6sense
Ask an AI agent about 6sense account insights, buying signals and keyword trends.
Search a Slack workspace and send messages, reactions and canvases.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The Slack MCP server connects a Slack workspace to Claude, ChatGPT and any MCP-compatible agent. Anthropic's directory lists 11 tools that search messages, channels and people, read channel and thread history, and send messages and canvases. Sign-in is confidential OAuth on a user token, so anything the agent writes appears under your own name.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
schedule_message, send_message_draft and get_reactions. schedule_message sends at a future time, which makes an undocumented tool an outbound one.as_user parameter is documented as classic-apps-only.chat:write bundles send with edit and delete. No tool exposes deletion today; the permission is nonetheless inside the grant.lists:read/lists:write and files:write. We could not determine what, if anything, uses them.client_id and client_secret. Only Marketplace-published or internal Slack apps may use MCP at all.Retry-After.admin.apps.mcp.servers.* methods as available only to workspaces on an Enterprise plan, so centralised approval controls are plan-gated even though the connector itself is not.As you. Slack's authorization server issues user tokens through the oauth/v2_user/authorize endpoint, and Slack's token documentation states that write actions with user tokens are performed as if by the user themselves. A message the agent sends carries your name and avatar, and colleagues cannot tell it came from an agent.
Yes, immediately and irreversibly by you. The send message tool posts to any conversation type in Slack — public channel, private channel, group DM or one-to-one DM — under your identity. Slack's audit log records it as mcp_slack_send_message_tool_called. There is no draft-then-approve step enforced by the server itself.
It depends on your granted scopes, so no single number is right. Anthropic's directory lists 11, Slack's rate-limit table describes 15, and a connected client showed 18 on 2026-08-22. Slack's MCP overview states the server responds with tool descriptions that match the token provided, so your list is a function of consent.
Only if you grant those scopes and consent in the Slack client. Search across direct messages needs search:read.im, and Slack's scope documentation states users must consent inside the Slack client before the API can search with it, and may revoke consent afterwards. Public-channel search needs only search:read.public.
No tool listed deletes one, but the scope that sends messages also permits deletion. Slack's chat:write scope documentation lists chat.delete, chat.update and chat.scheduleMessage as compatible methods alongside chat.postMessage. Granting send therefore grants edit and delete at the API level, even though no current tool name exposes them.
Thirty named Slack scopes, not an identity blanket. The server's RFC 9728 descriptor advertised scopes including chat:write, channels:history, search:read.private, canvases:write and users:read.email on 2026-08-22. Read and write are genuinely separable here, so you can grant channel history without also granting the ability to post a message.
Yes, in most workspaces. Slack's connect-to-Claude guide lists access to a workspace with the MCP integration approved by your workspace admin as a prerequisite. Slack also states that only Marketplace-published apps and internal apps may use MCP, so unlisted apps are prohibited regardless of user consent.
Yes, enforced per tool against the same Web API tiers. Slack documents reading a channel or thread at Tier 3, meaning 50 or more requests per minute, and searching users, channels or emoji at Tier 2, meaning 20 or more. Search carries an extra user-level limit of roughly 10 requests per minute.
Yes, by design. Reading a channel or thread and searching messages return prose authored by colleagues and by anyone in a Slack Connect channel. That text arrives in the agent's context alongside tools that can post as you, which makes it a direct prompt-injection surface. Treat retrieved messages as data, never as instructions.
docs.slack.dev/ai/mcp-server returns 301 to this page. · retrieved 2026-08-22chat:write (retrieved 2026-08-22) · retrieved 2026-08-22search:read.im (retrieved 2026-08-22) · retrieved 2026-08-22chat.postMessage · chat.delete · assistant.search.context — · · (retrieved 2026-08-22) · retrieved 2026-08-22docs.slack.dev/robots.txt returns Allow: / with no Content-Signal directive and invites .md suffixes on any page URL. · retrieved 2026-08-22initialize to https://mcp.slack.com/mcp returned HTTP 401 with www-authenticate: Bearer resource_metadata="https://mcp.slack.com/.well-known/oauth-protected-resource"; RFC 9728 descriptor and authorization-server metadata read at that host (2026-08-22) · retrieved 2026-08-22Connect Slack once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.