Slack MCP Server

Slack's hosted MCP server. The endpoint, the app-identity rules that decide who may connect, the OAuth flow and the user-token scopes behind each tool, read from the Slack developer documentation on 2 September 2026.

Interactive examples · No account is connected on this page

Updated

Slack MCP server is Slack's own Model Context Protocol endpoint at https://mcp.slack.com/mcp. It speaks JSON-RPC 2.0 over Streamable HTTP, and its tools search messages, files, users and channels, read channels and threads, send messages, manage canvases and lists, and upload files. Slack supports neither SSE nor Dynamic Client Registration, so every client has to be backed by a registered Slack app.

Try a Slack MCP task

Pick an example to see which Slack MCP tools a task would call and what the result looks like. Examples are illustrative; nothing on this page connects to Slack.

Slack

Connect to the Slack MCP server

Slack's MCP server lives at https://mcp.slack.com/mcp and speaks JSON-RPC 2.0 over Streamable HTTP only. Every client must be backed by a registered Slack app with a fixed app ID, so the simplest route is a partner client: Claude.ai, Claude Code, Perplexity or Cursor. Your own client needs confidential OAuth and only the user-token scopes its tools require.

Read the access rule before you write any config

This is the step that catches people out. Slack's documentation says MCP clients must be backed by a registered Slack app with a fixed app ID, and that the client has to hardcode that ID. Only directory-published apps or internal apps may use MCP; unlisted apps are prohibited. That is what lets workspace admins approve and manage the client through the normal Slack app approval process.

https://mcp.slack.com/mcp

Use a partner client if you are not building an app

Slack lists four clients where the server is already available with no coding: Claude.ai, Claude Code, Perplexity and Cursor. Each of those ships its own registered Slack app, so you connect from inside the client and approve it in your workspace. This is the shortest path, and the only one that does not require you to run through Slack app registration yourself.

https://claude.ai
https://code.claude.com
https://perplexity.ai
https://cursor.com

Point your own client at the endpoint

All requests go to one URL over Streamable HTTP. The documentation is explicit that SSE-based connections are not supported at this time, so a client that can only speak SSE cannot connect. Dynamic Client Registration is not supported either, which is why the fixed app ID above matters.

https://mcp.slack.com/mcp

Set up confidential OAuth

Slack supports confidential OAuth for MCP clients, using your app's client_id and client_secret. If your client implements OAuth 2.0 Authorization Server Metadata (RFC 8414), it can discover everything from the two well-known documents Slack publishes. PKCE support is available for desktop clients.

https://mcp.slack.com/.well-known/oauth-protected-resource
https://mcp.slack.com/.well-known/oauth-authorization-server

Authorize: https://slack.com/oauth/v2_user/authorize
Token:     https://slack.com/api/oauth.v2.user.access

Request only the user-token scopes your tools need

Scopes are granted per tool, not per server, so a read-only integration never has to ask for write access. Search needs search:read.public plus the private, mpim and im variants for those conversation types. Reading channels and threads needs the four history scopes. Sending needs chat:write, reactions need reactions:write, canvases need canvases:read and canvases:write, lists need lists:read and lists:write, and uploads need files:write.

search:read.public  search:read.private  search:read.mpim  search:read.im
channels:history  groups:history  mpim:history  im:history
chat:write  reactions:write  files:read  files:write
canvases:read  canvases:write  lists:read  lists:write
users:read  users:read.email  channels:read  groups:read

Check the guardrails that apply to your workspace

Two settings can silently break a working config. If your app has allowed IP address ranges configured, requests to the MCP server are subject to the same restriction and calls from other addresses are rejected, so the client's egress addresses have to be on the list. Separately, MCP activity is recorded in Slack's audit logs, which is where to look when you need to see what an agent actually did.

Audit Logs API — actions reference, mcp-server section

Official documentation: Read the Slack MCP docs.

Two ways to reach the Slack MCP server

There are two ways to reach the Slack MCP server, and both use the same endpoint and the same admin approval. Through a partner client you build nothing, because the client vendor ships a registered Slack app and holds the OAuth credentials. Through your own Slack app you manage client_id and client_secret yourself and choose the scopes, so read-only access is achievable.

What differsThrough a partner clientThrough your own Slack app
What you buildNothing; the client ships a registered Slack appA Slack app with a fixed app ID, published to the Marketplace or internal to your workspace
Clients Slack namesClaude.ai, Claude Code, Perplexity, CursorAny MCP client you control that speaks Streamable HTTP
Endpointhttps://mcp.slack.com/mcphttps://mcp.slack.com/mcp
OAuth credentialsHeld by the client vendorYour app's client_id and client_secret; PKCE available for desktop
Who approves itWorkspace admins, through the standard Slack app approval processWorkspace admins, through the same process
Scope controlWhatever the client requestsYou choose the user-token scopes, so read-only is achievable

Endpoint, transport, app-identity rules, scope table and client list transcribed from the Slack MCP server overview at docs.slack.dev, read 2026-09-02.

What the server can do in a workspace

Inside a workspace the Slack MCP server can search messages, files, users and channels, read full channel and thread histories, send messages, create and read canvases as markdown, work with Slack lists, and upload files in a deliberate two-step flow. Rate limits are the same per-method limits as the Slack Web API.

