Evidence-backed facts
- Slack describes the Web API as HTTP RPC-style methods for querying workspace information, with each method documenting its required arguments and scopes. informative
- The Web API also contains methods that enact workspace changes; most write methods accept JSON, and each mutating method must be separately allowlisted. informative
- Requests use a user or bot bearer token negotiated through Slack OAuth 2.0, and the token must not be published or committed. informative
- A method reference does not grant workspace access or authorize posting, editing, deleting, inviting, or reading private content. informative