Authentication
Slack
HTTP command and interaction handlers validate Slack’s timestamped HMAC signature using SLACK_SIGNING_SECRET. Keep SLACK_ALLOW_UNSIGNED_REQUESTS=false; enabling it bypasses this control for development. Socket Mode authenticates with SLACK_APP_TOKEN, while Slack Web API calls use SLACK_BOT_TOKEN.
GitHub and Confluence
GitHub installation mode uses short-lived installation tokens minted from the App ID, installation ID, and private key. Delegated mode binds GitHub OAuth tokens to a Slack user. Hybrid prefers a connected user’s credential and can fall back to installation credentials. Confluence combines an encrypted, per-Slack-user PAT with administrator-managed MuleSoft credentials.