Slack MCP Server: Setup in Claude, Cursor and ChatGPT
Slack runs its own MCP server, and it reaches your assistant through clients that carry a registered Slack app. How to connect Claude, Claude Code, Cursor and ChatGPT, what your workspace admin has to approve, which scopes each tool needs, and what an assistant should never post on its own.
7 min read
Slack’s official MCP server is hosted by Slack at https://mcp.slack.com/mcp and speaks streamable HTTP. It can search messages, files, channels and people, read channels and threads, send, schedule and draft messages, and work with canvases, lists and files, always as the signed-in user. The catch is sign-in: Slack does not support dynamic client registration, and every MCP client must be backed by a registered Slack app. In practice you connect through a client that already carries one: the Slack connector in Claude, Slack’s plugin for Claude Code, Slack’s configuration for Cursor, or the Slack app in ChatGPT. Your workspace admin decides whether any of them is allowed.
This guide covers each client, the approval step, the scopes, and a rule set for posting. If MCP itself is new to you, start with what MCP is.
Before you start
- A Slack workspace where the MCP integration is approved. Slack’s setup pages list it as a prerequisite for every client.
- Your admin’s app policy. By default members can install apps, but workspace owners can require approval (opens in a new tab), and approving an app means approving the scopes it will use. If sign-in is refused, ask your admin first.
- On Claude Team and Enterprise plans, an Owner has to enable the Slack connector for the organisation before members can connect it.
Claude on the web and desktop
- Open the sidebar and go to Customize, then Connectors.
- Click + to add a connector, find Slack and add it.
- Complete the OAuth flow in Slack, choosing the workspace.
- In a chat, open the + menu, go to Connectors and switch Slack on for that conversation.
This is Slack’s entry in the Claude connector directory, so there is no URL or client ID to type. How directory connectors differ from custom ones is covered in Claude’s connectors explained. Organisations on Slack Enterprise+ with Okta can also manage access to the Slack MCP server in Claude (opens in a new tab) through enterprise-managed authorisation, so people can only sign in with their work accounts.
Claude Code
Slack’s Claude guide (opens in a new tab) uses the Slack MCP and Skills plugin, which configures the server when it loads and prompts you to sign in with OAuth:
/plugin install slack claude plugin install slack
Behind the plugin is an ordinary HTTP server entry with Slack’s own client ID and a fixed callback port, which is why no dynamic registration is needed:
{
"mcpServers": {
"slack": {
"type": "http",
"url": "https://mcp.slack.com/mcp",
"oauth": {
"clientId": "1601185624273.8899143856786",
"callbackPort": 3118
}
}
}
}Run /mcp afterwards to check it shows as connected. More on the Claude Code side is on its integration page.
Cursor
Slack offers an Add to Cursor button on its Cursor setup page (opens in a new tab). To do it by hand, open Cursor Settings, go to the MCP section and add the entry below. A connect button appears; click it and sign in to your workspace.
{
"mcpServers": {
"slack": {
"url": "https://mcp.slack.com/mcp",
"auth": {
"CLIENT_ID": "3660753192626.8903469228982"
}
}
}
}ChatGPT
Slack’s Help Centre lists ChatGPT among the partner apps for its MCP server. In ChatGPT, Slack arrives as a ready-made app (newer menus say plugin) that you connect and sign in to, rather than a server address you paste. According to OpenAI’s help centre, the Slack app needs a paid ChatGPT plan, respects Slack’s existing permissions so only messages and files you can already see are searchable, and takes actions such as joining a channel or uploading a file only where a workspace admin has enabled them. How apps and connectors work in ChatGPT generally is in ChatGPT connectors and apps.
Do not confuse it with the ChatGPT app inside Slack, which puts ChatGPT in a Slack side panel. That is the other direction.
What it can do, and the scopes behind it
Slack’s MCP server overview (opens in a new tab) lists the user-token scope each tool needs, and it is the clearest map of what you are granting:
- Search messages and channels:
search:read.public,search:read.private,search:read.mpimandsearch:read.im. Files:search:read.files. People:search:read.users. - Read a channel or thread:
channels:history,groups:history,mpim:historyandim:history. - Send or schedule a message:
chat:write. - Create a channel or conversation:
channels:write,groups:write,im:writeormpim:write, depending on the kind. - Canvases:
canvases:readandcanvases:write. Lists:lists:readandlists:write. Upload a file:files:write. Reactions:reactions:readandreactions:write.
Notice that private channels and direct messages are in the search and read scopes. The server can reach anything you can reach, including your DMs. That is the right default for finding a decision someone made last month, and a reason to think before switching it on in a shared or automated setup.
Search and read vs post
Reading is where the value is: “What did the payments channel decide about the retry bug last week?”, “Summarise this thread and list the open questions”, “Who owns the billing service, and what is their status?” Mistakes there cost you a wrong answer you can check.
Posting is different. A message goes out under your name, to people who cannot tell it was drafted by an assistant, and it cannot be unsent in their notifications. Two controls help. In Claude, an Owner on Team and Enterprise plans can set each connector tool category to Always allow, Needs approval or Blocked, so an organisation can allow search and block sending outright; the steps are in Claude’s connector guide (opens in a new tab). In Claude Code and Cursor, leave the send, schedule and channel-creation tools on ask rather than pre-approving them, as described in auto-approve in Claude Code.
What an assistant should never post without a person
Slack’s server can draft and preview a message inside the assistant, which makes a simple rule workable: the assistant drafts, a person sends. Hold to it for at least these:
- Anything to a customer, partner or shared channel with another company.
- Announcements to large channels, and anything that mentions
@channelor@here. - Direct messages to people who have not asked to hear from the assistant.
- Messages that commit someone to a date, a price, a decision or an apology.
- Anything built from text the assistant read in Slack. A message in a channel can carry instructions aimed at the assistant, the prompt injection problem described in MCP security risks, and posting is how it would act on them.
- Scheduled messages. They go out later, when nobody is watching.
Pairing Slack with other servers deserves the same care. Slack’s own security note asks you to think before connecting other MCP servers at the same time, because the assistant can carry what it read in one into another.
Limits to know
- Registered apps only. Slack allows directory-published and internal apps to use MCP; unlisted apps are refused. You cannot simply paste the URL into a client that has no Slack app behind it.
- No SSE. Slack supports streamable HTTP only.
- Rate limits. The same tiers as the Slack Web API apply per tool; searching users or channels sits at Tier 2, around 20 or more calls a minute.
- IP allowlists. If the app has allowed IP ranges set, calls from anywhere else are rejected.
- Audit. Slack says MCP activity appears in the associated audit logs, which is where an admin checks what was sent.
Removing it
In Claude, disconnect Slack under Customize > Connectors. In Claude Code, uninstall the plugin or remove the server with claude mcp remove. In Cursor, delete the entry. The app authorisation stays in Slack until it is removed there, so remove it from your workspace’s app settings too, or ask your admin to.
If the work is a task list
Slack is where decisions are discussed, not where the resulting work is tracked. A useful pattern is to let the assistant read the thread and turn what was agreed into tasks on a board, where it does not need to post anything at all. fenbs is built for that: the assistant is a member of the board with its own role, connected to https://fenbs.ai/api/mcp with scopes you approve, and every task it files is recorded under its name. The setup is on the MCP docs page.
Related
Keeping a person in charge of what gets sent: human-in-the-loop AI agents. What happens during the OAuth step: how MCP sign-in works. Habits for any connection: MCP security best practices.