Integrations & Tools2026-07-192 min read

Slack's Official MCP Server: What Replaced Anthropic's Reference Version

Slack now ships its own official MCP server, which replaced and archived Anthropic's earlier community reference implementation — letting AI agents read, search, and post in a workspace with the same permissions as the connecting user.

Slack bot examplesIntegration showcases

Slack ships its own official MCP server, documented at docs.slack.dev/ai/slack-mcp-server/, which replaced an earlier reference implementation Anthropic maintained — that older version was archived in May 2025 once Slack took over with a first-party server.

What It Can Do

The official server gives AI agents (Claude, Cursor, Perplexity, Copilot, and custom agents) the ability to read messages from specific channels or threads, search workspace history, post replies, manage Slack Canvases, and generally act inside a workspace on the connected user's behalf.

Permissions Inherit From the User, Not a Bot Account

A key design detail: the server operates within the permissions of whichever human authorized the connection — it doesn't grant a separate, potentially broader bot-level access. An AI agent connected on behalf of someone who can only see three channels can only see those same three channels through MCP.

Part of a Larger Platform Push

Slack (owned by Salesforce) has framed this as part of a broader "agentic collaboration" platform push, with more than 50 partners — including Anthropic, Google, and OpenAI — building context-aware agents on top of it. This mirrors the same pattern seen across other major SaaS platforms this year: rather than dozens of competing community wrappers, the platform itself ships one official, maintained server.

The Real Security Consideration

Giving an AI agent read access to Slack history means it can encounter anything posted there — including content designed to manipulate an LLM reading it. Treat message content retrieved via the Slack MCP server the same way this site's security guidance treats any tool output: as untrusted data the model is reading, not as instructions to blindly follow, especially before letting an agent post or take action based on what it found in a channel.

Join the Discussion

Discussion (0)

Y

No comments yet. Be the first to share your thoughts!