Slack MCP Server: Setup in Claude, Cursor and ChatGPT

Slack runs its own MCP server, and it reaches your assistant through clients that carry a registered Slack app. How to connect Claude, Claude Code, Cursor and ChatGPT, what your workspace admin has to approve, which scopes each tool needs, and what an assistant should never post on its own.

7 min read

Slack’s official MCP server is hosted by Slack at https://mcp.slack.com/mcp and speaks streamable HTTP. It can search messages, files, channels and people, read channels and threads, send, schedule and draft messages, and work with canvases, lists and files, always as the signed-in user. The catch is sign-in: Slack does not support dynamic client registration, and every MCP client must be backed by a registered Slack app. In practice you connect through a client that already carries one: the Slack connector in Claude, Slack’s plugin for Claude Code, Slack’s configuration for Cursor, or the Slack app in ChatGPT. Your workspace admin decides whether any of them is allowed.

This guide covers each client, the approval step, the scopes, and a rule set for posting. If MCP itself is new to you, start with what MCP is.

Before you start

  • A Slack workspace where the MCP integration is approved. Slack’s setup pages list it as a prerequisite for every client.
  • Your admin’s app policy. By default members can install apps, but workspace owners can require approval (opens in a new tab), and approving an app means approving the scopes it will use. If sign-in is refused, ask your admin first.
  • On Claude Team and Enterprise plans, an Owner has to enable the Slack connector for the organisation before members can connect it.

Claude on the web and desktop

  1. Open the sidebar and go to Customize, then Connectors.
  2. Click + to add a connector, find Slack and add it.
  3. Complete the OAuth flow in Slack, choosing the workspace.
  4. In a chat, open the + menu, go to Connectors and switch Slack on for that conversation.

This is Slack’s entry in the Claude connector directory, so there is no URL or client ID to type. How directory connectors differ from custom ones is covered in Claude’s connectors explained. Organisations on Slack Enterprise+ with Okta can also manage access to the Slack MCP server in Claude (opens in a new tab) through enterprise-managed authorisation, so people can only sign in with their work accounts.

Claude Code

Slack’s Claude guide (opens in a new tab) uses the Slack MCP and Skills plugin, which configures the server when it loads and prompts you to sign in with OAuth:

In a Claude Code session, or from the shell
/plugin install slack

claude plugin install slack

Behind the plugin is an ordinary HTTP server entry with Slack’s own client ID and a fixed callback port, which is why no dynamic registration is needed:

The plugin’s .mcp.json, as Slack documents it
{
  "mcpServers": {
    "slack": {
      "type": "http",
      "url": "https://mcp.slack.com/mcp",
      "oauth": {
        "clientId": "1601185624273.8899143856786",
        "callbackPort": 3118
      }
    }
  }
}

Run /mcp afterwards to check it shows as connected. More on the Claude Code side is on its integration page.

Cursor

Slack offers an Add to Cursor button on its Cursor setup page (opens in a new tab). To do it by hand, open Cursor Settings, go to the MCP section and add the entry below. A connect button appears; click it and sign in to your workspace.

Cursor MCP configuration
{
  "mcpServers": {
    "slack": {
      "url": "https://mcp.slack.com/mcp",
      "auth": {
        "CLIENT_ID": "3660753192626.8903469228982"
      }
    }
  }
}

ChatGPT

Slack’s Help Centre lists ChatGPT among the partner apps for its MCP server. In ChatGPT, Slack arrives as a ready-made app (newer menus say plugin) that you connect and sign in to, rather than a server address you paste. According to OpenAI’s help centre, the Slack app needs a paid ChatGPT plan, respects Slack’s existing permissions so only messages and files you can already see are searchable, and takes actions such as joining a channel or uploading a file only where a workspace admin has enabled them. How apps and connectors work in ChatGPT generally is in ChatGPT connectors and apps.

Do not confuse it with the ChatGPT app inside Slack, which puts ChatGPT in a Slack side panel. That is the other direction.

What it can do, and the scopes behind it

Slack’s MCP server overview (opens in a new tab) lists the user-token scope each tool needs, and it is the clearest map of what you are granting:

  • Search messages and channels: search:read.public, search:read.private, search:read.mpim and search:read.im. Files: search:read.files. People: search:read.users.
  • Read a channel or thread: channels:history, groups:history, mpim:history and im:history.
  • Send or schedule a message: chat:write.
  • Create a channel or conversation: channels:write, groups:write, im:write or mpim:write, depending on the kind.
  • Canvases: canvases:read and canvases:write. Lists: lists:read and lists:write. Upload a file: files:write. Reactions: reactions:read and reactions:write.

