Build a Slack AI Agent with nanoinfra
This guide connects nanoinfra to Slack through Socket Mode. No public webhook URL is required for the first working setup.
What this guide builds
- a Slack app with Socket Mode
- a bot token and app-level token
- the
slackchannel enabled in nanoinfra - a DM pairing flow and mention test from an approved Slack user
Prerequisites
- A working nanoinfra reply:
nanoinfra agent -m "Hello!"
- Permission to create a Slack app in a workspace.
Install nanoinfra
Quick Start ranks four install methods easiest first. This is the first of them. Use pip, Docker or a source checkout instead if you prefer, and come back here.
uv tool install nanoinfra
nanoinfra onboard --wizard
Enable the Slack channel
Install the optional channel dependency:
nanoinfra plugins enable slack
In Slack, do these steps. Create an app. Enable Socket Mode. Create an app-level token with
connections:write. Add the bot scopes. Subscribe to the bot events. Install the app to your
workspace.
Merge this snippet into ~/.nanoinfra/config.json:
{
"channels": {
"slack": {
"enabled": true,
"botToken": "xoxb-...",
"appToken": "xapp-...",
"groupPolicy": "mention",
"dm": {
"policy": "allowlist"
}
}
}
}
Slack DMs are open by default. Setting dm.policy to "allowlist" with no
dm.allowFrom entries makes new DM senders receive a pairing code. Approve the
code before using the bot normally.
Run nanoinfra gateway
nanoinfra channels status
nanoinfra gateway
Test a message
DM the Slack bot directly. It should return a pairing code. Approve that code from a trusted local surface, and not the example below:
nanoinfra agent -m "/pairing approve <the code the bot sent you>"
If you missed the code, list the pending requests:
nanoinfra agent -m "/pairing"
Then DM the bot again, or mention it in a channel:
@nanoinfra Hello from Slack
Security notes
- Keep
groupPolicyasmentionunless the bot is intentionally listening to every channel message. - Keep
dm.policyas"allowlist"when you want pairing-based approval. - Use
groupAllowFromwith allowlist mode for approved channels. - Reinstall the Slack app after changing scopes.
- Keep bot and app tokens out of committed config files.
Troubleshooting
- If Socket Mode fails, confirm the app-level token starts with
xapp-. - If the bot cannot send files, add
files:write, reinstall the app, and restart nanoinfra. - If a DM responds normally without pairing, check that
dm.policyis"allowlist". - If channel messages are ignored, check event subscriptions and group policy.