Slack

Building a Custom Slack App or Bot (and What the API Actually Gives You)

Slack's API is really three pieces working together: the Web API (methods you call to post messages, read channels, manage users), the Events API (Slack calling your app when something happens), and Block Kit (the format for interactive messages and forms). Together they're how a custom app or bot gets built for a specific business, instead of relying on whatever's already listed in Slack's public app directory.

How a custom Slack app actually gets built

You start by creating an app at api.slack.com, which generates the credentials (a bot token, scoped to exactly the permissions you request) that everything else runs on. From there, a bot lives on the Web API side, calling methods like chat.postMessage, and on the Events API side, getting notified when a user mentions it, posts in a channel it's in, or reacts to a message. Most real bots use both directions at once: react to something happening, then post or update something back.

Slash commands and interactive components (buttons, menus, forms built with Block Kit) are what let a bot feel like part of the conversation instead of a one-way notification feed. A slash command like /status-check can call out to your own backend and return an answer in seconds, right inside the channel someone's already working in. Socket Mode is worth knowing about too: it lets a bot receive events over a websocket instead of needing its own public URL, which matters for internal tools that shouldn't be exposed to the open internet.

None of this requires publishing to Slack's app directory. A private, workspace-specific app skips that review process entirely, since it's only being installed into your own workspace, not distributed to strangers. The directory review only matters if you're trying to list the app publicly for other companies to install.

Where it stops being a weekend project

Slack's API is tiered by rate limits, and the tiers are not generous for a bot doing real work: some methods allow roughly one call a minute, others a handful per second, and going over means your app starts getting throttled with no useful retry built in unless you write that logic yourself. A bot that looks up order status for every message in a busy channel can hit that ceiling faster than you'd expect.

Proactive messaging, a bot reaching out first instead of just replying, needs a stored reference to the right channel or user from an earlier interaction, and keeping that mapping accurate as people join, leave, or get added to new channels is entirely on you. Token management across a growing number of scopes, handling OAuth reinstalls when permissions change, and making the bot resilient when Slack's API has a bad day are all real engineering, not configuration.

What that looks like built out

A lookup bot that actually scales

A slash command that answers “what's the status on order 4821” against your live systems, built with real rate-limit handling and retries, so it still works correctly during your busiest hour, not just in testing.

Proactive alerts that find the right person

A bot that reaches out first when something needs attention, tracking who's actually responsible as team membership changes, instead of posting to a channel and hoping the right person happens to see it.

What would your bot actually need to do?

A slash command, a proactive alert, a form that writes back to another system. Tell us the job and we can scope what building it for real looks like.

Let's talk

Thinking about a Slack bot but not sure where the API stops helping you?

Tell us what you want the bot to do day to day, not just the demo version, and we'll tell you honestly what Slack's rate limits and token model will and won't let it do on its own. Slack bots are one example; n-frames builds whatever custom automation a business actually needs, in Slack or anywhere else it runs.

Let's talk

Frequently Asked Questions

Is the Slack API free to use?+
Yes, building and running your own app against Slack's API doesn't cost anything extra beyond your existing Slack plan. Some methods and higher rate-limit tiers are reserved for apps on paid plans or Marketplace-approved apps, but a basic custom app for internal use works on any plan.
Do I need to publish my Slack app to the app directory?+
No. A private app built for your own workspace installs directly without any directory listing or review. Publishing publicly is only necessary if you want other companies to be able to find and install it themselves.
What programming language do I need to build a Slack app?+
Any language that can make HTTP requests works, since the Web API is just REST. Slack maintains official SDKs (Bolt) for JavaScript, Python, and Java that handle a lot of the boilerplate, but plenty of custom apps are built in other languages, including Go, directly against the raw API.
What's the difference between a Slack bot token and a user token?+
A bot token (starting with xoxb) acts as the app itself and is what most automation uses. A user token (xoxp) acts on behalf of a specific person who installed the app and can do things a bot token can't, like posting messages that appear to come from that person directly.
Can a Slack bot message someone who never messaged it first?+
Yes, but it needs the right scope and a valid channel or user ID to send to. There's no way to message a user purely by name or email alone; the bot needs to have already resolved that person's Slack user ID, usually from an earlier interaction or a lookup against your own user directory.

Let's talk

Tell us the one thing your team does manually that eats up time. We read every message and reply within a day.