Slack consent worked but MCP rejects the app: enable Slack MCP

If Slack OAuth consent succeeds but MCP initialization is rejected, the Slack app has not enabled the Slack MCP server. It is a separate switch from Agents.

5 min readSume
All posts

When Slack consent completes but the MCP connection is rejected, the cause is a setting in the Slack app, not a bad token. Sume's setup notes say to open the app, go to Agents, find the Slack Model Context Protocol server section and choose Enable Slack MCP Server. This step is separate from the Agent experience switch. Skip it and consent works while initialization fails.

Symptom

You see a normal Slack authorization screen and a successful redirect, and then the Slack tools never show up for agents in the workspace. That pattern points at the app configuration on Slack's side. It does not point at your workspace role, because the OAuth callback already re-checked admin membership.

The fix, in order

  • In the Slack app that Sume uses, open Agents.
  • Open the Slack Model Context Protocol server section.
  • Choose Enable Slack MCP Server. Do not confuse it with the Agent experience switch.
  • Connect Slack again from Dashboard, Integrations.

What a good result looks like

Live discovery on 2026-09-09 returned slack_search_public, slack_search_public_and_private, slack_read_channel and the other exact slack_* reads listed in policy.ts. If discovery returns names that are not on the allowlist, Sume does not expose them; the list and the call are both checked against the allowlist.

Scopes stay read-only

Fixing this does not require a write scope. A chat:write scope or any other write scope is not necessary, and the requested scopes cover search and read only. If a Slack admin asks why the app does not post, that is by design; see the read-only connector.

Who does this

This is an app-owner task on Slack's side, usually done once when the Slack app is set up for a Sume environment. A normal workspace admin who only clicks Connect on the Sume Integrations page cannot flip it. If you run into the rejection as a customer, tell your Sume contact that the connector reports consent without discovery.

Keep in mind that tokens last about an hour without a provider expiry and that Sume does not renew them. A rejected initialization and an expired token look similar from the agent's side, so check the Slack app setting first, then reconnect.

Triage table of look-alike failures

Three problems look alike from the outside: the Slack app lacks the MCP switch, the token is older than an hour, or the provider is hidden because it is coming soon. The first one shows up right after a fresh consent. The second one shows up later in the day for a connection that used to work. The third one never had a Connect button.

Work through them in that order and you will usually land on the answer in a couple of minutes.

Related posts

More in Integrations

All Integrations posts

Written by Sume