Skip to main content
The Slack channel enables IronClaw to respond to app mentions and direct messages in your Slack workspace.

Features

  • App mentions - @YourBot in any channel
  • Direct messages - DM the bot directly
  • Thread support - Conversations tracked via Slack’s native threading
  • Signature validation - HMAC-based request verification
  • DM pairing - Approve unknown users with pairing codes

Prerequisites

  • Slack workspace admin access
  • Public HTTPS URL for webhooks (ngrok, Cloudflare Tunnel, etc.)
  • IronClaw installed and configured

Setup

1. Create a Slack App

  1. Go to api.slack.com/apps
  2. Click Create New App → From scratch
  3. Name your app (e.g., “IronClaw Agent”) and select your workspace

2. Configure Bot Token Scopes

Under OAuth & Permissions, add these Bot Token Scopes:
  • app_mentions:read - Detect @mentions
  • chat:write - Send messages
  • im:history - Read DM history
  • im:read - Access DM channels
  • im:write - Send DMs

3. Install App to Workspace

  1. Click Install to Workspace
  2. Copy the Bot User OAuth Token (starts with xoxb-)

4. Enable Event Subscriptions

  1. Go to Event Subscriptions → Enable Events
  2. Set Request URL to https://your-tunnel-url/webhook/slack
  3. Under Subscribe to bot events, add:
    • app_mention - Bot is mentioned
    • message.im - DM received
  4. Save Changes

5. Get Signing Secret

  1. Go to Basic Information → App Credentials
  2. Copy the Signing Secret

6. Configure IronClaw

Set environment variables:
Or use the setup wizard:

7. Start IronClaw with Tunnel

Configuration

Edit ~/.ironclaw/channels/slack.capabilities.json:

Configuration Options

DM Pairing

When an unknown user DMs your bot with dm_policy: "pairing":

Flow

  1. Unknown user sends a DM
  2. Bot replies: To pair with this bot, run: ironclaw pairing approve slack ABC12345
  3. You run: ironclaw pairing approve slack ABC12345
  4. User is added to the allow list; future messages are delivered

Commands

Usage

App Mentions (Channel)

Mention the bot in any channel where it’s a member:

Direct Messages

DM the bot directly:

Threaded Conversations

Replies automatically thread under the original message:

Secrets

The channel requires two secrets:

Bot Token

Slack Bot OAuth Token (starts with xoxb-):
Or configure via secrets store:

Signing Secret

Slack Signing Secret for HMAC validation:
The host validates the X-Slack-Signature header before forwarding events to the WASM channel.

Events

URL Verification

When you first set the Request URL in Slack’s Event Subscriptions, Slack sends a challenge:
The channel automatically responds with the challenge to complete verification.

Event Callback

After verification, Slack sends event payloads:
The channel extracts the text, strips the <@U987XYZ> mention, and forwards "hello" to the agent.

Message Metadata

Each message includes metadata for response routing:
Responses use this metadata to post in the correct channel/thread.

Permissions

Owner Restriction

Limit the bot to a single user:
All messages from other users are silently dropped.

DM Policy

open - Allow all DMs:
allowlist - Only pre-approved users:
pairing - Allowlist + interactive pairing:

Rate Limiting

Slack’s API has a rate limit of ~1 request/second per method. The channel enforces 50 requests/minute for safety. If you exceed this, responses will be queued and sent when the rate limit resets.

Manual Installation

If the channel isn’t installed via the wizard:

Troubleshooting

Events not received

  1. Check Request URL - Verify the URL in Slack’s Event Subscriptions matches your tunnel
  2. Tunnel running - Ensure ngrok/Cloudflare tunnel is active
  3. Logs - Check ironclaw run logs for “Slack event” messages
  4. Signature validation - Ensure SLACK_SIGNING_SECRET is correct

Bot not responding

  1. Bot is a member - Add the bot to the channel (/invite @YourBot)
  2. Permissions - Verify bot has chat:write scope
  3. Token valid - Check SLACK_BOT_TOKEN starts with xoxb-
  4. Logs - Look for “Slack API error” in logs

Pairing not working

  1. DM policy - Ensure dm_policy is "pairing"
  2. Signing secret - Verify signature validation passes
  3. Logs - Check for “Pairing request” or “Pairing upsert failed”

Signature validation fails

  • Ensure SLACK_SIGNING_SECRET matches the value in Slack App Credentials
  • Check system clock is accurate (HMAC uses timestamp)
  • Verify webhook requests are coming from Slack (not a proxy/firewall rewriting headers)

Source Code

  • Implementation: ~/workspace/source/channels-src/slack/src/lib.rs
  • Capabilities: ~/workspace/source/channels-src/slack/slack.capabilities.json

Example App Manifest

For faster setup, use this app manifest:
  1. Go to api.slack.com/apps
  2. Click Create New App → From an app manifest
  3. Paste the manifest above
  4. Update request_url with your tunnel URL
  5. Install to workspace