Slack Permissions API

The Permissions API from Slack — 9 operation(s) for permissions.

Documentation

Specifications

Schemas & Data

Other Resources

OpenAPI Specification

slack-permissions-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  version: '1.0'
  title: Slack Admin Access Permissions API
  description: "The Slack Admin API is a set of privileged endpoints\x14primarily under admin.* with related SCIM and Audit Logs APIs\x14that lets Enterprise Grid owners and admins automate organization\x11 wide management and governance. It covers user lifecycle (provision, suspend, assign roles), workspace and channel administration across workspaces (create, move, archive channels; manage membership and settings), app governance (approve/deny or allowlist/ban apps and install them to workspaces), invite request handling, and security/compliance controls such as information barriers, session and authentication policies, and org\x11level analytics exports. These APIs require elevated admin scopes and are commonly used to power automated onboarding/offboarding, centralized channel and app controls, and integrations with identity, ITSM, and compliance systems."
tags:
- name: Permissions
paths:
  /apps.permissions.info:
    get:
      tags:
      - Permissions
      description: Returns list of permissions this app has on a team.
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.info
      operationId: getAppsPermissionsInfo
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        schema:
          type: string
      responses:
        '200':
          description: Standard success response when used with a user token
          content:
            application/json:
              schema:
                title: apps.permissions.info schema
                required:
                - info
                - ok
                type: object
                properties:
                  info:
                    required:
                    - app_home
                    - channel
                    - group
                    - im
                    - mpim
                    - team
                    type: object
                    properties:
                      app_home:
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                      channel:
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                      group:
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                      im:
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                      mpim:
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                      team:
                        required:
                        - resources
                        - scopes
                        type: object
                        properties:
                          resources:
                            $ref: '#/components/schemas/objs_resources'
                          scopes:
                            $ref: '#/components/schemas/objs_scopes'
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                additionalProperties: false
                description: Schema for successful response from apps.permissions.info method
              example:
                info:
                  app_home:
                    resources:
                      ids:
                      - D0C0NU1Q8
                      - D0BH95DLH
                    scopes:
                    - chat:write
                    - im:history
                    - im:read
                  channel:
                    resources:
                      excluded_ids: []
                      ids:
                      - C061FA5PB
                      wildcard: false
                    scopes:
                    - channels:read
                  group:
                    resources:
                      ids: []
                    scopes: []
                  im:
                    resources:
                      ids: []
                    scopes: []
                  mpim:
                    resources:
                      ids: []
                    scopes: []
                  team:
                    resources:
                      ids: []
                    scopes: []
                ok: true
        default:
          description: Standard failure response when used with an invalid token
          content:
            application/json:
              schema:
                title: apps.permissions.info error schema
                required:
                - error
                - ok
                type: object
                properties:
                  callstack:
                    type: string
                    description: 'Note: PHP callstack is only visible in dev/qa'
                  error:
                    type: string
                    enum:
                    - not_authed
                    - invalid_auth
                    - account_inactive
                    - token_revoked
                    - no_permission
                    - org_login_required
                    - user_is_bot
                    - invalid_arg_name
                    - invalid_array_arg
                    - invalid_charset
                    - invalid_form_data
                    - invalid_post_type
                    - missing_post_type
                    - team_added_to_org
                    - invalid_json
                    - json_not_object
                    - request_timeout
                    - upgrade_required
                    - fatal_error
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: false
                description: Schema for error response from apps.permissions.info method
              example:
                error: invalid_auth
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Info
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps.permissions.request:
    get:
      tags:
      - Permissions
      description: Allows an app to request additional scopes
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.request
      operationId: getAppsPermissionsRequest
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        required: true
        schema:
          type: string
      - name: scopes
        in: query
        description: A comma separated list of scopes to request for
        required: true
        schema:
          type: string
      - name: trigger_id
        in: query
        description: Token used to trigger the permissions API
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Standard success response when used with a user token
          content:
            application/json:
              schema:
                title: apps.permissions.request schema
                required:
                - ok
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                additionalProperties: false
                description: Schema for successful response from apps.permissions.request method
              example:
                ok: true
        default:
          description: Standard failure response when trigger_id is invalid
          content:
            application/json:
              schema:
                title: apps.permissions.request error schema
                required:
                - error
                - ok
                type: object
                properties:
                  callstack:
                    type: string
                    description: 'Note: PHP callstack is only visible in dev/qa'
                  error:
                    type: string
                    enum:
                    - invalid_trigger
                    - trigger_exchanged
                    - invalid_scope
                    - invalid_user
                    - not_authed
                    - invalid_auth
                    - account_inactive
                    - token_revoked
                    - no_permission
                    - org_login_required
                    - user_is_bot
                    - invalid_arg_name
                    - invalid_array_arg
                    - invalid_charset
                    - invalid_form_data
