Skip to main content
Self-hosted LangSmith uses a Slack app that your operator creates and configures. The operator is the person who manages your LangSmith deployment. The deployment exchanges OAuth codes and sends Engine notifications and alert notifications directly to Slack. LangSmith stores the app credentials and encrypted workspace bot tokens in your deployment. If Slack is not configured on your instance, contact your operator. This notice appears in organization settings and in the Slack tab under each Engine project’s Notifications settings. The operator follows the setup instructions below. After setup, users connect a workspace through Slack authorization without supplying app credentials themselves.
This connection requires LangSmith self-hosted v0.17 or later.
Before starting, make sure you have:
  • Deployment access: Permission to configure and restart your LangSmith platform backend. For Kubernetes, access to the namespace where LangSmith runs.
  • Slack access: Permission to create and install an app in the Slack workspace that receives notifications. Obtain administrator approval if your workspace restricts app installation.
  • LangSmith access: The organization:manage permission to connect or disconnect a Slack workspace. An organization administrator can complete this step after the operator configures the deployment.
  • Network access: Backend HTTPS access to Slack and browser access to your deployment’s HTTPS callback. See Allow network access.

Create your Slack app

Your operator creates one Slack app for the deployment. An app manifest is a JSON configuration that creates the bot and sets its permissions. Users reuse this app when connecting a workspace; they do not create an app for each user or project. To create the app:
  1. Copy the JSON below and replace the URL in oauth_config.redirect_urls. For the standard ingress, append /api/v1/platform/slack/callback to the URL you use to open LangSmith. For example, https://langsmith.example.com becomes https://langsmith.example.com/api/v1/platform/slack/callback. If LangSmith runs at https://langsmith.example.com/langsmith, use https://langsmith.example.com/langsmith/api/v1/platform/slack/callback. For a custom ingress or separate API host, use the HTTPS URL that reaches your deployment’s Slack callback.
  2. Open Your Apps and select Create New App. Choose From a manifest, then click Continue.
  3. Select the JSON tab, paste your edited manifest, and choose your Slack workspace. Click Next.
  4. Review the five permissions and click Create and Install. Complete any Slack authorization or administrator approval prompts.
  5. Open the new app’s Basic Information > App Credentials. Copy the Client ID and Client Secret, using Show to reveal the secret. Store them in your deployment’s secret manager. Use the Client ID, not the App ID or Signing Secret. You do not send these credentials to LangChain.
The manifest contains configuration, not credentials. Slack generates the app credentials after creation. It configures the five bot scopes requested by self-hosted LangSmith:
  • chat:write: Send notification messages.
  • channels:read: List public channels in the channel picker.
  • channels:join: Join a selected public channel when delivering a notification, if needed.
  • groups:read: List private channels that the bot has been invited to.
  • reactions:write: Add and remove emoji reactions. Notification delivery does not currently use this permission.
Keep token rotation disabled. The integration stores bot tokens and does not refresh rotating tokens. Leave Socket Mode disabled; Event Subscriptions and an app-level token are not required for notification delivery. Creating or installing the app in Slack does not connect it to LangSmith. Complete Connect a Slack workspace after configuring the deployment. LangSmith obtains and stores the workspace bot token through that authorization flow; you do not copy a bot token into the deployment.

Configure your deployment

Configure these variables on the LangSmith platform backend using your deployment’s environment variable configuration: For Helm deployments, including deployments on EKS, configure the app credentials through platformBackend.deployment.extraEnv. First, create a Kubernetes Secret in the namespace where LangSmith runs. If you use a secrets operator, provision slack-app-credentials with keys client-id and client-secret through that operator. To create it manually, save the following as slack-app-secret.yaml, replacing all three placeholders. Keep the file containing credentials out of version control.
Apply the Secret:
Next, merge these entries into your existing Helm values file. Keep any existing platformBackend.deployment.extraEnv entries. Replace the callback URL with the same URL used in your manifest:
The chart sets LANGSMITH_URL from its hostname configuration. Configure config.hostname, config.frontendHostname if the UI uses a separate host, and config.basePath as needed. Avoid adding a duplicate LANGSMITH_URL through extraEnv or commonEnv. Apply the updated values through your deployment process. If you manage Helm directly, use your existing release name, namespace, chart version, and complete values file:
Use a chart version that contains the supported LangSmith release. For upgrade prerequisites, see Upgrade a self-hosted deployment. Keep the existing API_KEY_SALT encryption secret consistent between the API and notification workers. They use it to encrypt and decrypt stored bot tokens. See Use an existing secret. Wait for the platform backend rollout to complete, then reload LangSmith. If you changed a Secret without changing the Helm values, restart the platform backend so it loads the new credentials. Under your organization’s General settings, the Slack section shows Connect Slack when configuration is complete. The backend checks that the app credentials are present and the callback URL is valid. Slack verifies the credentials during authorization. Incorrect credentials can still show Connect Slack, then fail when you try to connect. Changing or removing app credentials does not delete stored workspace connections or notification destinations. Previously stored bot tokens can continue delivering notifications. To stop delivery, disconnect the workspace or delete its notification destinations.

