line-notification-message — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited line-notification-message (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Do not answer LINE Notification Messages questions from memory — LINE updates APIs frequently and training data is unreliable. Always consult the references below.
LINE Notification Messages allow sending messages to users by specifying their phone number (SHA256-hashed E.164 format), even if they haven't added the LINE Official Account as a friend. Corporate-only service available in Japan, Thailand, and Taiwan. Not for advertising or commercial purposes.
LINE_CHANNEL_ACCESS_TOKEN=Bot access token (Messaging API channel)
LINE_CHANNEL_SECRET=Channel secret (webhook signature verification)Read [references/api-common.md](references/api-common.md) before writing any notification message code. Contains rules that affect all API interactions: forward compatibility (don't use strict schemas — LINE adds fields without notice), rate limits, error handling, and logging recommendations.
| Type | Description | UX Review | Send Endpoint |
|---|---|---|---|
| Template | Predefined layout with templateKey, itemKey, buttonKey. Easy to set up. | Not required | POST /v2/bot/message/pnp/templated/push |
| Flexible | Free-form message objects (Flex Message, text, etc.). Greater design freedom. | Required | POST /bot/pnp/push |
Full type comparison → [references/sending-api.md](references/sending-api.md)
# 1. Hash phone number (E.164 → SHA256)
phone = "+818000001234" # E.164 format, no hyphens
hashed = SHA256(phone.encode()).hexdigest() # 64-char lowercase hex
# 2a. Send via template type
POST https://api.line.me/v2/bot/message/pnp/templated/push
Authorization: Bearer {channel_access_token}
X-Line-Delivery-Tag: {optional_tracking_tag}
{
"to": hashed,
"templateKey": "shipment_completed_ja",
"body": {
"emphasizedItem": {"itemKey": "date_002_ja", "content": "August 10"},
"items": [{"itemKey": "number_001_ja", "content": "1234567"}],
"buttons": [{"buttonKey": "contact_ja", "url": "https://example.com"}]
}
}
# → Response: 202 Accepted
# 2b. OR send via flexible type
POST https://api.line.me/bot/pnp/push
Authorization: Bearer {channel_access_token}
{
"to": hashed,
"messages": [{"type": "text", "text": "Your order has shipped"}]
}
# → Response: 200 OK
# 3. IMPORTANT: 200/202 does NOT guarantee delivery
# User may be blocked, consent not given, SMS auth expired, etc.
# 4. Delivery confirmation arrives via webhook
# event.type = "delivery", delivery.data = hashed phone or delivery tag| Operation | Endpoint | Response |
|---|---|---|
| Send (Template) | POST /v2/bot/message/pnp/templated/push | 202 |
| Send (Flexible) | POST /bot/pnp/push | 200 |
| Count (Template) | GET /v2/bot/message/delivery/pnp/templated?date=yyyyMMdd | 200 |
| Count (Flexible) | GET /v2/bot/message/delivery/pnp?date=yyyyMMdd | 200 |
api.line.meX-Line-Retry-Key is NOT supported — do not use retry keysFull API specs, parameters, error codes → [references/sending-api.md](references/sending-api.md)
+818000001234hashlib.sha256("+818000001234".encode()).hexdigest()| State | Behavior |
|---|---|
| Agree (on) | Message delivered normally |
| Reject (off) | Message deleted, not delivered |
| Not set | User receives consent prompt; 24 hours to agree or message is deleted |
200/202 does NOT guarantee deliverytype: "delivery") to confirm actual deliveryFull technical specs → [references/technical-specs.md](references/technical-specs.md) Template system details → [references/template-system.md](references/template-system.md) Webhook details → [references/delivery-webhook.md](references/delivery-webhook.md)
| File | Topic |
|---|---|
| references/api-common.md | Read first. Rate limits, status codes, error handling, forward compatibility |
| references/sending-api.md | Send APIs (template + flexible), count APIs, request/response specs, error codes |
| references/template-system.md | Template structure: templateKey, itemKey, buttonKey, field limits, country suffixes |
| references/technical-specs.md | Phone hashing, sending conditions, consent flow, SMS auth, billing, IP restrictions |
| references/delivery-webhook.md | Delivery completion event, X-Line-Delivery-Tag, user consent flows, non-friend behavior |
| references/experts.md | LINE Notification Messages domain experts for architecture guidance |
Official SDKs: Python | Node.js | Go | Java | PHP | Ruby
Other languages: use LINE OpenAPI specs with OpenAPI Generator.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.