VibeHost
Guides

Slack link previews

Connect Slack to get real previews for workspace and private apps. You get a card only for apps you can open yourself, and because Slack has no per-person unfurl, the whole channel sees it.

Paste a VibeHost app link in Slack and you get a preview. For a public app that has always worked: Slack's crawler fetches the page and reads its og: tags, no account needed.

For a workspace or private app, the crawler gets nothing useful. It is an anonymous visitor, and an anonymous visitor is not allowed to see your app, so all it can render is a generic "Protected by VibeHost" card.

Connecting your Slack account fixes that, by making the request no longer anonymous.

How it works

you paste a link in Slack
      ↓
Slack tells VibeHost: "user U123 in workspace T456 shared this URL"
      ↓
VibeHost looks up which VibeHost account U123 is linked to
      ↓
…and asks the ordinary question: can THAT person open this app?
      ↓
yes → a card with the app's name, description and screenshot
no  → nothing at all

No new permission is created. The card exists only because you could have opened the app yourself.

Connect your account

Go to Settings → Integrations → Connect Slack. Slack asks you to confirm who you are and then sends you back. VibeHost asks Slack only for your identity, never for permission to read messages or post as you. The preview is posted by the VibeHost bot, not by you.

Disconnect from the same page at any time. Once disconnected, links you paste stop previewing non-public apps immediately.

What the channel sees

Slack has no per-person link preview. Slack's own documentation says "everyone in a channel can see your app's unfurls", and there is no way to show a card to one person. So the permission check decides whether a card is created at all, not who can look at it.

If you paste a link to a private app in a channel, everyone in that channel sees its name, description and screenshot, including people who cannot open the app itself. VibeHost sends you a private (ephemeral) reminder when that happens, so it is never a surprise.

This is the same trade-off Notion and Google Drive make in Slack. If a preview would say more than you want the channel to know, do not paste the link there.

About the screenshot

The screenshot in the card is the same one VibeHost captures for every deployment. Slack's servers fetch images themselves, carrying no identity, so the card's image URL has to be readable without signing in.

VibeHost issues a signed URL that expires after 30 days, minted at the moment the card is sent. That has two consequences:

  • The URL is not a permanent leak. It stops working, and it was only ever created for someone who could already open the app.
  • Within that window, anyone who obtains the URL can load the image, whether or not they have access in VibeHost.

Slack does not cache the picture on its own servers. VibeHost asks it not to, so that a deleted or taken-down app stops appearing in old cards right away. The flip side is that the card's image lives exactly as long as the signed URL does. A month is short enough to limit what a leaked URL can do, and long enough that scrolling back to last week's message still shows the preview.

You can end the window early with ordinary settings changes. The signed URL is tied to the app's visibility and password as they were when the card was sent. If you change either one (make the app private, set a password, or rotate one that's already set), every card image already posted stops loading at once. Old cards keep their title and description and lose only the picture.

This also happens when you widen access, such as making a workspace app public. The old card loses its image even though the app is now more open than before. Post the link again to get a fresh card.

Nothing else changes: the crawler still gets nothing for a non-public app, and every other way of reaching a screenshot still requires the usual permissions.

Before you connect

If you have not connected your account and you paste a link to a non-public app, Slack shows only you a prompt to connect. The prompt has no name, description, or screenshot, because there is no identity yet whose permissions could justify showing them.

The prompt itself does say one thing: that the link points at a VibeHost app which is not public. That is not new information. An anonymous request to the same URL already gets a "Protected by VibeHost" page, which is what Slack's own crawler renders for it today. And you are the person who already had the link.

Previews work for links on VibeHost's app domain, the *.vibehost.space address of your app or one of its channels. Links on your own custom domain are not previewed, because Slack only sends these events for domains registered on the VibeHost Slack app.

On this page