Volter World

Twins / Slack / 3.0.8

@volter/twin-slack

Slack

volter-aiVolter maintainedSelected defaultv3.0.8

Local Slack messages, channels, OAuth installation and incoming webhooks over a synthetic workspace. No real Slack messages or invitation emails are sent.

The example uses Slack 3.0.8. Keep its dependency pins when following it.

Setup gives the current installation instructions for @volter/twin-slack 3.0.8. Open the published README for credentials, seeds, supported operations and limits.

README shipped with @volter/twin-slack 3.0.8

These instructions were published with this package. Their tool versions may differ from the current starter cohort. Use Setup to install this version.

Slack's Web API, workspace invitations and member pages, app configuration and OAuth install pages, incoming webhooks and signed app deliveries. The pinned API and corrections are in spec/; provenance is spec/SOURCE.md. The current product callers, operation decisions and customer story are in journeys/.

Use with an existing app

Use Node 22.6 or newer.

In an app that already uses Slack, install the product CLI and this exact twin release:

npm install --save-dev --save-exact @volter/world@3.0.147 @volter/world-core@3.0.147 @volter/twin-slack@3.0.6
./node_modules/.bin/volter world init --name my-app --twins slack --source slack=@volter/twin-slack

Run the local executable from this app’s folder; if it is missing, complete the installation here before continuing.

Review the detected vendor and bindings before booting. The World issues throwaway bot, Socket Mode and signing credentials using the names listed below. Run the app's own command inside the World:

./node_modules/.bin/volter world up
./node_modules/.bin/volter world run -- npm test
./node_modules/.bin/volter world log
./node_modules/.bin/volter world down

Replace npm test with your app or test command. down retains state and a later up resumes it. Publisher and catalog contribution instructions: the public publisher guide.

The pack models an ordinary workspace with people, channels, timestamped messages and threads, files, normal workspace user groups, apps and their scoped grants. Its APIs keep Slack's ok/error envelope, cursor paging and caller visibility. OAuth codes and grants have their own secrets, expiry and revocation. File bytes use the kernel blob seam. Scheduled messages use the World clock. Conversation workspace identity uses Slack's context_team_id, including channel visibility after vendor refresh and shared-World cloning. Existing local rows that carry team_id remain readable.

A person creates the workspace at slack.com/get-started and joins through invitation mail and the Join page. Workspace admins manage members and invitation requests at slack.com/admin. Developers configure their app at api.slack.com/apps; installation uses slack.com/oauth/v2/authorize and oauth.v2.access. Program calls use their own issued tokens; a person's synthetic client session is xoxp-<user-id>. Real credentials are never needed. In a named World browser, an existing member enters OAuth consent through slack.com/signin: their email, the confirmation code in the twin's /_twin/mail inbox, then the browser session. The consent page shows the requested bot/user scopes and the eligible channel for an incoming webhook. Apple/Google, SSO, passkeys and multi-workspace switching are outside that screen's scope. This flow sends no real email. Fresh local Worlds seed a synthetic workspace named World with its owner and #general through that signup flow. The default seed is copied into the application's .volter/seeds/ by init and remains editable there. Use the CLI and core versions pinned above for this release.

World doors represent acts the API does not perform: an externally developed distributed app (/_twin/apps), a client slash command, Home opening, link share or action (/_twin/client/*), and observation of app deliveries or invitation mail (/_twin/deliveries and /_twin/mail). The application's own credentials come from /_twin/app-credentials, which the World asks at every boot: its own app, installed in its workspace, with a bot token (SLACK_BOT_TOKEN), an app-level Socket Mode token (SLACK_APP_TOKEN) and the app's signing secret. It is subscribed to every event the twin sends (link_shared aside: it names no unfurl domain) and receives them over Socket Mode (it has no Request URL); its bot holds every scope Slack's methods name. Stored vendor mutations still use the API or vendor pages.

Its callers are journeys/demand.json's: RH2's Slack app and channel bridge, Volter Harness's Slack platform (the Chat SDK in Socket Mode), Twin's on-call recipe, Dub's Slack integration and Postiz's Slack channel. Enterprise Grid administration, SCIM provisioning and legacy OAuth are outside the modeled slate. Every Web API operation no demand, life step or refresh reaches answers the gap (unknown_method), files.upload among them. The upload flow is files.getUploadURLExternal, its returned byte-upload URL and files.completeUploadExternal.

