Skip to content

Slack Integration

AI Coworker can receive Slack events/commands and queue coding tasks for human approval. The Slack handlers and their unit tests do not establish that a live Slack workspace-to-cloud-run workflow has been exercised. VERIFICATION.md records no live cloud end-to-end run.

The Slack integration is powered by the Orchestrator Worker and Durable Objects:

  1. Inbound Webhook: Slack sends event notifications (app_mention or direct message) to POST /api/slack/events.
  2. Signature Verification: The Worker validates the X-Slack-Signature and timestamp using your configured SLACK_SIGNING_SECRET.
  3. Task Coordination: A repository is resolved from the request/thread or configured channel mapping; if none is available, the bot asks in-thread rather than guessing. A valid request is queued as a pending approval.
  4. Approval card: Slash-command responses and mentions can present approval/rejection controls. Mentions require SLACK_BOT_TOKEN; an empty token means no mention card and no run. An approval queues execution; successful coding or PR creation is not guaranteed.
  5. Repo resolution: GitHub URL in the mention/thread, else SLACK_CHANNEL_REPOS, else an in-thread ask — never a guessed repo.
  1. Create a Slack App Fastest: at api.slack.com/apps choose Create New App → From a manifest and paste slack-app-manifest.yaml from the repository root — it declares the scopes, app_mention event, /shiba-ai-coworker command, and interactivity below. Edit the two your-worker.workers.dev URLs to your Worker hostname. Manual alternative:

  2. Configure Bot Token Scopes Under OAuth & Permissions, add the following Bot Token Scopes:

    • chat:write (post messages and replies)
    • app_mentions:read (listen for @AI Coworker mentions)
    • channels:history (read thread context)
    • im:history (read and reply to direct messages)
  3. Enable Event Subscriptions Set the Request URL to your Cloudflare Worker endpoint:

    https://your-worker.workers.dev/api/slack/events

    Subscribe to bot events: app_mention and message.im (the second one powers DM conversations with the coworker).

  4. Enable Interactivity Under Interactivity & Shortcuts, enable interactivity and set the Request URL:

    https://your-worker.workers.dev/api/slack/interact
  5. Store Secrets with Wrangler Set the secrets in your Cloudflare environment:

    Terminal window
    pnpm wrangler secret put SLACK_BOT_TOKEN --config apps/backend/wrangler.jsonc
    pnpm wrangler secret put SLACK_SIGNING_SECRET --config apps/backend/wrangler.jsonc

    Mentions need SLACK_BOT_TOKEN. Map channels to repos with the SLACK_CHANNEL_REPOS var ({"C123":"https://github.com/owner/repo"}). SLACK_APPROVERS is a comma-separated list of Slack user ids; unset means nobody can approve. Slack-originated runs launch claude-code by default; set the SLACK_AGENT_HARNESS var to override (it falls back to AGENT_HARNESS, then claude-code).

Example Interaction (illustrative, not a verification result)

Section titled “Example Interaction (illustrative, not a verification result)”

In any channel where the bot is invited — or in a DM:

Developer: @AI Coworker fix the typo in README.md and add pnpm instructions

AI Coworker: Approval requested for the repository and proposed action; approve or reject before a sandbox starts.

[ Approve ] [ Reject ]

After approval, the Worker attempts the run and posts its outcome to the Slack thread. A PR link is posted only when publishing was requested and succeeds. The recorded local OpenCode run stopped at a provider 401; no cloud end-to-end run is recorded (see Verification status).