Slack
Slack is how a REVIEW can be answered outside the Vulnify app. The connection is configured in the app, under Integrations. It is not an SDK method.
The app offers two Slack modes. They are not interchangeable on one integration. To switch modes, add another integration.
Slack app
Section titled “Slack app”The Slack app is the path that can put Approve and Deny on the message. Install it with Add to Slack (OAuth into your workspace). Only owners and admins can connect Slack.
The app can also accept a bot token (xoxb-…) instead of OAuth. Pasting a bot token can be turned off on a deployment. When it is off, the app says to use Add to Slack. The token is stored encrypted and is not shown again.
Set a channel id (C0123…) or a channel name. Invite the bot to that channel first. In Slack, /invite the app into the channel.
Approve and Deny in the message is a setting on the integration. You can leave it off and use the app for alerts only. Some deployments report that Slack buttons over HTTP are not enabled. If that is the case in your workspace, reviewers answer in the Vulnify app instead. A signature check rejects button requests that did not come from Slack.
Approving a HIGH or CRITICAL review still asks for an authenticator code when the reviewer has MFA on.
Disconnecting the Slack app revokes the bot token at Slack and stops new posts. Open messages can keep their buttons, and clicks on those buttons are refused. The integration history stays so you can reconnect.
Incoming webhook
Section titled “Incoming webhook”An incoming webhook posts alerts into the channel the webhook was created for. The URL must be https://hooks.slack.com/services/…. The app rejects other URLs.
This mode does not approve reviews. The channel field is a label for your team. An incoming webhook always posts to the channel it was created for.
An organization has one Slack incoming webhook. Open it to change the URL, the label, or which alerts it sends. Disconnecting deletes the stored URL. The webhook remains in Slack until you remove it there.
What gets posted
Section titled “What gets posted”Slack is notified about decisions. It does not receive the contents of your records. With the hosted Slack app, reviewers see enough to approve or deny the action. An incoming webhook only posts the alert. The decision and the review note stay on the Vulnify event.