Publishing and catalog process: the public publisher guide. Standing is the Protocol 3 grade and score-pack report, recorded after the whole slate is written. No result here asserts that the final walk or independent review has run.

Dub priority support can create a channel and send a recipient-specific Slack Connect email invitation. The stored pending invitation is read through conversations.listConnectInvites with count/cursor pagination and retained in the local mail outbox. Receiving-workspace acceptance, approval, user-id recipients and join links are outside this workflow; the twin sends no real invitation mail. Targeted invitation responses disclose no shareable URL.

Set up this release

The example uses Slack 3.0.8. Keep its dependency pins when following it.

For a complete example, follow Workplace agent handoff. It includes the application code and its own exact dependency pins.

Use Node 22.6 or newer. Install this exact starter cohort in your app folder:

npm install --save-dev --save-exact @volter/world@3.0.158 @volter/world-core@3.0.148 @volter/world-runtime@3.0.156 @volter/world-console@3.0.149 @volter/twin-slack@3.0.8

In your app’s folder, initialize a World with this implementation:

./node_modules/.bin/volter world init --name my-app --twins slack --source slack=@volter/twin-slack

Review the detected vendor and retain the generated bindings. The slack service’s source must select this version:

{
  "source": {
    "package": "@volter/twin-slack",
    "version": "3.0.8"
  }
}

This is the source field, not a complete config. Keep the installed version, lockfile and generated service source in agreement. Use the release README for throwaway SDK credentials, seeds and limits.

The assessment records its own earlier tool versions under Measurements. This setup uses the current starter cohort.

Run your app’s own test command inside the World:

./node_modules/.bin/volter world up
./node_modules/.bin/volter world run -- npm test
./node_modules/.bin/volter world log
./node_modules/.bin/volter world down

down stops compute and retains state.

Versions and implementations

Evidence for 3.0.8

Installed first use · Passed
Installed first use
Passed
Fresh app installation
Verified
Workflow scope
Exact installed artifact; normal CLI initialization, unchanged SDK, result assertions and retained-state read-only resume where applicable
Customer SDK versions
@slack/web-api@7.19.0
CLI, kernel and runtime versions
@volter/world@3.0.147 · @volter/world-core@3.0.147 · @volter/world-runtime@3.0.147
World clock
{"mode":"wall"}
Retained-state readback
Verified
Stopped compute
Verified
Customer journey failures
0
API coverage, replay and browser measurements

Counts describe the declared HTTP surface, not separate command tables or other protocols. Consult the release README for those workflows.

