Sume Slack connector: read and search only, no chat:write

The Sume Slack integration gives agents search and read tools over a user token. It requests no chat:write, reactions, canvas, list or file-upload scopes.

5 min readSume
All posts

The Sume Slack connector is read-only. An agent in a connected workspace can search and read messages, files, users, channels and threads, but it cannot post, react, create channels, write canvases or upload files. The requested scopes cover search and read only, and chat:write is not among them. If you want an automation that posts to Slack, that is a separate path.

What the connector can do

After you connect, the agents of that workspace get tools whose names start with slack_, for example slack_search_public, slack_search_public_and_private and slack_read_channel. Live discovery on 2026-09-09 returned these exact names; an earlier set of unprefixed names matched no live tools, so Sume uses the prefixed ones from policy.ts.

What it cannot do

The architecture doc is explicit: the requested Slack scopes cover only search and read for messages, files, emoji, users, channels, threads and channel membership. They do not include:

  • chat:write (posting messages)
  • conversation creation
  • reactions
  • canvas writes and list writes
  • file upload

Why there is no generic proxy

Sume does not give agents a tool-call proxy for connected servers. There is no URL argument, no write operation and no prefix-based permission grant. Every tool name must be on an explicit allowlist, and the allowlist is enforced twice: when the tool list is built and again when a call executes. See readOnlyHint is not authorization.

Auth model

Slack's own MCP server is documented as confidential OAuth backed by a registered Slack app, using user tokens (Slack MCP server overview, read 2026-10-05). Sume follows that: it uses a Slack client id and secret on the server and the documented user-token endpoints. The Slack app admin must also switch on the Slack MCP server for the app, otherwise consent succeeds but MCP initialization is rejected.

If you need to post

Pushing a finished video or image into a channel is a different job from reading Slack. Use Slack's own upload API from your automation after a Sume job completes. The post Slack API upload file walks through the three-call flow.

What to tell your security team

The short answer is that the connector holds a Slack user token with search and read scopes and nothing that writes. An agent cannot send a message as you, add a reaction, upload a file or create a conversation, and Sume offers no generic proxy through which it could try.

Because the token belongs to a user, the data the agent can read is what that Slack user can read. Pick the connecting admin with that in mind, and disconnect from Integrations when the project ends.

Sources

Related posts

More in Integrations

All Integrations posts

Written by Sume