Chat approvals
Slack interactions
POST
/slack/interactionsApprove and Deny buttons, verified by Slack’s signature before anything is read.
#Authentication
Issuer signature
No bearer credential: the caller proves itself by signing the raw request body. Anything that does not verify is refused (or, on the card rail, declined) before the body is read.
Slack's v0 signature (x-slack-signature and x-slack-request-timestamp), five minute window, each signature accepted once.