Assessment scope
packaged-customer-journey; in-process
Declared HTTP surface
68 served · 179 gaps · 247 declared operations
Exercised HTTP operation coverage
59 / 247 declared operations (23.9%)
Journey steps
195 answered / 220 steps
Replay
Equal across 2 runs
Journey failures
0
Browser target
Not measured
HTTP operations exercised through Chromium
Not measured
Chromium journey replay
Not measured
Browser response observation
Not recorded
Application-origin CORS coverage
Not measured
Native cookie-jar coverage
Not measured
DOM coverage
Not measured
Source code coverage
Not measured
State transition coverage
Not measured
Operations not exercised
  • slack:admin_analytics_getFile
  • slack:admin_apps_activities_list
  • slack:admin_apps_approve
  • slack:admin_apps_approved_list
  • slack:admin_apps_config_lookup
  • slack:admin_apps_config_set
  • slack:admin_apps_requests_cancel
  • slack:admin_apps_requests_list
  • slack:admin_apps_restrict
  • slack:admin_apps_restricted_list
  • slack:admin_audit_anomaly_allow_getItem
  • slack:admin_audit_anomaly_allow_updateItem
  • slack:admin_auth_policy_assignEntities
  • slack:admin_auth_policy_getEntities
  • slack:admin_auth_policy_removeEntities
  • slack:admin_barriers_create
  • slack:admin_barriers_delete
  • slack:admin_barriers_list
  • slack:admin_barriers_update
  • slack:admin_conversations_archive
  • slack:admin_conversations_convertToPrivate
  • slack:admin_conversations_create
  • slack:admin_conversations_delete
  • slack:admin_conversations_disconnectShared
  • slack:admin_conversations_ekm_listOriginalConnectedChannelInfo
  • slack:admin_conversations_getConversationPrefs
  • slack:admin_conversations_getCustomRetention
  • slack:admin_conversations_getTeams
  • slack:admin_conversations_invite
  • slack:admin_conversations_removeCustomRetention
  • slack:admin_conversations_rename
  • slack:admin_conversations_restrictAccess_addGroup
  • slack:admin_conversations_restrictAccess_listGroups
  • slack:admin_conversations_restrictAccess_removeGroup
  • slack:admin_conversations_search
  • slack:admin_conversations_setConversationPrefs
  • slack:admin_conversations_setCustomRetention
  • slack:admin_conversations_setTeams
  • slack:admin_conversations_unarchive
  • slack:admin_emoji_add
  • slack:admin_emoji_addAlias
  • slack:admin_emoji_list
  • slack:admin_emoji_remove
  • slack:admin_emoji_rename
  • slack:admin_functions_list
  • slack:admin_functions_permissions_lookup
  • slack:admin_functions_permissions_set
  • slack:admin_inviteRequests_approve
  • slack:admin_inviteRequests_approved_list
  • slack:admin_inviteRequests_denied_list
  • slack:admin_inviteRequests_deny
  • slack:admin_inviteRequests_list
  • slack:admin_roles_addAssignments
  • slack:admin_roles_listAssignments
  • slack:admin_roles_removeAssignments
  • slack:admin_teams_admins_list
  • slack:admin_teams_create
  • slack:admin_teams_list
  • slack:admin_teams_owners_list
  • slack:admin_teams_settings_info
  • slack:admin_teams_settings_setDefaultChannels
  • slack:admin_teams_settings_setDescription
  • slack:admin_teams_settings_setDiscoverability
  • slack:admin_teams_settings_setIcon
  • slack:admin_teams_settings_setName
  • slack:admin_usergroups_addChannels
  • slack:admin_usergroups_addTeams
  • slack:admin_usergroups_listChannels
  • slack:admin_usergroups_removeChannels
  • slack:admin_users_assign
  • slack:admin_users_invite
  • slack:admin_users_list
  • slack:admin_users_remove
  • slack:admin_users_session_clearSettings
  • slack:admin_users_session_getSettings
  • slack:admin_users_session_invalidate
  • slack:admin_users_session_list
  • slack:admin_users_session_reset
  • slack:admin_users_session_resetBulk
  • slack:admin_users_session_setSettings
  • slack:admin_users_setAdmin
  • slack:admin_users_setExpiration
  • slack:admin_users_setOwner
  • slack:admin_users_setRegular
  • slack:admin_users_unsupportedVersions_export
  • slack:admin_workflows_collaborators_add
  • slack:admin_workflows_collaborators_remove
  • slack:admin_workflows_permissions_lookup
  • slack:admin_workflows_search
  • slack:admin_workflows_unpublish
  • slack:api_test
  • slack:apps_event_authorizations_list
  • slack:apps_permissions_info
  • slack:apps_permissions_request
  • slack:apps_permissions_resources_list
  • slack:apps_permissions_scopes_list
  • slack:apps_permissions_users_list
  • slack:apps_permissions_users_request
  • slack:audit_v1_actions
  • slack:audit_v1_logs
