Slack Integration
AI Coworker can receive Slack events/commands and queue coding tasks for human approval. The Slack handlers and their unit tests do not establish that a live Slack workspace-to-cloud-run workflow has been exercised. VERIFICATION.md records no live cloud end-to-end run.
Architecture
Section titled “Architecture”The Slack integration is powered by the Orchestrator Worker and Durable Objects:
- Inbound Webhook: Slack sends event notifications (
app_mentionor direct message) toPOST /api/slack/events. - Signature Verification: The Worker validates the
X-Slack-Signatureand timestamp using your configuredSLACK_SIGNING_SECRET. - Task Coordination: A repository is resolved from the request/thread or configured channel mapping; if none is available, the bot asks in-thread rather than guessing. A valid request is queued as a pending approval.
- Approval card: Slash-command responses and mentions can present approval/rejection controls. Mentions require
SLACK_BOT_TOKEN; an empty token means no mention card and no run. An approval queues execution; successful coding or PR creation is not guaranteed. - Repo resolution: GitHub URL in the mention/thread, else
SLACK_CHANNEL_REPOS, else an in-thread ask — never a guessed repo.
Setup Instructions
Section titled “Setup Instructions”-
Create a Slack App Fastest: at api.slack.com/apps choose Create New App → From a manifest and paste
slack-app-manifest.yamlfrom the repository root — it declares the scopes,app_mentionevent,/shiba-ai-coworkercommand, and interactivity below. Edit the twoyour-worker.workers.devURLs to your Worker hostname. Manual alternative: -
Configure Bot Token Scopes Under OAuth & Permissions, add the following Bot Token Scopes:
chat:write(post messages and replies)app_mentions:read(listen for @AI Coworker mentions)channels:history(read thread context)im:history(read and reply to direct messages)
-
Enable Event Subscriptions Set the Request URL to your Cloudflare Worker endpoint:
https://your-worker.workers.dev/api/slack/eventsSubscribe to bot events:
app_mentionandmessage.im(the second one powers DM conversations with the coworker). -
Enable Interactivity Under Interactivity & Shortcuts, enable interactivity and set the Request URL:
https://your-worker.workers.dev/api/slack/interact -
Store Secrets with Wrangler Set the secrets in your Cloudflare environment:
Terminal window pnpm wrangler secret put SLACK_BOT_TOKEN --config apps/backend/wrangler.jsoncpnpm wrangler secret put SLACK_SIGNING_SECRET --config apps/backend/wrangler.jsoncMentions need
SLACK_BOT_TOKEN. Map channels to repos with theSLACK_CHANNEL_REPOSvar ({"C123":"https://github.com/owner/repo"}).SLACK_APPROVERSis a comma-separated list of Slack user ids; unset means nobody can approve. Slack-originated runs launchclaude-codeby default; set theSLACK_AGENT_HARNESSvar to override (it falls back toAGENT_HARNESS, thenclaude-code).
Example Interaction (illustrative, not a verification result)
Section titled “Example Interaction (illustrative, not a verification result)”In any channel where the bot is invited — or in a DM:
Developer:
@AI Coworker fix the typo in README.md and add pnpm instructionsAI Coworker: Approval requested for the repository and proposed action; approve or reject before a sandbox starts.
[ Approve ] [ Reject ]
After approval, the Worker attempts the run and posts its outcome to the Slack thread. A PR link is posted only when publishing was requested and succeeds. The recorded local OpenCode run stopped at a provider 401; no cloud end-to-end run is recorded (see Verification status).