Notice that private channels and direct messages are in the search and read scopes. The server can reach anything you can reach, including your DMs. That is the right default for finding a decision someone made last month, and a reason to think before switching it on in a shared or automated setup.

Search and read vs post

Reading is where the value is: “What did the payments channel decide about the retry bug last week?”, “Summarise this thread and list the open questions”, “Who owns the billing service, and what is their status?” Mistakes there cost you a wrong answer you can check.

Posting is different. A message goes out under your name, to people who cannot tell it was drafted by an assistant, and it cannot be unsent in their notifications. Two controls help. In Claude, an Owner on Team and Enterprise plans can set each connector tool category to Always allow, Needs approval or Blocked, so an organisation can allow search and block sending outright; the steps are in Claude’s connector guide (opens in a new tab). In Claude Code and Cursor, leave the send, schedule and channel-creation tools on ask rather than pre-approving them, as described in auto-approve in Claude Code.

What an assistant should never post without a person

Slack’s server can draft and preview a message inside the assistant, which makes a simple rule workable: the assistant drafts, a person sends. Hold to it for at least these:

  • Anything to a customer, partner or shared channel with another company.
  • Announcements to large channels, and anything that mentions @channel or @here.
  • Direct messages to people who have not asked to hear from the assistant.
  • Messages that commit someone to a date, a price, a decision or an apology.
  • Anything built from text the assistant read in Slack. A message in a channel can carry instructions aimed at the assistant, the prompt injection problem described in MCP security risks, and posting is how it would act on them.
  • Scheduled messages. They go out later, when nobody is watching.

Pairing Slack with other servers deserves the same care. Slack’s own security note asks you to think before connecting other MCP servers at the same time, because the assistant can carry what it read in one into another.

Limits to know

  • Registered apps only. Slack allows directory-published and internal apps to use MCP; unlisted apps are refused. You cannot simply paste the URL into a client that has no Slack app behind it.
  • No SSE. Slack supports streamable HTTP only.
  • Rate limits. The same tiers as the Slack Web API apply per tool; searching users or channels sits at Tier 2, around 20 or more calls a minute.
  • IP allowlists. If the app has allowed IP ranges set, calls from anywhere else are rejected.
  • Audit. Slack says MCP activity appears in the associated audit logs, which is where an admin checks what was sent.

Removing it

In Claude, disconnect Slack under Customize > Connectors. In Claude Code, uninstall the plugin or remove the server with claude mcp remove. In Cursor, delete the entry. The app authorisation stays in Slack until it is removed there, so remove it from your workspace’s app settings too, or ask your admin to.

If the work is a task list

Slack is where decisions are discussed, not where the resulting work is tracked. A useful pattern is to let the assistant read the thread and turn what was agreed into tasks on a board, where it does not need to post anything at all. fenbs is built for that: the assistant is a member of the board with its own role, connected to https://fenbs.ai/api/mcp with scopes you approve, and every task it files is recorded under its name. The setup is on the MCP docs page.

Related

Keeping a person in charge of what gets sent: human-in-the-loop AI agents. What happens during the OAuth step: how MCP sign-in works. Habits for any connection: MCP security best practices.

Questions people ask.

What is the Slack MCP server URL?

Slack hosts it at https://mcp.slack.com/mcp over streamable HTTP. SSE connections and dynamic client registration are not supported, so a client must use a registered Slack app’s client ID.

How do I connect the Slack MCP server to Claude Code?

Install Slack’s plugin with /plugin install slack inside a session, or claude plugin install slack from the shell. It configures the server with Slack’s client ID and prompts you to sign in to your workspace.

Does the Slack MCP server need admin approval?

Slack’s setup pages require a workspace where the MCP integration has been approved by an admin. Where app approval is on, owners approve the app and the scopes it uses before members can connect it.

Can the Slack MCP server read private channels and DMs?

Yes, if you grant the matching scopes. Search and read cover public and private channels, group DMs and direct messages, limited to conversations the signed-in user can already see.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.