  • slack:audit_v1_schemas
  • slack:bookmarks_add
  • slack:bookmarks_edit
  • slack:bookmarks_list
  • slack:bookmarks_remove
  • slack:bots_info
  • slack:calls_add
  • slack:calls_end
  • slack:calls_info
  • slack:calls_participants_add
  • slack:calls_participants_remove
  • slack:calls_update
  • slack:canvases_access_delete
  • slack:canvases_access_set
  • slack:canvases_create
  • slack:canvases_delete
  • slack:canvases_edit
  • slack:canvases_sections_lookup
  • slack:chat_scheduledMessages_list
  • slack:conversations_canvases_create
  • slack:conversations_close
  • slack:conversations_externalInvitePermissions_set
  • slack:conversations_kick
  • slack:conversations_members
  • slack:dialog_open
  • slack:dnd_endDnd
  • slack:dnd_info
  • slack:dnd_teamInfo
  • slack:files_comments_add
  • slack:files_comments_delete
  • slack:files_comments_list
  • slack:files_info
  • slack:files_list
  • slack:files_remote_add
  • slack:files_remote_info
  • slack:files_remote_list
  • slack:files_remote_remove
  • slack:files_remote_share
  • slack:files_remote_update
  • slack:files_revokePublicURL
  • slack:files_sharedPublicURL
  • slack:files_upload
  • slack:functions_completeError
  • slack:functions_completeSuccess
  • slack:migration_exchange
  • slack:oauth_access
  • slack:oauth_token
  • slack:openid_connect_token
  • slack:openid_connect_userInfo
  • slack:pins_list
  • slack:reactions_get
  • slack:reactions_list
  • slack:reminders_add
  • slack:reminders_complete
  • slack:reminders_delete
  • slack:reminders_info
  • slack:reminders_list
  • slack:rtm_connect
  • slack:search_all
  • slack:search_files
  • slack:search_messages
  • slack:stars_add
  • slack:stars_list
  • slack:stars_remove
  • slack:team_accessLogs
  • slack:team_billableInfo
  • slack:team_integrationLogs
  • slack:team_preferences_list
  • slack:team_profile_get
  • slack:usergroups_list
  • slack:usergroups_users_list
  • slack:users_deletePhoto
  • slack:users_identity
  • slack:users_info
  • slack:users_list
  • slack:users_lookupByEmail
  • slack:users_setActive
  • slack:users_setPhoto
  • slack:views_open
  • slack:views_push
  • slack:views_update
  • slack:workflows_stepCompleted
  • slack:workflows_stepFailed
  • slack:workflows_triggers_create
  • slack:workflows_triggers_delete
  • slack:workflows_triggers_list
  • slack:workflows_triggers_update
  • slack:workflows_updateStep
Conformance results
  • decided: 0 failures · every served operation is decided with its demand; every demanded and every refreshed operation is served
  • published: 0 failures · what a release publishes holds every unit: its manifest, its spec and its journeys
  • cited: 0 failures · every vendor fact cited is recorded as a page that answered, each quote found on it
  • refresh: 0 failures · every stored resource of a vendor-backed unit declares how it is read back, and a unit that sends events ingests the vendor's
  • registered: 0 failures · a vendor-backed unit, lane or not, reaches the registered pack's state system
  • allowance: 0 failures · a rate budget above the fallback rests on the vendor's documented allowance, cited in its manifest
  • client: 0 failures · driven by the vendor's own client (its official SDK), served as a World runs it, the vendor's documented behaviour holds · 2 case(s) through the vendor's client
  • life: 0 failures · the life walked over HTTP against the pack served as a World runs it, with its scenario: every check held
  • standalone: 0 failures · served by its server.ts as a World runs it, the pack answers HTTP and the boot probe, and each declared socket upgrades
Publisher, admission and provenance
Source commit
fd9ac81c5dbce29a4c857ac72468f63b646c86a8
Catalog record commit
4a0ae5e553706a7116707dc23bf28dcbf8894fe0
Package integrity
sha512-NEJIoA0Y7rmQQ7fzP+IdjcPYpYIXeaCDLyjH4p/WkeKdj6iRoUpa7EnGPhRHp0phLaq+qB1QUrhZsvS0WcGdaA==
Admission mode
Trusted internal publisher · maintainer merge
Catalog assessment
Bundled report checksum verified
Assessed at
Not recorded
Assessment input head
53a2d3e891617f67ec533f5f7bb61a6d618b2edd

Read the catalog snapshot

Catalog snapshot · @volter/twin-catalog@0.2.62
Source commit
2d891e44624083a0ee54c058f1a566f050f38f1e
Catalog digest
72cc7d129522aaa089c84552b9d0839ab4cb0924ee7bd56ab359f827cddaa258
Installer integrity
sha512-MelxBw6h8W8k67EMu7SlYXOPwg8Z0QVcpDNKEcMzB8gH4v0JfYK2vuL7WdXNY1epjPZqxyK/5pEvDCiRqU0nAA==

Snapshot identity and measurements