Custom Apps

Connect Slack and Salesforce through OAuth apps your workspace controls

Custom apps let your workspace use its own Slack or Salesforce OAuth client. Open Settings → Integrations → Custom apps to add an app, manage its settings, and connect accounts through it.

Apps and Connections

An app registration stores the provider configuration and allowed permissions. Each connection authorizes an account or installation through that app.

ResourcePurposeAccess
Custom appClient configuration, permissions, and Slack manifestApp permissions control who can manage it or connect through it
Slack bot installationPost as the app and receive bot events for a Slack workspaceWorkspace resource; permitted workflow editors can use it, subject to explicit denies
Personal Slack connectionPerform actions as the person who connectedOnly that person can use its user token
Salesforce connectionAccess the connected Salesforce account through the custom clientCredential permissions control its use

Sharing an app does not share every account connected through it. Bot credentials can also be shared with members or groups through credential access controls. Personal Slack tokens stay private.

Custom apps lists active registrations by default. Use the status filter to include disabled or archived apps. Archived app details are read-only.

Set Up Slack

  1. Add a custom app and choose Slack. Choose the setup path for a new or existing Slack app.
  2. For a new app, follow Create New App → From scratch in Slack. Return with its app ID, client ID, client secret when required, and signing secret. For an existing app, enter its details and review its current manifest before replacing settings.
  3. Set the app name and Bot display name. Display names can contain spaces and capitals, such as Operator Bot Pluto.
  4. Choose bot permissions and bot event subscriptions. The event list shows required permissions and offers to add missing ones. Removing an event keeps its permissions until you remove them separately. Optional user permissions enable personal actions.
  5. Match Use PKCE to the Slack app's configuration. SteelEngine enforces PKCE for local or non-web callbacks. Use a public HTTPS origin for bot installation and events.
  6. Save the app. Its Slack setup section now provides a complete manifest with the redirect URL, Events API URL, display name, permissions, and bot subscriptions.
  7. Copy the JSON into the Slack app's App Manifest settings and save it, or use automatic setup below. Verify the Events API request URL in Slack.
  8. Select Install Slack app and complete OAuth. Custom Slack bot installation and reconnect require workspace administrator access.

Saving a registration stores settings in SteelEngine. Applying a manifest changes the Slack app. Installing or reconnecting grants access to the Slack workspace. Complete each step the setup screen requests.

Automatic Setup and Manifest Review

You can optionally save an app configuration access token and refresh token in Automatic setup. These tokens manage the Slack app configuration and are separate from the bot and personal OAuth tokens used by workflows. Saved tokens are encrypted; use Refresh token or replace them when needed.

Importing Slack's current manifest opens a side-by-side review. Keep the local version, use Slack's version, or merge individual changes. Review unsupported settings and permissions before saving. Existing callbacks and unrelated supported manifest settings are preserved by the review flow.

Save the reviewed settings before applying them to Slack. Automatic setup checks that Slack's manifest has not changed since the review; if it has, review the new differences before applying. Manual setup can import pasted JSON and provide a complete replacement manifest without a configuration token.

Personal Actions

After a bot installation is available, choose Connect my Slack account to authorize your own user token when needed. Other members connect their own accounts.

In a Slack action block, select the app under Auth connection, choose Act as, then choose the matching credential. Select App bot to act as the installation or the connected-user option to act as yourself. If you have no personal connection, the block offers OAuth connection. Operations, destinations, and channel choices reflect the selected token's permissions.

Events and Channels

Managed Slack triggers use bot installations. Select the hosted app or a custom app, its bot credential, and an event from the app's saved subscriptions. Personal user-event triggers are unsupported. Change older user-event or combined-event triggers to a bot installation and redeploy them.

All workflows for a custom app receive events through its saved Events API URL, /api/integrations/apps/{routingKey}. Hosted Slack uses /api/integrations/slack/events. SteelEngine verifies signatures, matches the app and Slack workspace to the installation, and routes matching events to deployed workflows. Trigger filters do not change the Slack manifest.

Use event type, channels, message-change handling, and file handling to narrow each trigger. Channel controls distinguish visible channels from channels the selected identity can access. Join an eligible channel when the token has permission, or follow the invitation instructions. Receiving events also requires the channel to be allowed by the connection's policy and included in the app's subscriptions. Joining a channel does not automatically enable its events.

Enterprise Grid organization-wide installations and Slack Connect external shared-channel events are unsupported.

Connection Needs Attention

If a connection has permissions outside the saved configuration, review the app settings or import Slack's current manifest. Save the intended permissions and reconnect when required. Reconnecting alone cannot reconcile a configuration mismatch.

If Slack cannot verify the Events API URL, check that the saved signing secret belongs to the same app and that the public URL reaches SteelEngine.

Set Up Salesforce

Add a Salesforce custom app using your External Client App or existing Connected App. Copy the redirect URL shown by SteelEngine into the provider configuration, enter the consumer key and secret, and choose the production, sandbox, or HTTPS My Domain login environment.

Select the required permissions, save the app, and connect an account through it. The default permissions are api and refresh_token. Workflow and connector credential choices remain bound to the selected app and account. Changing client identity or login environment requires a new registration.

Local Development with a Tunnel

Start an HTTPS tunnel to port 3000. Stop the existing web process on that port, then start the web app from the repository root:

bun run dev:web:public -- https://your-tunnel.ngrok-free.app

This command sets NEXT_PUBLIC_APP_URL and APP_URL for the web process and keeps internal API calls on localhost unless INTERNAL_API_BASE_URL is already set. It does not edit environment files or start the rest of the local stack. Keep your usual infrastructure and worker services running.

Open the tunnel URL and sign in there before starting OAuth. Copy a fresh manifest using that same origin and update the Slack app's redirect and Events API URLs. Begin and finish authorization in the same browser session and origin.

For the deployment-wide hosted Slack app, see Slack Events.

On this page