                    - invalid_post_type
                    - missing_post_type
                    - team_added_to_org
                    - invalid_json
                    - json_not_object
                    - request_timeout
                    - upgrade_required
                    - fatal_error
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: false
                description: Schema for error response from apps.permissions.request method
              example:
                error: invalid_trigger_id
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Request
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps.permissions.resources.list:
    get:
      tags:
      - Permissions
      description: Returns list of resource grants this app has on a team.
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.resources.list
      operationId: getAppsPermissionsResourcesList
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        required: true
        schema:
          type: string
      - name: cursor
        in: query
        description: Paginate through collections of data by setting the `cursor` parameter to a `next_cursor` attribute returned by a previous request's `response_metadata`. Default value fetches the first "page" of the collection. See [pagination](/docs/pagination) for more detail.
        schema:
          type: string
      - name: limit
        in: query
        description: The maximum number of items to return.
        schema:
          type: integer
      responses:
        '200':
          description: Typical successful paginated response
          content:
            application/json:
              schema:
                title: apps.permissions.resources.list success schema
                required:
                - ok
                - resources
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                  resources:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          title: An ID for a resource
                          type: string
                        type:
                          title: The type of resource the `id` corresponds to
                          type: string
                  response_metadata:
                    type: object
                    additionalProperties: false
                additionalProperties: true
                description: Schema for successful response apps.permissions.resources.list method
              example:
                ok: true
                resources:
                - id: T0DES3UAN
                  type: team
                - id: D024BFF1M
                  type: app_home
                - id: C024BE91L
                  type: channel
                response_metadata:
                  next_cursor: dGVhbTpDMUg5UkVTR0w=
        default:
          description: Typical error response
          content:
            application/json:
              schema:
                title: apps.permissions.resources.list error schema
                required:
                - error
                - ok
                type: object
                properties:
                  callstack:
                    type: string
                    description: 'Note: PHP callstack is only visible in dev/qa'
                  error:
                    type: string
                    enum:
                    - invalid_cursor
                    - not_authed
                    - invalid_auth
                    - account_inactive
                    - token_revoked
                    - no_permission
                    - org_login_required
                    - user_is_bot
                    - invalid_arg_name
                    - invalid_array_arg
                    - invalid_charset
                    - invalid_form_data
                    - invalid_post_type
                    - missing_post_type
                    - team_added_to_org
                    - invalid_json
                    - json_not_object
                    - request_timeout
                    - upgrade_required
                    - fatal_error
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: false
                description: Schema for error response from apps.permissions.resources.list method
              example:
                error: invalid_cursor
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Resources List
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps.permissions.scopes.list:
    get:
      tags:
      - Permissions
      description: Returns list of scopes this app has on a team.
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.scopes.list
      operationId: getAppsPermissionsScopesList
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Typical successful paginated response
          content:
            application/json:
              schema:
                title: api.permissions.scopes.list success schema
                required:
                - ok
                - scopes
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                  scopes:
                    type: object
                    additionalProperties: true
                additionalProperties: true
                description: Schema for successful response api.permissions.scopes.list method
              example:
                ok: true
                scopes:
                  app_home:
                  - chat:write
                  - im:history
                  - im:read
                  channel:
                  - channels:history
                  - chat:write
                  group:
                  - chat:write
                  im:
                  - chat:write
                  mpim:
                  - chat:write
                  team:
                  - users:read
                  user: []
        default:
          description: Typical error response
          content:
            application/json:
              schema:
                title: apps.permissions.scopes.list error schema
                required:
                - error
                - ok
                type: object
                properties:
                  callstack:
                    type: string
                    description: 'Note: PHP callstack is only visible in dev/qa'
                  error:
                    type: string
                    enum:
                    - not_authed
                    - invalid_auth
                    - account_inactive
                    - token_revoked
                    - no_permission
                    - org_login_required
                    - user_is_bot
                    - invalid_arg_name
                    - invalid_array_arg
                    - invalid_charset
                    - invalid_form_data
                    - invalid_post_type
                    - missing_post_type
                    - team_added_to_org
                    - invalid_json
                    - json_not_object
                    - request_timeout
                    - upgrade_required
                    - fatal_error
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: false
                description: Schema for error response from apps.permissions.scopes.list method
              example:
                error: invalid_auth
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Scopes List
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps.permissions.users.list:
    get:
      tags:
      - Permissions
      description: Returns list of user grants and corresponding scopes this app has on a team.
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.users.list
      operationId: getAppsPermissionsUsersList
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        required: true
        schema:
          type: string
      - name: cursor
        in: query
        description: Paginate through collections of data by setting the `cursor` parameter to a `next_cursor` attribute returned by a previous request's `response_metadata`. Default value fetches the first "page" of the collection. See [pagination](/docs/pagination) for more detail.
        schema:
          type: string
      - name: limit
        in: query
