Slack MCP Server: Which Implementation Is Right for Your Use Case
The Slack MCP Server allows AI agents to read and send messages, manage channels, and interact with Slack workspaces through a standardized protocol.
The Slack MCP server is not a single thing. Search for setup instructions and you will find five distinct implementations — each with different tool sets, authentication models, transport support, and security postures. Pick the wrong one and your agent either can’t search messages, bypasses your company’s admin approval workflow, or stores tokens in ways that won’t survive a security review.
What the Slack MCP Server Actually Does
Across the major implementations, tools fall into four categories: Search (messages, files, channels, users), Messaging (post, reply, DM, read history), Canvas management (official server only), and User data (profiles, emails, custom fields).
The official Slack MCP server uses streamable HTTP over JSON-RPC 2.0 — no SSE. Community implementations vary.
The Bot Token vs. User Token Problem
The critical limitation: search:read.* scopes are user-only. Bot tokens cannot search Slack. Configure any Slack MCP server with a bot token alone, and the slack_search_messages tool either won’t appear in the tool list or will return a not_authed error — silently, with no startup error.
Bot token (xoxb) covers: chat:write, channels:history, groups:history, im:history, mpim:history, users:read, reactions:write
User token (xoxp) required for: search:read.public, search:read.private, search:read.files, search:read.users, search:read.mpim, search:read.im
If your agent can’t find slack_search_messages, this is almost always the reason.
The Five Implementations, Compared
| Implementation | Language | Auth Methods | Tools Exposed | Transports | Production Ready |
|---|---|---|---|---|---|
| Official Slack MCP Server | Hosted | OAuth 2.0 user token | Full: search, messaging, canvases, users | Streamable HTTP only | Yes |
| korotovsky/slack-mcp-server | Go | xoxp, xoxb, xoxc, xoxd browser tokens | Extensive, per-tool toggles | SSE + stdio + HTTP | With caveats |
| ubie-oss/slack-mcp-server | TypeScript | Bot + user token (both required) | 9 core tools | stdio + streamable HTTP | Partial |
| jtalk22/slack-mcp-server | TypeScript | Token file or OAuth | 16 tools, JSON schema validated | stdio + HTTP + hosted HTTP | With caveats |
| piekstra/slack-mcp-server | TypeScript | Bot token only (macOS keychain) | Write-focused, no search | stdio | Personal use only |
Official Slack MCP Server
Hosted and managed by Slack. Requires a registered Slack app; every action goes through workspace admin approval and Slack’s OAuth flow. Canvas support is exclusive to this implementation. The only one that benefits from Slack’s ongoing maintenance and security response.
korotovsky/slack-mcp-server
Most flexible community server. Accepts all four token types, supports SSE/stdio/HTTP, and offers smart history fetch by date range. Its “stealth mode” (browser session tokens) enables use without a registered Slack app — see the security section for why that matters.
ubie-oss/slack-mcp-server
Simplest to configure. Nine core tools, requires both token types (which enforces correct scoping). No canvas support, no SSE.
jtalk22/slack-mcp-server
16 tools with JSON schema validation, Docker deployment, multiple transport options.
piekstra/slack-mcp-server
Write-focused, macOS-specific, keychain storage. Bot token only, no search. Personal use.
Decision Framework: Which One for Your Use Case
Personal productivity with Claude Desktop or Claude.ai → ubie-oss. Two-token setup enforces correct scoping; readable TypeScript codebase.
Developer workflow in Cursor or VS Code → korotovsky. SSE transport persists without reinitializing; per-tool env var toggles let you scope down.
Production agentic pipeline → Official Slack MCP Server. Audit logs matter at scale — this is the only implementation that generates entries in Slack’s admin audit log.
Quick personal Slack reader, no app registration → korotovsky in stealth mode. Understand what you’re accepting: no audit trail, not acceptable for any production or regulated environment.
Note for enterprise and compliance-sensitive teams: If your organization requires SOC 2 compliance, operates on Slack Enterprise Grid, or has DLP requirements, the official Slack MCP server is the only defensible choice.
Security Posture Breakdown
Stealth mode and the audit trail gap. korotovsky’s browser token support means your AI agent can post, read, and search with zero admin visibility. Acceptable for a personal experiment; a compliance failure waiting to be discovered in any organizational context.
Token storage anti-patterns. Most tutorials tell you to place tokens in a .env file. For anything beyond a personal experiment, use a secrets manager and never commit token files, even to private repos.
Scope minimization. Only request the scopes your tools actually use. A minimal read-only config needs search:read.public/search:read.private (user token) plus channels:history/groups:history/users:read (bot token).
Rate limit handling. None of the community implementations include automatic exponential back-off. Slack’s Tier 2 limit (20 req/min, search operations) is where agents get throttled first. Build retry logic before you discover this in production.
Minimum scope reference table
| Tool | Required Token | Required Scopes |
|---|---|---|
slack_search_messages | User (xoxp) | search:read.public, search:read.private |
slack_post_message | Bot (xoxb) | chat:write |
slack_get_channel_history | Bot (xoxb) | channels:history, groups:history |
slack_reply_to_thread | Bot (xoxb) | chat:write |
slack_get_users | Bot (xoxb) | users:read |
| Canvas read/write | User (xoxp) | canvases:read / canvases:write |
Setup Walkthrough
Official Slack MCP Server
- Create a Slack app at api.slack.com/apps. Add both bot and user token scopes listed above.
- Install to your workspace via the OAuth flow (admin approval may be required).
- Add to Claude Desktop (
claude_desktop_config.json):
{
"mcpServers": {
"slack": {
"url": "https://mcp.slack.com/api/mcp",
"headers": {
"Authorization": "Bearer YOUR_USER_OAUTH_TOKEN"
}
}
}
}
ubie-oss/slack-mcp-server (personal use)
{
"mcpServers": {
"slack": {
"command": "npx",
"args": ["-y", "@ubie-oss/slack-mcp-server"],
"env": {
"SLACK_BOT_TOKEN": "xoxb-your-bot-token",
"SLACK_USER_TOKEN": "xoxp-your-user-token"
}
}
}
}
Common failure: configuring only SLACK_BOT_TOKEN. Both tokens are required for search to work.
FAQ
Which Slack MCP server works with Cursor?
Both the official server (HTTP) and korotovsky (SSE). For persistent local setups, korotovsky with SSE is more reliable.
How do I use the Slack MCP server with Claude Code?
Both the official server and ubie-oss work via stdio, using the same JSON config structure as Claude Desktop.
Why can’t my agent search Slack messages?
Almost certainly a missing user token or missing search:read.* scopes. Bot tokens cannot search.
Is the Slack MCP server free?
The open source implementations are free. The official server is part of standard paid Slack plans.
What’s the difference between the official server and the open source ones?
Audit logging, admin visibility, proper OAuth 2.0 with rotation, and canvas support — all exclusive to the official server.
Conclusion
If you need to pick one default: ubie-oss for personal use, the official Slack MCP server for anything touching a team workspace or production workflow.
Browse Slack MCP server listings on MyMCP Shelf to compare verified implementations.