How to Connect Slack to Claude Securely

Last updated ·Read as Markdown
Answer

Connect Slack to Claude through an MCP gateway rather than a shared bot token in a local config. Create the Slack integration, expose only read tools, get the Slack app approved if your workspace requires it, allow the integration for a group, and have each person authorize with their own Slack account. Each person then adds one MCP URL to Claude. With Metorial, that URL is a Magic MCP URL, and every tool call is logged with the person it ran for.

Slack holds private channels, direct messages, and whatever people pasted into them, so the useful question is not whether Claude can connect. It is which Slack access the agent gets, and who it acts as.

If you want Claude to
Start with
Search and summarize public channels
Read tools, with each person's own Slack account
Post updates or reply in threads
Write tools, for one group, after a read-only trial
Read private channels or direct messages
An explicit admin decision, never the default
Run a scheduled digest with nobody at the keyboard
A service account, not an employee's login

What do you need before starting?

  • Claude Desktop, Claude Code, or another MCP client.
  • A Metorial account. The Dev plan is free.
  • A Slack workspace owner, or someone who can approve apps. If app approval is on, members cannot install apps that have not been approved.
  • A decision to start read-only.

How do you connect Slack to Claude?

1. Create the integration. In Metorial, open Integrations, select Create Integration, and choose Slack. Under Auth Method, pick the Slack option and select or create the credentials if prompted.

2. Limit the tools. Open Tool Filters. Allow the tools that read and search channels, and set the tools that send messages to Reject. Use Mixed if you want to allow specific tools within a group.

3. Get the app approved in Slack. If your workspace uses app approval, a workspace owner or an appointed app manager approves the request before anyone can authorize it. Do this first so the first person to connect is not blocked.

4. Allow it for a group. In Workforce, under Access, select Integrations, then Add Integration. Open the integration, select Add Group in its Access section, choose the group, set it to Allow, and save. Publish it in a portal as a user-configured listing, so each person connects with their own credentials.

5. Each person connects and adds the URL. People open the portal, authorize Slack with their own account, and copy their Magic MCP URL into Claude's MCP server settings.

6. Check the first call. Ask Claude for something narrow, such as "summarize the last week in the release-notes channel". Then open Integrations, Connection Logs, Tool Calls, and confirm the row shows the tool, the arguments, and the right person.

Which Slack permissions should the agent have?

Slack asks the person to approve a list of scopes when they authorize. Read that list. Slack's own MCP server documentation shows how granular they are: posting needs chat:write, while search is split into scopes such as search:read.public, search:read.private, and search:read.im.

A channel summarizer needs the public search scope at most. Posting and private or direct-message search go beyond it, so decline them until a use case requires them. Slack notes that scopes accumulate across installations and an access token's scopes cannot be downgraded, so granting too much now means reauthorizing later to correct it.

What does per-user authorization change?

When each person authorizes with their own Slack account, Slack's own channel membership decides what that person's agent can read. Nobody gets a view of Slack they did not already have.

A shared bot connection behaves differently: everyone who uses it sees the same thing, and nothing in the call record says which person asked. The reasoning is the same as in How to connect AI agents to company apps without sharing API keys.

What about prompt injection and writes?

Slack messages are free text written by many people, and an agent that reads a message containing instructions may follow them. Protoguard inspects calls before they run, which lowers the risk without removing it. Read-only tools keep the damage small if it fails. For how to hold that line across systems, see How to restrict AI agents to read-only tools.

When you do enable posting, enable it for one group, review the Tool Calls table after a week, and widen from there.

What if the workspace blocks the app?

With app approval on, members can install pre-approved apps right away and see restricted apps listed but cannot install them. If your app is not yet approved, members can request it where owners allow requests. Slack's default approver is the workspace owner, who can also appoint app managers or set automation rules for requests. Send the owner the integration name and the scopes it will ask for, so the decision takes minutes instead of a thread.

How do you roll it out?

Start with one team that has a clear use, such as support summarizing escalation channels. Keep them on read tools for two weeks, review the Tool Calls table, and then add the next group. A small first group means you read every call that matters.

Frequently asked questions

Can Claude read private Slack channels and direct messages?

Only if the Slack account the agent acts as can read them and the scopes granted allow it. Slack splits search permissions by public channels, private channels, and direct messages, so you can decline the ones the use case does not need. Metorial tool filters add a second limit on what the agent can call.

Does a Slack workspace owner have to approve the connection?

If the workspace has app approval turned on, yes. Slack lets workspace owners restrict which apps members can install, and owners can appoint other members as app managers to review requests.

Should Claude be allowed to post messages in Slack?

Not at first. Start with read tools, review the call records for a week or two, then allow posting for one group. A message sent by an agent is visible to the whole channel, which makes mistakes harder to undo than a bad search.

Does the same setup work in Cursor or ChatGPT?

Yes. The endpoint is a standard MCP URL, so the same integration, group access, and tool filters apply in any client that supports MCP. Adding a client does not repeat the Slack setup.

How do I see what Claude read in Slack?

In Metorial, open Integrations, then Connection Logs, then Tool Calls. Each row opens the session and shows the tool, its arguments, and the result. An account's Operations view shows the same calls for one person.

Sources

  1. Metorial documentation: Create an integration
  2. Slack documentation: Slack MCP server
  3. Slack documentation: Installing with OAuth
  4. Slack Help Center: Manage app approval for your workspace

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.