API Key on API Gateway to use with slash commands

Viewed 927

I'm creating a new Slack app that basically accepts slash commands. It's working already, but I would like to secure my API using an API Key. Configured the API key + Usage plan already, but not sure how to use it on the slack-side.

I basically need to send a x-api-key header, but that doesn't seem to be possible from the Slack side?

Having an open API just relying on the slack verification token seems very risky, depending on your command...

Is there a way to do it or is that the way to go? Verifying just with the token and the team ID.

2 Answers

Its not possible to add custom headers to requests coming from Slack like x-api-key as you suggested.

The standard approach to securing your API is to use the "signed secrets", not the verification token. The verification token is an older security feature that still works, but is less secure and therefore no longer recommended.

Signed secrets will cryptographically sign every request from Slack with a generated key using standard HMAC-SHA256 keyed hash. You can find that key on your app configuration page.

Check out this documentation for more details on how to use signed secrets.

API Gateway allows you to configure a Velocity template to remap HTTP requests. You could configure your API key as a query parameter as part of the webhook you specify in the Slack app config (secure as long as you're using HTTPS) and direct it to an endpoint that doesn't not require a key. Then remap the query parameter to a the x-api-key header and forward to the authenticated endpoint.

Related