Search across the workspace

Messages and files, filtered by date, user and content type. Users, by name with partial matching, email or user ID. Public and private channels, by name and description. Custom emoji. There is also a channel listing that returns the conversations you are a member of, filterable by type and name prefix, with pagination and archived channels included by default.

Read and send messages

Complete channel histories and complete thread conversations, sending to any conversation type, and drafting and previewing a message inside the AI client before it goes out. It can also create a channel, group DM or IM on behalf of the authenticated user, and add emoji reactions.

Canvases as markdown

Create and update Slack canvases, and read one back exported as a markdown file. That export is the practical route for getting a formatted Slack document into a model's context without screenshots.

Two-step file upload

Uploads are deliberately not a single call. Call slack_get_file_upload_url to get a signed URL and a file ID, POST the bytes to that URL, then call slack_complete_file_upload with the file ID to finalise it and optionally share it to a channel. The file is not visible until the second step completes.

Slack lists

Lists hold structured tabular data with typed columns — text, date, select, user and more. The server can create lists with custom schemas, read their contents, update list metadata and columns, and add or update individual records. Columns are addressed by display name or internal key.

Rate limits are the Web API's rate limits

Limits are enforced per tool or action type, and are the same whether the call arrives through MCP or a direct Web API method. Reading a channel or thread sits at Tier 3, searching users, channels or emoji at Tier 2, reading a user profile or listing channel members at Tier 4, while search and send-message have their own special limits.

What is the Slack MCP server?

Slack MCP server is Slack’s official Model Context Protocol endpoint at https://mcp.slack.com/mcp. It speaks JSON-RPC 2.0 over Streamable HTTP and lets an AI client search and read messages, files, users and channels, send messages, and manage canvases and lists.

Slack does not support SSE or Dynamic Client Registration, so every client is backed by a registered Slack app — either a partner client Slack has approved or your own app with confidential OAuth.

How to connect Slack MCP

  1. Check the access rule

    Every client needs a registered Slack app; partner clients have one already.

  2. Set up OAuth

    For your own app, configure confidential OAuth and request only the user-token scopes your tools need.

  3. Test a read

    Search or read one channel before allowing the agent to send messages.

See the full Slack MCP setup

Slack MCP use cases

Catch up on a channel

Read a channel’s history and its threads, then summarise decisions and open questions.

Find a file or message fast

Search messages and files filtered by date, user and content type.

Turn a discussion into a canvas

Create or update a canvas from the summary, and export one back as markdown for the model.

Keep structured lists up to date

Add or update records in a Slack list with typed columns.

Slack MCP server questions

These answers cover the Slack MCP constraints that surprise people: whether any client can connect, which clients work without code, whether SSE is supported, how to give an agent read-only access, why calls fail after OAuth succeeded, and where to see what an agent did in Slack.

Can I add the Slack MCP server to any MCP client?

No, and this is the constraint that surprises people. Slack's documentation says MCP clients must be backed by a registered Slack app with a fixed, hardcoded app ID, and that only directory-published apps or internal apps may use MCP — unlisted apps are prohibited. Dynamic Client Registration is not supported either. So a generic client that expects to register itself on the fly cannot connect. Either use one of the four clients Slack names, or register your own Slack app.

Which clients can use it without writing code?

Slack's documentation lists four partner-built clients: Claude.ai, Claude Code, Perplexity and Cursor. Each ships its own registered Slack app, so you connect from inside the client and your workspace admin approves it through the standard Slack app approval process.

Does the Slack MCP server support SSE?

No. Slack supports JSON-RPC 2.0 over Streamable HTTP only, with all requests sent to https://mcp.slack.com/mcp, and the documentation states plainly that SSE-based connections are not supported at this time. If your client offers a transport choice, pick Streamable HTTP.

Can I give an agent read-only access to Slack?

Effectively, yes, if you control the app. Scopes are granted per tool on the user token, so an app that requests only the search and history scopes — search:read.public, search:read.private, channels:history, groups:history, mpim:history, im:history, plus files:read and users:read — has no way to post. Leave out chat:write, reactions:write, files:write, canvases:write and lists:write and the writing tools have nothing to authenticate with.

Why are my MCP calls being rejected even though OAuth succeeded?

Check two things the documentation calls out. If your app has allowed IP address ranges configured, requests to the Slack MCP server are subject to the same restriction, and calls from addresses outside the list are rejected — so the client's egress addresses must be on it. Second, Slack MCP is subject to the same Web API rate limits as direct method calls, enforced per tool, so a burst of searches can hit a Tier 2 limit while the rest of the server keeps working.

How do I see what an agent did in Slack?

Slack records MCP activity in its audit logs; the Audit Logs API actions reference has a section for the MCP server. That is the trail to check when you need to reconstruct which messages were sent or which content was read, rather than relying on the AI client's own transcript.

Reading Slack is the easy half

Pulling a decision out of a thread is one call. Turning it into a ticket, a record update and a follow-up on a schedule is a workflow, and that is a different piece of the stack. It needs a trigger, a place to write the result, and a rule for which messages an agent may post on its own.