        description: The maximum number of items to return.
        schema:
          type: integer
      responses:
        '200':
          description: Typical successful paginated response
          content:
            application/json:
              schema:
                title: Default success template
                required:
                - ok
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                additionalProperties: true
                description: This method either only returns a brief _OK_ response or a verbose schema is not available for this method.
              example:
                ok: true
                resources:
                - id: U0DES3UAN
                  scopes:
                  - dnd:write:user
                  - reminders:write:user
                - id: U024BFF1M
                  scopes:
                  - reminders:write:user
                response_metadata:
                  next_cursor: dGVhbTdPMUg5UkFTT0w=
        default:
          description: Typical error response
          content:
            application/json:
              schema:
                title: Default error template
                required:
                - ok
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: true
                description: This method either only returns a brief _not OK_ response or a verbose schema is not available for this method.
              example:
                error: invalid_cursor
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Users List
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /apps.permissions.users.request:
    get:
      tags:
      - Permissions
      description: Enables an app to trigger a permissions modal to grant an app access to a user access scope.
      externalDocs:
        description: API method documentation
        url: https://api.slack.com/methods/apps.permissions.users.request
      operationId: getAppsPermissionsUsersRequest
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `none`'
        required: true
        schema:
          type: string
      - name: scopes
        in: query
        description: A comma separated list of user scopes to request for
        required: true
        schema:
          type: string
      - name: trigger_id
        in: query
        description: Token used to trigger the request
        required: true
        schema:
          type: string
      - name: user
        in: query
        description: The user this scope is being requested for
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Standard success response when used with a user token
          content:
            application/json:
              schema:
                title: Default success template
                required:
                - ok
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_true'
                additionalProperties: true
                description: This method either only returns a brief _OK_ response or a verbose schema is not available for this method.
              example:
                ok: true
        default:
          description: Standard failure response when trigger_id is invalid
          content:
            application/json:
              schema:
                title: Default error template
                required:
                - ok
                type: object
                properties:
                  ok:
                    $ref: '#/components/schemas/defs_ok_false'
                additionalProperties: true
                description: This method either only returns a brief _not OK_ response or a verbose schema is not available for this method.
              example:
                error: invalid_trigger_id
                ok: false
      security:
      - slackAuth:
        - none
      summary: Slack Get Apps Permissions Users Request
      x-api-evangelist-processing:
        GenerateOperationSummariesFromPath: true
        PascalCaseOperationSummaries: true
        CaselCaseOperationIds: true
        ChooseTags: true
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /functions.distributions.permissions.add:
    post:
      tags:
      - Permissions
      summary: Add Function Distribution Permissions
      description: Adds permissions for distributing a custom function to additional users or workspaces.
      operationId: postFunctionsDistributionsPermissionsAdd
      parameters:
      - name: token
        in: header
        description: 'Authentication token. Requires scope: `functions:write`'
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              required:
              - function_app_id
              - permission_type
              type: object
              properties:
                function_app_id:
                  type: string
                  description: ID of the function app.
                permission_type:
                  type: string
                  description: Type of permission to grant (named_entities, everyone).
                user_ids:
                  type: string
                  description: Comma-separated list of user IDs to grant access to.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
              example:
                ok: true
        default:
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                  error:
                    type: string
              example:
                ok: false
                error: invalid_auth
      security:
      - slackAuth:
        - functions:write
  /functions.distributions.permissions.list:
    get:
      tags:
      - Permissions
      summary: List Function Distribution Permissions
      description: Lists the distribution permissions for a custom function.
      operationId: getFunctionsDistributionsPermissionsList
      parameters:
      - name: token
        in: query
        description: 'Authentication token. Requires scope: `functions:read`'
        required: true
        schema:
          type: string
      - name: function_app_id
        in: query
        description: ID of the function app.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                  permission_type:
                    type: string
                  user_ids:
                    type: array
                    items:
                      type: string
              example:
                ok: true
                permission_type: named_entities
                user_ids:
                - U123ABC
        default:
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                  error:
                    type: string
              example:
                ok: false
                error: invalid_auth
      security:
      - slackAuth:
        - functions:read
  /functions.distributions.permissions.remove:
    post:
      tags:
      - Permissions
      summary: Remove Function Distribution Permissions
      description: Removes distribution permissions for a custom function from users or workspaces.
      operationId: postFunctionsDistributionsPermissionsRemove
      parameters:
      - name: token
        in: header
        description: 'Authentication token. Requires scope: `functions:write`'
        required: true
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              required:
              - function_app_id
              type: object
              properties:
                function_app_id:
                  type: string
                  description: ID of the function app.
                user_ids:
                  type: string
                  description: Comma-separated list of user IDs to remove access from.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
              example:
                ok: true
        default:
          description: Error response
          content:
            application/json:
              schema:
                type: object
                properties:
                  ok:
                    type: boolean
                  error:
                    type: string
              example:
                ok: false
                error: invalid_auth
      security:
      - slackAuth:
        - functions:write