1. Guides
  2. Slack with your own app

​
Slack with your own app

This is the path where your workspace owns the Slack app. Your name is on it, your admins control it, and if you ever leave WhooshBang the app is still yours to keep or delete. WhooshBang holds only what it needs to deliver through it.

Slack does not let anyone create an app on your behalf, so three of the steps below happen in Slack. Everything else is in WhooshBang, and the whole runbook is on screen before you start — nothing arrives as a surprise halfway through.

​
Before you start

  • You need permission to create Slack apps. Many workspaces restrict this. If yours does, Slack will say so at the first step, and an administrator has to either lift the restriction or do the creation for you. WhooshBang cannot work around it and does not try.
  • Choose the names carefully. Slack shows the app name and the bot display name to your whole workspace. You can rename them in Slack afterwards, under Basic Information → Display Information — but WhooshBang keeps showing the names you chose here, so the two drift apart until you enter them again. Pick what you want people to read in their notifications.
  • The icon is not part of this. Slack has no way to set an app icon from a creation link, so your app starts with Slack’s default. Upload one yourself in Slack afterwards, under Basic Information → Display Information. It changes nothing about how the connection works.

​
The journey

​
1. Name the app in WhooshBang

Choose Your own Slack app — Customer-owned, then enter the app name, the bot display name, and a one-line description. WhooshBang generates a Slack app configuration from them and returns a creation link.

Nothing has been created in Slack yet, and nothing has been claimed. You can read exactly what the app will ask for before you go anywhere:

curl --silent --show-error \
  --header "Authorization: Bearer $WHOOSHBANG_CREDENTIAL" \
  "https://api.whooshbang.com/v1/projects/$PROJECT_ID/environments/$ENVIRONMENT_ID/channel-connections/$CONNECTION_ID/app-manifest"

​
2. Create it in Slack

Open the creation link. Slack shows the configuration already filled in — there is nothing to paste. Choose the workspace, review what the app asks for, and press Create.

It asks for two permissions and no others:

PermissionWho approves itWhat it is for
chat:writeA workspace administrator, once, at installSending the notification
openidEach recipient, for themselvesConfirming which Slack person they are

There is no channel read, no directory read, no workspace-wide token, and nothing requested for a feature that has not shipped.

​
3. Hand over three values

Slack keeps three values on Basic Information → App Credentials that it will not give WhooshBang any other way. Enter them once, in WhooshBang:

ValueWhat it doesRead back later?
Client IDNames your app in the sign-in redirect your workspace can already seeYes — it is not a secret
Client SecretCompletes the install exchange and each recipient’s sign-inNever
Signing SecretProves an inbound request really came from SlackNever

The two secrets are sealed the moment they arrive. No WhooshBang surface returns either of them afterwards — not the API, not the SDK, not the dashboard, not a support view. Absence is the mechanism, not redaction.

Select Show beside each one in Slack to reveal it. WhooshBang never asks for anything confidential inside Slack itself: every link it opens goes to Slack to create, install, or view something, and the three values are typed into WhooshBang.

There is no bot-token field, and that is the point. A bot token is the credential that can post as your app, and copying one through a browser and a clipboard is exactly the risk this path avoids. WhooshBang gets it from Slack’s own installation exchange in the next step, server to server.

​
4. Install it into your workspace

Select Install. Slack asks an administrator to approve chat:write for this workspace, then hands the bot grant to WhooshBang directly. You are never asked to copy it.

​
5. Open the app once in Slack

Its Home tab is enough. That first request Slack signs is the only thing that can prove the Signing Secret reached us intact — no amount of checking on our side can produce it.

Setup is complete when WhooshBang has verified all four: the app, the workspace, the bot grant, and one request Slack signed.

​
Prove it works

Two checks you can run at any time, from the dashboard, the API, the SDK, or an MCP client. Both go only to the person who installed the app and count as no delivery to anybody:

  • Delivery test — one private message through your app’s own identity. It settles on Slack’s acceptance, and tells you the bot grant works.
  • Round-trip test — the same message with one button. Press it, and Slack sends WhooshBang a signed request back. This is the only check that proves the Signing Secret, the interactivity request URL, and public reachability are all correct at once.
curl --silent --show-error --request POST \
  --header "Authorization: Bearer $WHOOSHBANG_CREDENTIAL" \
  --header "Content-Type: application/json" \
  --header "Idempotency-Key: $(uuidgen)" \
  --data '{"kind":"signed_interaction"}' \
  "https://api.whooshbang.com/v1/projects/$PROJECT_ID/environments/$ENVIRONMENT_ID/channel-connections/$CONNECTION_ID/tests"

A round-trip test comes back pending and settles when the button is pressed. Every result is kept, so the test history is also the failure history: what was tried, when, what came back, and what to do about it.

​
Living with it

​
Rotating the secrets

Enter all three values again. Slack shows them on one screen, and they are sealed together as one set — replacing one alone would mean reading the other two back at a boundary whose whole purpose is that nothing reads them.

Rotating does not change your app’s identity, so subscribers stay bound to the identity they consented to.

​
Reinstalling

Reinstalling asks Slack for a fresh bot grant for the same app and workspace. It is the answer when the grant is revoked, expires, or a health check reports the installation is no longer usable. Subscribers keep their consent: it is the same app and the same workspace.

​
Starting over

If you abandoned the setup or want a different app name, start it over. This replaces the connection with a new one, because Slack bakes WhooshBang’s request URLs into the app at the moment it is created and they cannot be re-pointed afterwards; a second setup on one connection would mean two Slack apps answering to one address.

Read the id on the response — the connection you were watching is now archived. Any app you already created in Slack stays yours; delete it there when you are ready. WhooshBang holds no authority to remove it, which is what customer-owned means.

Re-entering the three values is not starting over and does not need it.

​
Resuming

Closing the browser loses nothing. Everything durable is written before you ever leave for Slack, so the connection is there to come back to with the same link and the same step outstanding.

​
Uninstalling and removing

Removing the app in Slack revokes the grant. WhooshBang notices, marks the connection as needing reinstalling, and stops sending rather than failing silently.

Retiring the connection in WhooshBang is the other direction: consent granted against it is invalidated, its subscription links are revoked, and the notifier stops routing through it. Purging additionally destroys what WhooshBang holds, so nothing here can act as your app afterwards. Neither deletes the app in Slack — that is yours.

​
The other Slack paths

PathWho owns the appWho your workspace sees
WhooshBang for SlackWhooshBangThe WhooshBang app, installed in your workspace
Your own Slack app (this page)YouYour app, under your name
Dedicated WhooshBang-managed appWhooshBangAn app under your name that WhooshBang creates and operates

The third is not available yet, and when it is, it will be presented honestly as what it is. A dedicated app carries your name but WhooshBang’s ownership: WhooshBang creates it, holds its credentials, and can change its configuration. Only the path on this page is genuinely customer-owned, where the app exists in your workspace whatever happens to your WhooshBang organization.

​
Not supported, on purpose

  • Workspace-wide configuration tokens. They would let WhooshBang change any app in your workspace. The three app-specific values are the smallest authority that does this job, so they are the only thing asked for.
  • Socket Mode. It replaces public request URLs with a persistent WebSocket per app. It cannot be listed on the Slack Marketplace and it is reserved for a future self-hosted connector.
  • Incoming webhooks. They deliver a message and nothing else: no buttons, no replies, no App Home management. A delivery-only Slack connection is deliberately not offered, because it would look like the product and answer nothing.
  • One app distributed across several workspaces. Each connection is one app in one workspace, which is what keeps a credential, a consent, and an environment from ever spanning two.
  • Posting to channels. This release is personal delivery. Nothing here reads a channel or posts to one.