Cosmovex Tools

Slack slash command or request signature failing? Capture it and verify X-Slack-Signature

Slack slash command with Hookwatch Webhook Tester

This inbox is set up as the Request URL of a Slack slash command. Run the command in Slack and the form-encoded payload appears here with command, text, user, channel, response_url and trigger_id, plus the X-Slack-Signature and timestamp headers. The Signature tab rebuilds the v0 base string and checks it with your app's Signing Secret and the five-minute window.

  1. Copy the inbox URL. It ends in /slack/commands, the path a slash-command handler usually listens on.
  2. In your app at api.slack.com open Slash Commands, create a command such as /deploy and paste the URL as Request URL. For buttons and modals, paste it under Interactivity & Shortcuts instead.
  3. Reinstall the app, run /deploy staging in Slack, or press Send a signed test Slack event here to see a signed slash-command payload first.
  4. Select the request. The Body tab shows the form fields; the Signature tab reads X-Slack-Signature and X-Slack-Request-Timestamp.
  5. Paste the Signing Secret from Basic Information. Valid with an old timestamp means the signature is right but the request is outside Slack's five-minute window.
slack slash command request url slack signature verificationx-slack-signatureslack request signing secretslack webhook testerslack interactivity request url
Open Hookwatch Webhook Tester Free · Pro $5/mo · no account

What to know

Slack signs every request it sends to your app, slash commands, interactivity and Events API alike, with the same scheme. It joins the version, the timestamp and the raw body as v0:{X-Slack-Request-Timestamp}:{body}, computes HMAC-SHA256 with the app's Signing Secret and sends v0=<hex digest> in X-Slack-Signature. Slash commands and interactive payloads are application/x-www-form-urlencoded, so the body to hash is the encoded form string, not the parsed fields; interactive payloads put their JSON inside a payload= field.

Reject requests whose timestamp is more than five minutes from your server clock, as Slack recommends, to stop replays. If the signature is Valid here but your handler rejects it, check that your framework did not parse the form before you read the raw body, that you used the Signing Secret and not the deprecated verification token sent in the token field, and that your server clock is in sync. The Bolt SDKs do all of this for you when they receive the raw request.

Slack waits 3,000 ms for the response to a slash command. Answer within that time with an acknowledgement, then send the real result to response_url, which accepts up to five messages within 30 minutes. trigger_id, needed to open a modal, expires after 3 seconds. This inbox always answers 200 with {"ok":true} on the free plan, so Slack will not show your usual reply in the channel; a Pro inbox can return a custom JSON body such as {"text":"Deploying…"} to test what users see.

Event Subscriptions are different: when you save an Events API Request URL, Slack sends a url_verification request and expects the challenge value echoed back. This inbox returns a fixed response, so it cannot pass that check, and Slack will not save the URL. Use this page for slash commands and interactivity, and the Send a signed test Slack event button or a captured payload to test the Events API signature itself.

Updated · Cosmovex

Questions

Where is the Slack Signing Secret?

At api.slack.com/apps, open your app and go to Basic Information → App Credentials → Signing Secret. It is different from the bot token (xoxb-…) and from the deprecated verification token that still appears in the token field of slash-command payloads.

What exactly does Slack sign?

The string v0:, the X-Slack-Request-Timestamp value, a colon, then the raw request body, hashed with HMAC-SHA256 and the Signing Secret. The header is v0= followed by the hex digest. Press Show the exact signed string in the Signature tab to see it for any request.

Can I use this URL for the Events API?

Not for the Request URL in Event Subscriptions. Slack verifies that URL by sending a challenge it expects echoed back, and this inbox replies with a fixed body. Slash commands and Interactivity & Shortcuts URLs are not verified that way, so they work.

Why does my slash command show a timeout in Slack?

Slack waits 3 seconds for the response. Acknowledge immediately with a 200, do the work in the background and post the result to the response_url from the payload.

Is the Signing Secret sent to your server?

No. The HMAC is computed in your browser with WebCrypto. The slash-command request is stored on our server so it can show in your inbox; the secret stays in this browser's storage.

The free plan covers everything on this page. Hookwatch Webhook Tester Pro ($5/mo, billed monthly) is described on the Hookwatch Webhook Tester page.