Slack Link Unfurling for App-Owned Domains Prompt
Design and implement custom link unfurls so internal tool URLs render as rich Block Kit attachments in Slack
- Target user
- engineers building Slack ChatOps and bots
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior platform engineer who builds Slack apps and owns the company's internal-tooling unfurl experience. I will provide: - The domains and URL patterns I want my app to unfurl (e.g. dashboards, runbooks, incidents) - The data available behind each URL (fields, auth model, latency) and any per-user access rules - My current Slack app scopes, event subscriptions, and hosting/runtime details Your job: 1. **Scope and event wiring** — confirm `links:read` / `links:write`, the App Unfurl Domains config, and the `link_shared` event subscription, and flag anything missing or misconfigured. 2. **Unfurl matching** — design the URL-pattern parser that maps each shared link to a content type, rejecting non-matching or spoofed hosts before any fetch. 3. **Authorization model** — specify how to resolve the *sharing user's* permission to the target resource so unfurls never leak data the user cannot see; default to a minimal "no preview / locked" card on denial. 4. **Block Kit design** — produce the unfurl block payload per content type (header, key fields, context, action buttons), keeping within size limits and degrading gracefully when upstream data is partial. 5. **chat.unfurl call and idempotency** — show the `chat.unfurl` request shape keyed by `channel` + `message_ts`, and how to debounce duplicate `link_shared` events. 6. **Failure and latency handling** — define timeouts, fallbacks, and caching so a slow or down backend never blocks the Slack 3-second-friendly response. 7. **Rollout and verification** — give a test plan covering authorized, unauthorized, expired, and malformed links. Output as: a numbered implementation spec, an annotated example `chat.unfurl` payload, and a test matrix table (link type x user permission x expected card). Do not fetch target resources before verifying the sharing user's access, and never embed secrets or signed URLs in unfurl blocks.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Slack Block Kit Modal Input Validation & Error Display Prompt
Design server-side validation for Block Kit modals — response_action errors, per-input error keying, cross-field rules, and re-render UX that never loses user input.
-
Slack Live Progress Bar with chat.update Prompt
Render a single self-updating Slack message that shows live progress for a long-running deploy or job, using chat.update against a stored ts instead of spamming the channel with per-step posts.
-
Slack Block Kit Rich Text Input Composer Prompt
Capture and round-trip formatted user input using the rich_text_input block and rich_text element trees
-
Slack External Select Dynamic Options Menus Prompt
Implement external data source select menus in Block Kit that load type-ahead options from your backend at interaction time
More Slack prompts & error guides
Browse every Slack prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.