Manage access to the Slack MCP server through your identity provider
Manage access to the Slack MCP server through your identity provider
The Slack Model Context Protocol (MCP) server allows AI assistants to establish secure connections to Slack so they can access and interact with your organization’s data. If you’re on the Slack Enterprise+ plan and use Okta as your identity provider (IDP), you can manage access to the Slack MCP server in Claude from Okta.
You can use Enterprise-Managed Authorization (EMA) to provision access to the Slack MCP server in Claude if you’re on the Slack Enterprise+ plan and the Claude Team or Enterprise plan.
When you manage access to Slack (or other MCP servers) through your IDP, you can ensure that members of your organization only authenticate with their work accounts.
Step 1: Install the Claude app to Slack
Skip ahead to Step 2 if you’re already installed the Claude app at the org level.
From your desktop, click your organization name in the sidebar.
Hover over Tools & settings, then click Organization settings.
From the left sidebar, click Integrations.
Click Manage Apps in the top right, then select Install an app.
Search for Claude and click Continue, then click Allow to grant the app access to your org.
Now that you’ve granted the app access to your org, you’ll be prompted to return to the admin dashboard to add the app to workspaces (if you only want members of certain workspaces to have access to Claude in Slack).
From the Integrations section of the admin dashboard, click Installed apps.
Click the three dots icon next to Claude.
Select Add to more workspaces.
Check the boxes next to any workspaces you’d like to add the app to.
Click Next.
Check the box next to I’m ready to add this app.
Click Add App.
Step 2: Enable Enterprise-Managed Authorization in Slack
Once the Claude app is installed, turn on Enterprise-Managed Authorization in Slack.
From your desktop, click your organization name in the sidebar.
Hover over Tools & settings, then click Organization settings.
Click Security in the left sidebar, then select SSO settings.
Next to Enterprise-Managed Authorization, click Edit.
Click the toggle to enable Enterprise-Managed Authorization.