Authentication

Slack

HTTP command and interaction handlers validate Slack’s timestamped HMAC signature using SLACK_SIGNING_SECRET. Keep SLACK_ALLOW_UNSIGNED_REQUESTS=false; enabling it bypasses this control for development. Socket Mode authenticates with SLACK_APP_TOKEN, while Slack Web API calls use SLACK_BOT_TOKEN.

GitHub and Confluence

GitHub installation mode uses short-lived installation tokens minted from the App ID, installation ID, and private key. Delegated mode binds GitHub OAuth tokens to a Slack user. Hybrid prefers a connected user’s credential and can fall back to installation credentials. Confluence combines an encrypted, per-Slack-user PAT with administrator-managed MuleSoft credentials.

Security assessment

Application: Slack KB Agent. SRA status: Approved. Reference: RI0038086. Last approved: 2026-06-18. Next review, reviewer, data classification, AMR link, ACT link, and ServiceNow application link: TO_BE_CONFIRMED.