use it, add search:read under OAuth & Permissions → User Token Scopes,
reinstall, and use the User OAuth Token (xoxp-…) that appears beside the
bot token. That token acts as you — everything it posts is posted by you — so
hand it only the search tool. The Slack pack page has the rest.
Your users’ workspaces
The same app, distributed. Under OAuth & Permissions, add your app’s callback as a Redirect URL. Under Manage Distribution, turn on public distribution. Each workspace then installs through your consent route instead of the Install button. Whether to turn token rotation on, and what changes when you do, is on Slack’s provider page; the route itself is getting the grant.Related
- Slack — the server constant, both token shapes, and refresh under rotation
- Every pack — what the other packs need, in one table