Skip to content

feat: add app_level_token_rotation_enabled setting to app manifest - #682

Merged
mwbrooks merged 1 commit into
mainfrom
app-level-token-rotation
Oct 2, 2026
Merged

mwbrooks merged 1 commit into
mainfrom
app-level-token-rotation

Conversation

@zimeg

@zimeg zimeg commented Oct 1, 2026

Copy link
Copy Markdown
Member

Changelog

Add support for the settings.app_level_token_rotation_enabled: <bool> manifest property to opt in to rotating app-level tokens.

Summary

This pull request adds the settings.app_level_token_rotation_enabled boolean field to the AppSettings manifest type.

  • Apps that opt in get rotating app-level tokens (xoxe.xapp-) that expire after 12 hours and come with a single-use refresh token
  • Adds the field to the typed manifest so it's handled like the other boolean settings, such as token_rotation_enabled

Preview

N/A

Testing

# Create a new app
$ slack create

# Update the manifest.json with `settings.app_level_token_rotation_enabled: true`
$ vim manifest.json

# Install the app
$ slack install

# Confirm rotation is enabled
$ slack app settings
# → Select "Basic Information" and scroll to "App-Level Tokens"
# → Confirm token rotation is enabled

Notes

Follows the existing *bool + omitempty pattern used by token_rotation_enabled and is_mcp_enabled (#513). gofmt realigned the AppSettings struct tags since the new field name is the longest.

Companion schema change: slackapi/manifest-schema#90.

Requirements

🤖 Generated with Claude Code

Co-Authored-By: Claude <svc-devxp-claude@slack-corp.com>
@zimeg zimeg added enhancement M-T: A feature request for new functionality changelog Use on updates to be included in the release notes semver:minor Use on pull requests to describe the release version increment labels Oct 1, 2026
@zimeg zimeg self-assigned this Oct 1, 2026
@zimeg zimeg added this to the Next Release milestone Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 78.22%. Comparing base (20dd730) to head (1c0c562).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #682      +/-   ##
==========================================
- Coverage   78.23%   78.22%   -0.01%     
==========================================
  Files         239      239              
  Lines       18149    18149              
==========================================
- Hits        14198    14197       -1     
- Misses       3951     3952       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@zimeg
zimeg marked this pull request as ready for review October 1, 2026 21:50
@zimeg
zimeg requested a review from a team as a code owner October 1, 2026 21:50

@mwbrooks mwbrooks left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Thanks for getting ahead of this one! 🙇🏻

@mwbrooks
mwbrooks merged commit e70c8bc into main Oct 2, 2026
13 checks passed
@mwbrooks
mwbrooks deleted the app-level-token-rotation branch October 2, 2026 21:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

changelog Use on updates to be included in the release notes enhancement M-T: A feature request for new functionality semver:minor Use on pull requests to describe the release version increment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants