Skip to main content
Slack issues tokens to apps, not to people, so the slack pack needs an app installed in your workspace before its first call. The manifest below carries every scope the pack’s tools declare, so creating the app is one click and a review rather than a page of scopes ticked by hand. The links open in a new tab; this page stays where you left it.
1

Create the app

Create the Slack app from this manifest
manifest.json
The link opens Slack’s Create an app dialog with this manifest already in it. Pick the workspace, Next, check the scopes, Next, Create. If the link arrives with an empty editor, choose From a manifest yourself and paste the block above into the JSON tab.The scopes are the pack’s own, read off its tools when this page is generated. The name is only a default: call the app anything, and that is the name your workspace sees on the messages it posts.The first eleven scopes read channels and history, post, and react. The other eight belong to five tools that do more: reactions_get (reactions:read), conversations_open (im:write, mpim:write), conversations_create (channels:manage, groups:write), conversations_invite (the two *:write.invites) and conversations_join (channels:join). An app that will never be handed those tools can drop their scopes from the manifest before Next; a tool whose scope is missing answers missing_scope when called, not at install.
2

Install it

On the app’s page, Install App in the sidebar → Install to your workspace → Allow.A workspace that restricts apps sends an approval request to its admins instead, and the token appears once they approve.
3

Copy the bot token

The same page now shows a Bot User OAuth Token beginning xoxb-. That is the credential:
The pack reads it on its next call. Rotation is off in the manifest, so this token does not expire; it stops working only if the app is uninstalled.
4

Invite the bot to the channels it should read

A bot reads only the channels it is a member of, and a channel it has not been invited to answers not_in_channel — on the tool call, not at install time. In each channel, type:
Direct messages to the bot need no invite.
5

Verify

verify_slack.py
The workspace’s channels, which is also the cheapest way to turn a channel name into the ID every other Slack tool asks for.

Searching messages

search_messages is the one tool a bot token cannot call: Slack answers search.messages only for a user token. To use it, add search:read under OAuth & Permissions → User Token Scopes, reinstall, and use the User OAuth Token (xoxp-…) that appears beside the bot token. That token acts as you — everything it posts is posted by you — so hand it only the search tool. The Slack pack page has the rest.

Your users’ workspaces

The same app, distributed. Under OAuth & Permissions, add your app’s callback as a Redirect URL. Under Manage Distribution, turn on public distribution. Each workspace then installs through your consent route instead of the Install button. Whether to turn token rotation on, and what changes when you do, is on Slack’s provider page; the route itself is getting the grant.
  • Slack — the server constant, both token shapes, and refresh under rotation
  • Every pack — what the other packs need, in one table