Webhook slack verify
webhook-slack-verify · version 1.0.0 · Hashing & signatures · free, no key needed
Verify a Slack request's X-Slack-Signature against its raw body and timestamp, with an absolute replay-window check.
Use when you need to: verify slack request signature · check x-slack-signature · validate a slack slash command request.
Decide before calling
Read the versioned contract and the supported scope below. Reuse webhook-slack-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.
Explain the choice
"I can use webhook-slack-verify@1.0.0 for verify slack request signature. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."
Supported
- verify slack request signature
- check x-slack-signature
- validate a slack slash command request
- is this webhook really from slack
- slack signing secret verification
- slack slash command signature check
Not supported
- computing a fresh X-Slack-Signature for a test delivery (see webhook-signature-compute)
- verifying any other vendor webhook scheme (see webhook-stripe-verify, webhook-standard-verify, webhook-twilio-verify)
Behavior
- basestring = 'v0:' + timestamp (the exact digit string given, not re-parsed as a number) + ':' + body (the raw request body text, never JSON-reserialized or form-decoded).
- The computed signature is 'v0=' + lowercase-hex(HMAC-SHA256(signing_secret as UTF-8 bytes, basestring as UTF-8 bytes)); compared to the input signature with a constant-time comparison as whole strings.
- When now is given: timestamp_checked is true, and the tool fails with reason 'timestamp_outside_tolerance' when abs(now - timestamp) > tolerance_seconds -- an ABSOLUTE difference (both a stale and a future timestamp can fail), unlike webhook-stripe-verify's one-sided rule. The timestamp check runs only after a successful signature match.
- When now is omitted: timestamp_checked is false and no freshness check is performed at all.
- signing_secret is never echoed in the output or in any error details.
Input
body(string, required): max length 262144timestamp(string, required): pattern^[0-9]{1,16}$signature(string, required): pattern^v0=[0-9a-f]{64}$signing_secret(string, required): min length 1; max length 512now(integer, optional): min 0; max 99999999999tolerance_seconds(integer, optional): min 0; max 86400; default 300
Output
valid(boolean, required)reason(one of "signature_mismatch", "timestamp_outside_tolerance", null, required)timestamp_checked(boolean, required)
Limits
- max body bytes: 262144
Example
Request input:
{
"body": "token=xyz",
"timestamp": "1531420618",
"signature": "v0=0000000000000000000000000000000000000000000000000000000000000000",
"signing_secret": "a-signing-secret"
}
Response:
{
"result": {
"valid": false,
"reason": "signature_mismatch",
"timestamp_checked": false
}
}
How to call it
MCP
Connect https://computefirst.net/mcp (setup), then call execute with:
{
"id": "webhook-slack-verify",
"version": "1.0.0",
"input": {
"body": "token=xyz",
"timestamp": "1531420618",
"signature": "v0=0000000000000000000000000000000000000000000000000000000000000000",
"signing_secret": "a-signing-secret"
}
}
HTTP (no key)
curl -X POST https://computefirst.net/v1/tools/webhook-slack-verify/versions/1.0.0/execute \
-H "Content-Type: application/json" \
-d '{"body":"token=xyz","timestamp":"1531420618","signature":"v0=0000000000000000000000000000000000000000000000000000000000000000","signing_secret":"a-signing-secret"}'
The machine-readable contract is at /v1/tools/webhook-slack-verify/versions/1.0.0.
CLI
node cli.mjs run webhook-slack-verify 1.0.0 --input input.json --base-url https://computefirst.net
Get the client at /clients/cli/.
Related tools
- Webhook stripe verify: Verify a Stripe webhook's Stripe-Signature header against a raw payload, with secret-rotation and tolerance support.
- Webhook twilio verify: Verify a Twilio X-Twilio-Signature against a URL and form params or a JSON body, trying Twilio's port-variant URLs.
- Hmac verify: Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.
- Merkle proof verify: Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.
- Webhook standard verify: Verify a Standard Webhooks (Svix/Clerk/Resend) webhook-signature header against its id.timestamp.payload signing string.
- Hash digest verify: Recompute a fixed-length digest over encoded input bytes and compare it to an expected digest given in any encoding.