Skip to main content
This page is for the person who approves the app in a Slack workspace. It lists every permission (scope) and event the manifest Lua generates asks for, what the agent does with each, and what happens without it. The bot only ever reads conversations it was added to. Verified against lua-cli 3.41.0.

Required and optional

Slack lets an app mark permissions as optional, and the app’s OAuth & Permissions page lists each one with Required: No. The agent works without them: a workspace that doesn’t grant one only loses that feature. Twelve permissions are required: without them the bot cannot receive a mention or a direct message, know who wrote, or be connected at all. Eight are optional. Permissions are only ever added. Installing again with a longer list adds the new ones to the same bot token.

Required permissions

Optional permissions

What is deliberately not there: commands (no slash commands), users:write, and every *:write scope for channels, user groups or pins.

Events

Slack sends these to Lua. None of them needs a permission beyond the list above.

Signing secret

Every event Slack sends is signed with the app’s Signing Secret (Basic Information → App Credentials). Lua asks for it when you connect and checks each event against it. The first event that matches confirms the secret; from then on Lua rejects any event that doesn’t match, so nobody can make the agent act on a forged message. Until that first match, an event that doesn’t match is still answered and the dashboard says the secret doesn’t match. A wrongly pasted secret never silences a working bot.

Applying a newer manifest

Lua can’t change an app that belongs to your workspace; its owner applies each new version. When a connection lacks a required permission or has no signing secret, the dashboard shows Update available on the Slack card:
  1. Copy the manifest from the update dialog and paste it under App Manifest in Slack, on the JSON tab, then Save Changes.
  2. Save the Signing Secret in the dialog.
  3. Reinstall: a public app through Install in Slack in the dialog; a private app with the banner Slack shows, or Install App → Reinstall to Workspace.
  4. Select Check again; the card updates once Slack reports the new permissions.

Next steps

Connect Slack

Create the app, connect it, and choose when it answers.

Teams permissions

The same page for Microsoft Teams.