Allow network access

For this integration, allow the following connections:
  • Backend: Outbound HTTPS to the Slack Web API at slack.com for OAuth exchange, channel lookup, and notifications.
  • Browser: Access to Slack and your deployment’s callback URL and UI.
Slack redirects the browser to your callback. Slack does not need inbound network access to your deployment for notification delivery.

Connect a Slack workspace

A Slack workspace connection belongs to your LangSmith organization, so you can reuse it across projects:
  1. Open your LangSmith instance and go to Settings > your organization’s General settings.
  2. Under Slack, click Connect Slack. You can also connect from the channel selector when configuring an Engine or alert notification.
  3. Choose the Slack workspace, review your app’s requested permissions, and click Allow. Complete administrator approval if required.
  4. Confirm that the browser returns to your LangSmith instance and the workspace appears as Connected. Choose that workspace and a channel in your notification settings. For a private channel, invite your configured Slack app to the channel first, then refresh the picker. LangSmith joins the selected public channel when it first delivers a message, if needed.
  5. Save the destination with the event types and minimum issue severity you need. See Configure Engine notifications or Configure alert notifications.

Verify delivery

Saving a destination does not send a test message. An Engine destination sends notifications for new events that match its event types and minimum issue severity. Existing issues do not emit a new notification when you save the destination. To verify an Engine destination:
  1. Save a Slack destination for issue.created on a test project. Under Notify when, select Issue created. Set Minimum issue severity to All severities during testing.
  2. Enable Engine for the test project and let it analyze new traces. Wait for Engine to create a new issue. If Engine finds no new issue, there is no issue.created notification to send.
  3. Check that a message arrives in the selected channel and that View issue opens your self-hosted instance.
To verify Slack delivery without waiting for a new Engine issue, configure a Slack destination in a test project’s alert settings. Click Send Test Notification and check the selected channel. See Test the alert integration. This checks the Slack connection, not Engine’s event generation. Slack notifications send content outside your deployment to the selected workspace. Engine messages can include issue titles, descriptions, severity, project information, links, and recurrence charts. Alert messages include alert and workspace names, metric values, thresholds, and links. Choose channels with access appropriate for that content. See Engine notification format and Alert notification format.

Troubleshoot the connection

  • Slack is not configured: Contact your operator. Confirm that your release supports the connection and all three Slack environment variables are set. Reload the UI after restarting the backend.
  • Slack configuration unavailable: The UI could not load the backend’s configuration. Reload the page and have your operator check the backend; this message does not mean app credentials are absent.
  • The backend pod cannot start: Check that slack-app-credentials exists in the same namespace as LangSmith and contains both client-id and client-secret.
  • Slack rejects the app credentials: Copy the Client ID and Client Secret from the same Slack app. Update the deployment Secret, restart the platform backend, and start Connect Slack again.
  • Authorization cannot start: Confirm that the app has a bot user, all listed scopes, and permission to install in the selected workspace.
  • Slack reports a redirect mismatch: Ensure LANGSMITH_SLACK_REDIRECT_URI matches the saved Slack Redirect URL, including scheme, host, port, and path.
  • Authorization fails after returning: Start Connect Slack again. Authorization state expires after 10 minutes. Check browser access to the callback, backend access to Slack, and the configured app credentials. Keep token rotation disabled.
  • A private channel is absent: Invite your configured Slack app to the channel, then refresh the picker.
  • Messages do not arrive: Confirm Slack Web API access, matching encryption secrets on the API and workers, and the destination’s event and severity filters. If someone removed the app from Slack, reconnect the workspace.
  • Links open the wrong host: Correct your deployment’s browser-facing URL configuration.

See also