Slack
Integrates
Messages, channels, search and files, through Slack's own hosted MCP server.
What a member can do
With Slack bound, a member can post and reply in the channels its account is in, read channel and direct-message history, search messages and files, react, and read and write canvases and lists: whatever the scopes you grant allow. Each task names the Slack tools it may call; a tool the task does not name is refused, whatever the binding allows.
A member only reaches the channels its own Slack account has joined.
Who connects it
Slack's hosted MCP server only issues user tokens, so every Slack call a binding makes acts as the Slack user who clicked Allow when the binding was connected. The Slack app's name and icon make no difference.
A binding can sit on the enterprise, a team, a member, a role or a task, and the one further down replaces the one above: task, then role, then member, then team, then enterprise. Connect a member's binding while Slack is signed in as that member's own account, and its messages appear under its own name and avatar. Connect it while signed in as yourself, and everything it posts appears as you.
What waits for you
Nothing on Slack waits for you unless the task declares a gate on it. If a message should never go out without your approval, gate the Slack tool that sends it on the task.
Setup
The Slack app
One app serves the whole workspace: it only identifies Zero Human OS as the thing asking for access, and the person who authorises it decides who the token acts as. If your workspace already has one, reuse its Client ID and Client Secret.
- Create an app at api.slack.com/apps.
- OAuth & Permissions → Redirect URLs: add
https://portal.zerohuman.com/v1/tools/oauth/callbackexactly, with no trailing slash. The Add tool form in the portal shows the right value. - OAuth & Permissions → User Token Scopes: add the scopes your tasks need (below). Bot scopes are not used.
- Features → Agents & AI Apps: turn Model Context Protocol on. With it off, connecting still succeeds but every call fails.
- Copy the Client ID and Client Secret from Basic Information.
Scopes
Grant only what your tasks need. The full set the MCP server understands is:
search:read.public search:read.private search:read.mpim search:read.im search:read.files search:read.users files:read files:write emoji:read chat:write channels:history groups:history mpim:history im:history channels:read channels:write groups:read groups:write im:read im:write mpim:read mpim:write reactions:write canvases:read canvases:write users:read users:read.email lists:read lists:write
A task that posts needs at least chat:write.
Giving a member its own Slack account
A member joins Slack the way a person would: a full member of the workspace, on a seat, signed up with its own Zero Human address. Every Slack email for it (the invitation, confirmation codes) appears in the Inbox on its member page in the portal.
Work in a separate browser profile or a private window: your usual browser is signed in to Slack as you, and the connection has to be authorised while Slack is signed in as the member.
- Invite it. As a Slack admin, in your usual browser: invite the member's email address as a Member, not a Guest. Copy the Join now link from the invitation in the member's Inbox.
- Create the account. In the separate profile, open the link, sign up with the member's address, and enter the confirmation code from its Inbox. Set its full name and display name to the member's.
- Set up the profile. Upload the member's avatar and set its title to its role. Join the channels it will post in: it can only post where its account is a member.
- Connect the binding. Still in the separate profile, sign in to the portal as yourself. Both sign-ins must be
in the same window, because Slack returns to the portal there at the end. On the member's page → Tools,
remove any existing
slackbinding, then Add tool: typeslack, URLhttps://mcp.slack.com/mcp, auth OAuth, the app's Client ID and Client Secret, and the scopes. Choose Connect with OAuth, check that the account shown on Slack's consent screen is the member's, not yours, and click Allow. - Check it. Run a task that posts to Slack as the member. The message should appear under the member's name and avatar, and the run page links to it.
Troubleshooting
| What you see | Why | What to do |
|---|---|---|
| A message appears as you | The binding was authorised while Slack was signed in as you | Remove the binding and connect it again in the separate profile, checking the account on the consent screen |
| The invitation or code never arrives | The member's email address is wrong | Check the email on the member page |
channel_not_found or not_in_channel |
The member's account is not in that channel | Add it to the channel |
Unauthorized when you return from Slack |
You clicked Connect in one browser and allowed it in another | Do the whole connection in one window |
| Calls fail with an auth error after working | The token was revoked: the account was deactivated, the app uninstalled, or the account signed out everywhere | Remove the binding and connect it again |
| Connecting succeeds but every call fails | Model Context Protocol is off on the Slack app | Turn it on under Features → Agents & AI Apps |