Slack App Workflow
Workflow
- Choose a workspace app, distribution model, event delivery route, and a narrow OAuth scope inventory before code.
- Use Events API plus a public receiver when the service owns inbound HTTPS; use Socket Mode only when its operational model fits the deployment.
- Verify Slack request signatures, acknowledge events and interactive payloads promptly, and use the response URL or Web API only within their documented lifecycle.
- Treat workspace, enterprise, channel, user, and installation identities as distinct. Check authorization before acting on a command, shortcut, modal submission, or message event.
- Make interactive state explicit and short-lived; never place secrets or unverified authority in action values.
- Validate OAuth reinstall, scope changes, signature failures, retry headers, modal errors, and a workspace-admin removal path.
Handoffs
Start with Slack apps and Bolt. Use webhook-and-event-lifecycle and the selected server stack skill for implementation.