Webhook slack verify

webhook-slack-verify · version 1.0.0 · Hashing & signatures · free, no key needed

Verify a Slack request's X-Slack-Signature against its raw body and timestamp, with an absolute replay-window check.

Use when you need to: verify slack request signature · check x-slack-signature · validate a slack slash command request.

Decide before calling

Read the versioned contract and the supported scope below. Reuse webhook-slack-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.

Explain the choice

"I can use webhook-slack-verify@1.0.0 for verify slack request signature. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

Supported

Not supported

Behavior

Input

Output

Limits

Example

Request input:

{
  "body": "token=xyz",
  "timestamp": "1531420618",
  "signature": "v0=0000000000000000000000000000000000000000000000000000000000000000",
  "signing_secret": "a-signing-secret"
}

Response:

{
  "result": {
    "valid": false,
    "reason": "signature_mismatch",
    "timestamp_checked": false
  }
}

How to call it

MCP

Connect https://computefirst.net/mcp (setup), then call execute with:

{
  "id": "webhook-slack-verify",
  "version": "1.0.0",
  "input": {
    "body": "token=xyz",
    "timestamp": "1531420618",
    "signature": "v0=0000000000000000000000000000000000000000000000000000000000000000",
    "signing_secret": "a-signing-secret"
  }
}

HTTP (no key)

curl -X POST https://computefirst.net/v1/tools/webhook-slack-verify/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"body":"token=xyz","timestamp":"1531420618","signature":"v0=0000000000000000000000000000000000000000000000000000000000000000","signing_secret":"a-signing-secret"}'

The machine-readable contract is at /v1/tools/webhook-slack-verify/versions/1.0.0.

CLI

node cli.mjs run webhook-slack-verify 1.0.0 --input input.json --base-url https://computefirst.net

Get the client at /clients/cli/.