0082 — LINE: an Official Account of your own, through the public door
Status: accepted · 2026-10-04
- Status: accepted
- Date: 2026-10-04
- Amends: ADR 0045 (the public door serves one more app)
Context
LINE is the chat app most people use in Japan, Taiwan and Thailand. OpenClaw and Hermes Agent both reach it. What the Messaging API offers (checked 2026-10-04, developers.line.biz):
- A bot is an Official Account with the Messaging API turned on. Its channel has a channel secret and a long-lived channel access token.
- Messages are only delivered to a web address (the webhook), as JSON
signed with
x-line-signature: the base64 HMAC-SHA256 of the body with the channel secret. Each event has awebhookEventIdand a timestamp, and LINE may redeliver (deliveryContext.isRedelivery). The address can be set through the API (PUT /v2/bot/channel/webhook/endpoint); Use webhook is a switch only the console has. - Answers: a reply with the event's
replyTokenis free; a push message counts against the plan's monthly messages (429 "monthly limit" when used up). No Markdown, 5000 characters a message. Quick-reply buttons send apostback, delivered and signed like any event. A loading animation can be shown in a one-to-one chat. - Groups: a mention of the bot carries
mention.mentionees[].isSelf.
Decision
LINE is a channel like SMS (ADR 0076), in channels/line.ts: an account of
the assistant's own, through the public door (ADR 0045). The person makes the
account and pastes the channel secret and a token; Conch checks the token
(GET /v2/bot/info), opens the door, and points the webhook at it itself,
again whenever the door's address changes. The one step only a person can
take, Use webhook (and turning off LINE's own auto-responses), is its own
step in the setup.
- Nothing is read before the signature checks out, in constant time,
against the exact body. A repeated
webhookEventIdis one event, and an event more than an hour old is not read. - Answers are plain text. The first message after yours uses the free reply token while it's fresh (50 seconds), the rest are push messages. A used-up month says so on the channel's page, in plain words.
- Approvals are quick-reply buttons; a press counts only from someone let in, in the chat it was asked in. A LINE message can't be changed once sent, so a decided question just stops taking presses.
- Files come only from LINE's content host, with the token, at most 20 MB.
- Groups (ADR 0075) are answered only once you turn them on, and only when the account is @mentioned; everyone but you gets words only.
ChannelKindandChannelSecretsgainline(channelSecret,accessToken),ReplaceChannelTokenBodya token on its own, and a pretend LINE (channels/mock/line.ts) signs its webhooks as LINE does.
Security
- Who can reach it: the internet, at the door, only with a body signed with this channel's secret. Forged deliveries (another secret, none, a body changed after signing) are tested to be 401s that reach no conversation, and so are replays.
- Who may talk: nobody until you press That's me or Let in.
- Keys: the secret and the token live in the sealed
channels.secrets.json, listed in Passwords, never logged, and the token goes only to LINE's API hosts.
Consequences
- About six minutes, with one switch only the LINE console has.
- The free plan's push messages run out quickly with a chatty assistant; answers that come within a minute stay free.