Slack MCP server and Dome
Let agents read Slack. Decide where they post.
Connect Slack's MCP server to Dome once. Every call runs with the Slack user token of the person the agent acts for, and rules decide each message on its channel.
How Dome helps
Dome provides a tool gateway and authorization for Slack
Decided on the channel
One tool, allowed in one channel and refused in another. Rules read the channel_id of every message.
Their token, their channels
Each teammate authorizes your Slack app once, on their first call. An agent acting for them reads only what they can.
Reads stay open
Search and read calls pass while posts are narrowed. A prompt can't send an agent's message to #general.
Get started
Slack behind the Gateway in three steps
Slack's MCP server takes an internal or directory-published Slack app, with no dynamic client registration. Add the server with the app's client ID and secret, sync, and apply the rules.
01
Add the Slack MCP server
Turn on MCP for your Slack app and give it the user token scopes your agents need. Credentials are per user, through OAuth.
$ dome tools add --name slack \--url https://mcp.slack.com/mcp \--auth-method oauth --credential-type per-user \--oauth-client-origin manual \--oauth-client-id "$SLACK_CLIENT_ID" \--oauth-client-secret "$SLACK_CLIENT_SECRET" \--oauth-authorize-url https://slack.com/oauth/v2_user/authorize \--oauth-token-url https://slack.com/api/oauth.v2.user.access \--oauth-token-endpoint-auth client_secret_post \--oauth-default-scope search:read.public \--oauth-default-scope channels:history \--oauth-default-scope chat:write \--gateway ops-gateway02
Sync the catalog
Sync spends your own Slack credential, so authorize the app first. Until then it fails and agents get “tool not available in this gateway”.
$ dome tools catalog sync slack03
Apply the rules
Scope them to one agent while you try them. Simulate before you deploy.
$ dome rules apply slack-args.cedar \--agent escalation-bot --name slack-per-channel
Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Slack itself, see Slack's documentation.
Rules
Read anywhere, post in one channel
The permit opens Slack to the agent. The forbid refuses sent and scheduled messages to any channel but #support-escalations.
permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "slack" }; forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)when { resource.connection_name == "slack" && ["slack_send_message", "slack_schedule_message"].contains(resource.tool_name) && resource has arguments && resource.arguments has channel_id && resource.arguments.channel_id != "C04ESCALATE"};Try it
One call, two outcomes
Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.
Channel
- Agentescalation-bot is registered and active
- Callerl.chen verified through Okta
- RulePosts to #support-escalations are allowed
Example agents
Three agents on Slack
From our template library. Each one reads broadly and writes narrowly.
thread-summarizer
Summarize long threads
Reads a long thread and drafts a summary for the person who asked. Sending stays with them.
- slack/slack_read_thread
- slack/slack_read_channel
- slack/slack_send_message_draft
escalation-bot
Escalate breached tickets
Posts tickets that breach their SLA to #support-escalations, with the customer's recent history.
- slack/slack_search_public
- slack/slack_read_user_profile
- slack/slack_send_message
standup-digest
Schedule a standup digest
Reads yesterday's team channels and schedules a morning digest in the team's own channel.
- slack/slack_read_channel
- slack/slack_search_users
- slack/slack_schedule_message
Agent workflow
Bringing it together
Connecting Slack to registered agents, models, and identity in Dome completes a governed agent application.
Acting for
Control point
Gateway
- Rules
- Guards
- Quotas
Every call decided and audited
Tools
MCP server
Slack
This page
Models
FAQ
Common questions
Does Dome work with Slack's MCP server?
Yes. Add it by URL with your Slack app's client ID and secret, and each teammate authorizes the app on their first call.
Can I limit which Slack channels an agent posts to?
Yes. Rules read the channel_id of every message, so the same tool is allowed in one channel and refused in another.
Why does Slack need my own app?
Slack's MCP server takes only internal or directory-published apps, and doesn't support dynamic client registration. Your app's credentials go on the connection.
Whose Slack access does an agent use?
The user token of the person it acts for. Dome picks it from their verified identity.
Explore
More of what Dome works with
Model
Claude Fable
Fable 5.1 from Anthropic and Amazon Bedrock in one failover pool, open to one group and capped by quota.
Read moreProvider
Anthropic
The Claude API behind the Model Broker: the key held in Dome, every call authorized, metered and audited.
Read moreIdentity
Microsoft Entra ID
Entra access tokens verified on every agent call, so rules read app roles and audit names the person.
Read moreRuntime
LangGraph
LangGraph agents with their model calls on the Model Broker and their MCP tools on the Tool Gateway.
Read moreClient
Claude Code
Claude Code on a Dome Gateway with per-developer sign-in, rules on every tool call, and audit by name.
Read moreAgent service
TinyFish
TinyFish's web agents behind the Tool Gateway, with rules that decide each run on the site it targets.
Read moreNext steps
Talk with our FDE team
Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.
No card required to start. Register your first agent in minutes.
MCP servers for AI agents: per-argument rules on every call
Put any remote MCP server behind the Tool Gateway. Agents reach it through one governed endpoint, and rules decide each call on its arguments.
See them all