关于Slack API OAuth流程文档不一致及移动端client_secret安全的问询
Great question—this is a super common pain point when building mobile apps with Slack's OAuth flow, and the core issue here is that the direct oauth.access call is designed for server-side applications, not client-side/mobile apps where you can't safely store sensitive credentials. Here's how to fix it:
The Root of the Conflict
Slack's oauth.access method requires a client_secret because it's part of the standard OAuth 2.0 Authorization Code Flow, which assumes you have a secure backend to handle sensitive credentials. Mobile apps can't safely store client_secret—anyone could decompile your app, extract it, and use it to impersonate your application, which is exactly what Slack's OAuth safety guidelines warn against.
The Solution: Use a Backend Proxy
The only secure way to resolve this is to route the token exchange through your own backend server. Here's the step-by-step flow:
- Mobile app initiates OAuth: Your mobile app sends the user to Slack's authorization page (using your
client_idand desired scopes). - Slack returns authorization code: Once the user approves, Slack sends an authorization
codeto your app (via a custom URL scheme or universal link). - Mobile sends code to your backend: Instead of calling
oauth.accessdirectly, your app sends thiscodeto your own backend API over HTTPS. - Backend handles token exchange: Your backend uses the received
code, plus yourclient_idandclient_secret(stored securely on the server), to call Slack'soauth.accessendpoint. - Backend returns tokens to mobile: After receiving the Slack access/refresh tokens, your backend can either send them directly to the mobile app (with proper encryption) or store them in your database and provide the mobile app with a secure session token to access Slack resources via your backend APIs.
Additional Safety Tips
- Never expose
client_secretto the client: Even in obfuscated form, mobile apps aren't a safe place for secrets—stick to storing it only on your backend. - Secure backend-client communication: Always use HTTPS for all API calls between your mobile app and backend to prevent man-in-the-middle attacks.
- Validate requests on the backend: Add checks to ensure the
codecoming from your mobile app is legitimate (e.g., associate it with a user session, verify the state parameter from the initial OAuth request). - Use refresh tokens securely: If your backend stores refresh tokens, encrypt them and limit their scope to only what your app needs.
This approach aligns with both Slack's API requirements and their security guidelines, keeping your client_secret safe while still enabling your mobile app to integrate with Slack.
内容的提问来源于stack exchange,提问作者Lee

