Sume Slack connector: read and search only, no chat:write
The Sume Slack integration gives agents search and read tools over a user token. It requests no chat:write, reactions, canvas, list or file-upload scopes.

The Sume Slack connector is read-only. An agent in a connected workspace can search and read messages, files, users, channels and threads, but it cannot post, react, create channels, write canvases or upload files. The requested scopes cover search and read only, and chat:write is not among them. If you want an automation that posts to Slack, that is a separate path.
What the connector can do
After you connect, the agents of that workspace get tools whose names start with slack_, for example slack_search_public, slack_search_public_and_private and slack_read_channel. Live discovery on 2026-09-09 returned these exact names; an earlier set of unprefixed names matched no live tools, so Sume uses the prefixed ones from policy.ts.
What it cannot do
The architecture doc is explicit: the requested Slack scopes cover only search and read for messages, files, emoji, users, channels, threads and channel membership. They do not include:
chat:write(posting messages)- conversation creation
- reactions
- canvas writes and list writes
- file upload
Why there is no generic proxy
Sume does not give agents a tool-call proxy for connected servers. There is no URL argument, no write operation and no prefix-based permission grant. Every tool name must be on an explicit allowlist, and the allowlist is enforced twice: when the tool list is built and again when a call executes. See readOnlyHint is not authorization.
Auth model
Slack's own MCP server is documented as confidential OAuth backed by a registered Slack app, using user tokens (Slack MCP server overview, read 2026-10-05). Sume follows that: it uses a Slack client id and secret on the server and the documented user-token endpoints. The Slack app admin must also switch on the Slack MCP server for the app, otherwise consent succeeds but MCP initialization is rejected.
If you need to post
Pushing a finished video or image into a channel is a different job from reading Slack. Use Slack's own upload API from your automation after a Sume job completes. The post Slack API upload file walks through the three-call flow.
What to tell your security team
The short answer is that the connector holds a Slack user token with search and read scopes and nothing that writes. An agent cannot send a message as you, add a reaction, upload a file or create a conversation, and Sume offers no generic proxy through which it could try.
Because the token belongs to a user, the data the agent can read is what that Slack user can read. Pick the connecting admin with that in mind, and disconnect from Integrations when the project ends.
Sources
Related posts
More in Integrations
- Tally webhook to a Sume music job: verify, dedupe, return 200 fast
Tally signs with base64 HMAC-SHA256, waits 10 s and retries up to a day. Verify the signature, use eventId as the Idempotency-Key, then start the Sume job.
- Telegram sendAudio for a Sume track: URL 20 MB, upload 50 MB
Telegram can fetch a sendAudio file from a URL up to 20 MB, or accept an upload up to 50 MB. Pass the Sume artifact link first; upload only as a fallback.
- Threads link limit: 5 unique URLs per post, checked before publish
Threads allows 5 unique URLs per post and returns THREADS_API__LINK_LIMIT_EXCEEDED past that. Count unique links in the caption before posting a Sume clip.
- Threads topic tag: 1 to 50 characters, no periods or ampersands
Meta's Threads API accepts a topic tag of 1 to 50 characters and rejects periods and ampersands. Validate the tag in code before you publish a Sume clip.
Written by Sume