01-authentication-setup.md
May 14, 2026 · View on GitHub
1. Authentication Setup
Open up your Slack in your browser and login.
Note: You only need one of the following: an
xoxp-*User OAuth token, anxoxb-*Bot token, or bothxoxc-*andxoxd-*session tokens. User/Bot tokens are more secure and do not require a browser session. If multiple are provided, priority isxoxp>xoxb>xoxc/xoxd.
Option 1: Using SLACK_MCP_XOXC_TOKEN/SLACK_MCP_XOXD_TOKEN (Browser session)
Lookup SLACK_MCP_XOXC_TOKEN
- Open your browser's Developer Console.
- In Firefox, under
Tools -> Browser Tools -> Web Developer toolsin the menu bar - In Chrome, click the "three dots" button to the right of the URL Bar, then select
More Tools -> Developer Tools - Switch to the console tab.
- Type "allow pasting" and press ENTER.
- Paste the following snippet and press ENTER to execute:
JSON.parse(localStorage.localConfig_v2).teams[document.location.pathname.match(/^\/client\/([A-Z0-9]+)/)[1]].token
Token value is printed right after the executed command (it starts with
xoxc-), save it somewhere for now.
Lookup SLACK_MCP_XOXD_TOKEN
- Switch to "Application" tab and select "Cookies" in the left navigation pane.
- Find the cookie with the name
d. That's right, just the letterd. - Double-click the Value of this cookie.
- Press Ctrl+C or Cmd+C to copy it's value to clipboard.
- Save it for later.
Option 2: Using SLACK_MCP_XOXP_TOKEN (User OAuth)
Instead of using browser-based tokens (xoxc/xoxd), you can use a User OAuth token:
-
Go to api.slack.com/apps and create a new app
-
Under "OAuth & Permissions", add the following to the "User Token Scopes":
channels:history- View messages in public channelschannels:read- View basic information about public channelsgroups:history- View messages in private channelsgroups:read- View basic information about private channelsim:history- View messages in direct messages.im:read- View basic information about direct messagesim:write- Start direct messages with people on a user’s behalf (new sincev1.1.18)mpim:history- View messages in group direct messagesmpim:read- View basic information about group direct messagesmpim:write- Start group direct messages with people on a user’s behalf (new sincev1.1.18)users:read- View people in a workspace.chat:write- Send messages on a user's behalf. (new sincev1.1.18)search:read- Search a workspace's content. (new sincev1.1.18)usergroups:read- View user groups in a workspace.usergroups:write- Create and manage user groups.channels:write- Join and leave public channels.
-
Install the app to your workspace
-
Copy the "User OAuth Token" (starts with
xoxp-)
App manifest (preconfigured scopes)
To create the app from a manifest with permissions preconfigured, use the following code snippet:
{
"display_information": {
"name": "Slack MCP"
},
"oauth_config": {
"scopes": {
"user": [
"channels:history",
"channels:read",
"groups:history",
"groups:read",
"im:history",
"im:read",
"im:write",
"mpim:history",
"mpim:read",
"mpim:write",
"users:read",
"chat:write",
"search:read",
"usergroups:read",
"usergroups:write",
"channels:write"
]
}
},
"settings": {
"org_deploy_enabled": false,
"socket_mode_enabled": false,
"token_rotation_enabled": false
}
}
Option 3: Using SLACK_MCP_XOXB_TOKEN (Bot Token)
You can also use a Bot token instead of a User token:
- Go to api.slack.com/apps and create a new app
- Under "OAuth & Permissions", add Bot Token Scopes (same as User scopes above, except replace
search:readwithsearch:read.publicand replacechannels:writewithchannels:join+channels:manage) - Install the app to your workspace
- Copy the "Bot User OAuth Token" (starts with
xoxb-) - Important: Bot must be invited to channels for access
Note: Bot tokens cannot use
search.messagesAPI, soconversations_search_messagestool will not be available.
See next: Installation