View as Markdown
Slack icon

Slack ACTION

Verify Slack Signature

Verifying requests from Slack, slack signs its requests using a secret that's unique to your app. Request Body must be the raw request body as a string (not a parsed object) — Slack computes its signature over the exact raw bytes it sent, so re-serializing a parsed object will not match. See the documentation
  • Action
  • Read only
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's Slack account once, then configure and run Verify Slack Signature from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "slack_v2-verify-slack-signature",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    slack_v2: { authProvisionId: "apn_xxxxxxx" },
    slackSigningSecret: "Signing Secret",
    slackSignature: "X-Slack-Signature",
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Verify Slack Signature inputs
Property Type Description
slackSigningSecret Signing Secret string
Slack Signing Secret, available in the app admin panel under Basic Info.
Required
slackSignature X-Slack-Signature string
Slack signature (from X-Slack-Signature header).
Required
slackRequestTimestamp X-Slack-Request-Timestamp string
Slack request timestamp (from X-Slack-Request-Timestamp header).
Required
requestBody Request Body string
The body of the request to be verified.
Required

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
slack_v2-verify-slack-signature
Version
1.0.4
App
Slack
Authentication
OAuth
Read-only
Yes
Destructive
No
Open world
Yes