{"id":"webhook-slack-verify","version":"1.0.0","description":"Verify a Slack request's X-Slack-Signature against its raw body and timestamp, with an absolute replay-window check.","supported_operations":["verify slack request signature","check x-slack-signature","validate a slack slash command request","is this webhook really from slack","slack signing secret verification","slack slash command signature check"],"unsupported_operations":["computing a fresh X-Slack-Signature for a test delivery (see webhook-signature-compute)","verifying any other vendor webhook scheme (see webhook-stripe-verify, webhook-standard-verify, webhook-twilio-verify)"],"semantics":["basestring = 'v0:' + timestamp (the exact digit string given, not re-parsed as a number) + ':' + body (the raw request body text, never JSON-reserialized or form-decoded).","The computed signature is 'v0=' + lowercase-hex(HMAC-SHA256(signing_secret as UTF-8 bytes, basestring as UTF-8 bytes)); compared to the input signature with a constant-time comparison as whole strings.","When now is given: timestamp_checked is true, and the tool fails with reason 'timestamp_outside_tolerance' when abs(now - timestamp) > tolerance_seconds -- an ABSOLUTE difference (both a stale and a future timestamp can fail), unlike webhook-stripe-verify's one-sided rule. The timestamp check runs only after a successful signature match.","When now is omitted: timestamp_checked is false and no freshness check is performed at all.","signing_secret is never echoed in the output or in any error details."],"limits":{"max_body_bytes":262144},"pricing":{"status":"unpriced","charge_usd":null},"input_schema":{"type":"object","additionalProperties":false,"required":["body","timestamp","signature","signing_secret"],"properties":{"body":{"type":"string","maxLength":262144},"timestamp":{"type":"string","pattern":"^[0-9]{1,16}$"},"signature":{"type":"string","pattern":"^v0=[0-9a-f]{64}$"},"signing_secret":{"type":"string","minLength":1,"maxLength":512},"now":{"type":"integer","minimum":0,"maximum":99999999999},"tolerance_seconds":{"type":"integer","minimum":0,"maximum":86400,"default":300}}},"output_schema":{"type":"object","additionalProperties":false,"required":["valid","reason","timestamp_checked"],"properties":{"valid":{"type":"boolean"},"reason":{"type":["string","null"],"enum":["signature_mismatch","timestamp_outside_tolerance",null]},"timestamp_checked":{"type":"boolean"}}},"examples":[{"input":{"body":"token=xyz","timestamp":"1531420618","signature":"v0=0000000000000000000000000000000000000000000000000000000000000000","signing_secret":"a-signing-secret"},"output":{"valid":false,"reason":"signature_mismatch","timestamp_checked":false}},{"input":{"body":"x","timestamp":"1","signature":"v0=e5f428eb7cd8bb5fbef4c3c4bd9d9a72b0e29be95d17f6c02b6cf47b95a9adc9","signing_secret":"k"},"output":{"valid":false,"reason":"signature_mismatch","timestamp_checked":false}}],"execute_url":"/v1/tools/webhook-slack-verify/versions/1.0.0/execute"}