Interested in beta testing pebl? I'm looking for early testers. Sign up here →
← Back to connect
Slack admin approval

Get pebl approved at work

Some Slack workspaces ask an admin to approve new apps. This page has everything your admin needs to say yes.

1. Send your admin a note

When you click Add to Slack, Slack lets you send an install request to your workspace admins with a message. Paste this in, or send it to your admin directly:

I'd like to install pebl, a small e-paper display that shows emoji reactions to my Slack messages on my desk. It only reads reaction metadata (which emoji, who reacted, which channel), never message content unless I opt in. Details for admins: https://pebl.ink/slack-approval

Once an admin approves pebl, Slack notifies you. Then go back to the connect page and click Add to Slack again to finish.

For workspace admins

What pebl is

pebl is a small e-paper display that sits on someone's desk and shows emoji reactions to their own Slack messages as they happen. Each person installs it for themselves; it doesn't post messages, join channels or act on anyone's behalf.

Permissions requested

The standard install asks only for these read-only scopes. No message history scopes, no write scopes.

ScopeTypeWhy
channels:readUserShow the name of the public channel a reaction happened in.
groups:readUserShow the name of the private channel a reaction happened in.
im:readUserRecognize reactions in direct messages.
mpim:readUserRecognize reactions in group direct messages.
emoji:readBotDraw your workspace's custom emoji on the display.
users:readBotShow who reacted.

Optional: Message Previews

Off by default. If the person turns on Message Previews later, Slack asks for these additional scopes. They only reach the specific message that received a reaction, not channel history.

ScopeTypeWhy
reactions:readUserFetch a short snippet of the one message that was reacted to.
users:readUserShow names of people from other organizations in Slack Connect channels.

What data pebl keeps

  • By default, reaction metadata only: which emoji, who reacted, which channel and when. No message content.
  • With Message Previews on: a short, sanitized snippet of the reacted message, encrypted at rest and deleted within 24 hours.
  • Slack tokens are encrypted at rest, rotated automatically, and deleted after 365 days of inactivity.
  • Uninstalling pebl from Slack deletes the user's data within 14 business days, or immediately on request to support@pebl.ink.

Full details are in the privacy policy.

Security

  • Every request from Slack is verified with Slack's signing secret and a 5-minute timestamp window.
  • The install flow is protected against forged requests with a one-time state value.
  • All traffic uses HTTPS. Reaction data sent to the display is additionally encrypted for that device.
  • Device firmware updates are cryptographically signed and verified before install.
  • The device software is open source: ESP32 firmware and Raspberry Pi client.

How to approve

Open the request from the Slack notification and choose Approve. You can also pre-approve pebl so other members can install it without asking. Slack's guides: manage app requests and manage app approval.

Questions?

pebl is built and run by one developer, and I answer every email personally. If your security team has a questionnaire or needs more detail, write to support@pebl.ink.