Slack Integration
Audit Slack workspace security and receive threat alerts via webhook.
#Setup
Create a Slack app and bot token
api.slack.com/apps → Create New App → From scratch. Add the channels:read, channels:join, groups:read, and users:read bot scopes, install the app to your workspace, and copy the Bot User OAuth Token (xoxb-...).(Optional) Create an incoming webhook for alerts
https://hooks.slack.com/services/...). Paste it into the Webhook URL (for alerts) field when connecting.Connect in Vergate
Verify
auth.test endpoint.#Threat Alerts
When a Webhook URL is set, Slack also acts as a notification channel: monitoring threat re-scans that find new or regressed findings post a security alert to your channel. Alerts are diff-based — you only get pinged when something actually changed. Slack uses the webhook URL for alert delivery only; the bot token is never used for sending.
#What It Scans
Token validity — Does the bot token authenticate?
Token type — Is it a bot token (xoxb-) or a user token?
Channel exposure — How many public channels can the bot see?
Message access — Is the bot a member of channels it can read, or does it have unrestricted access?
xoxp-) for scanning — it exposes the user's full workspace access. Bot tokens are scoped and revocable.