<!-- llms-explorer concept facts · https://llms-explorer.com/tree/slack-developer-platform/ · pack 2026-09-08 · ~6011 tokens -->

# Slack Developer Platform

> Use when building Slack apps, calling Web API methods, building Block Kit UIs, handling Events, configuring OAuth, or using the Slack MCP server. For auditing slash command registrations, orphaned sub

Parent: [SaaS APIs & Integrations](https://llms-explorer.com/tree/saas-apis-integrations/) · 32 facets · 91 facts · page: https://llms-explorer.com/tree/slack-developer-platform/

## When to use this skill

- Use when building Slack apps, calling Web API methods, building Block Kit UIs, handling Events, configuring OAuth, or using the Slack MCP server. For auditing slash command registrations, orphaned subscriptions, or bot token scope creep, use slack-subscription-auditor instead. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#when-to-use-this-skill)

## Core Concepts

- Web API - HTTP RPC at https://slack.com/api/METHOD.name. NOT REST. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)
- Events API - Slack POSTs events to your URL when things happen. Requires URL verification challenge. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)
- Socket Mode - WebSocket-based alternative to Events API. No public URL needed. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)
- Block Kit - JSON schema for rich UI in messages, modals, and Home tab. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)
- Interactive Components - Buttons, select menus, modals. Slack POSTs interaction payloads to your app. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)
- Slash Commands - /command invocations. Slack POSTs form data to your URL. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#core-concepts)

## Request/Response Pattern

- Always check ok: true before using response data. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#requestresponse-pattern)

## Token Rotation

- Opt in via App Settings → Manage Distribution → Rotate Tokens. Expiring tokens include refresh_token; call tooling.tokens.rotate before expiry. All tokens can be revoked with auth.revoke. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#token-rotation)

## 3. Slack CLI Reference

- Install: curl -fsSL https://downloads.slack-edge.com/slack-cli/install.sh | bash — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#3-slack-cli-reference)

## 4. Web API

- Base URL: https://slack.com/api/ Auth: Authorization: Bearer <token> header (never query string) — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#4-web-api)

## Rate Limits

- On 429, Slack returns Retry-After header. Always implement exponential backoff. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#rate-limits)

## chat.postMessage — Key Arguments

- Response includes ts (unique message ID) and channel. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#chatpostmessage-key-arguments)

## Setup

- App Config → Event Subscriptions → Enable Events — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#setup)
- Set Request URL (must respond to verification challenge) — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#setup)
- Subscribe to events (bot / workspace scopes) — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#setup)

## Interaction Payloads

- POSTed to your interactivity_url: — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#interaction-payloads)
- trigger_id expires in 3 seconds - use immediately to open modals. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#interaction-payloads)

## 6. Socket Mode

- Requirements: Enable Socket Mode in App Config; generate an App-Level Token (xapp-) with connections:write scope. App cannot be published to Slack Marketplace. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#6-socket-mode)
- Multi-connection: Up to 10 simultaneous WebSocket connections per app. All connections receive identical events. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#6-socket-mode)

## Blocks (Top-Level)

- Limits: 50 blocks per message, 100 per modal/Home tab. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#blocks-top-level)

## 8. Modals and Views

- View stack operations: views.open (requires trigger_id) → views.push → views.update. Stack limit: 3 views deep. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#8-modals-and-views)
- Handling submission: — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#8-modals-and-views)
- Private metadata: max 3000 chars, URL-encoded string. Use JSON.stringify({}) to pass structured data. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#8-modals-and-views)

## Bolt for JavaScript

- Required env vars: — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#bolt-for-javascript)

## 10. Slack MCP Server

- Transport: JSON-RPC 2.0 over Streamable HTTP — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#10-slack-mcp-server)
- Endpoint: https://mcp.slack.com/mcp — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#10-slack-mcp-server)
- Auth: Confidential OAuth 2.0 (user tokens) — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#10-slack-mcp-server)
- Availability: Marketplace-published and internal apps only (unlisted apps prohibited) — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#10-slack-mcp-server)

## Config

- Partner MCP clients: Claude.ai, Claude Code, Perplexity, Cursor. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#config)

## 11. Agents and AI Apps

- Enable: App Settings → Agents & AI Apps → Toggle on. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#11-agents-and-ai-apps)

## Key Events for Agents

- Required scopes: assistant:write, chat:write, im:history — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#key-events-for-agents)

## 12. Real-Time Search (RTS) API

- GA February 2026. Allows real-time searches across Slack workspace data for AI agent RAG patterns without external data storage. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#12-real-time-search-rts-api)
  - Availability: Directory-published and internal apps only — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#12-real-time-search-rts-api)
  - Auth: User token (xoxp-) required - bot tokens not supported — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#12-real-time-search-rts-api)
  - Use case: AI agent RAG, context retrieval, real-time data freshness — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#12-real-time-search-rts-api)
- Launch partners: Claude.ai, Google Agentspace, Dropbox Dash, Perplexity Enterprise, Notion AI. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#12-real-time-search-rts-api)

## 13. Work Objects

- GA October 2025. Transform static content from third-party services into interactive, dynamic experiences combining unfurls with a rich flexpane detail view. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#13-work-objects)

## Implementation Flow

- Docs: https://docs.slack.dev/messaging/work-objects — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#implementation-flow)

## 15. Deprecation and Migration Timeline

- Classic apps → Granular permissions: Map each classic scope to its granular equivalent. New apps require OAuth with granular xoxb- tokens. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#15-deprecation-and-migration-timeline)

## 16. Sources

- Slack Developer Docs — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Slack Web API Reference — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Slack CLI Docs — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Slack MCP Server — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Agents & AI Apps — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Work Objects — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- RTS API — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)
- Changelog — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#16-sources)

## 17. 2026 Q1–Q2 Platform Delta (added 2026-06-10)

- Verified against the official changelog (docs.slack.dev/changelog) and Slack dev blog, accessed 2026-06-10. Confidence tags as elsewhere. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Slack MCP Server expanded (2026-05-13): tool surface now 13 - added add_reaction, create_conversation, list_channel_members, list_emoji, read_files; per-app toggle via manifest settings.is_mcp_enabled (CLI 4.1.0). Directory-published or internal apps only. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Block Kit agent components: Alert, Card, Carousel blocks (2026-04-16); data table block GA (2026-05-20); "Thinking Steps" streaming chunks (task_card/plan/url-source via chat.startStream/appendStream/stopStream, chunks + task_display_mode params, 2026-02-11); Work Object slugs/unfurls + Code block announced. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Agent Developer Kit / CLI 4.x (2026-04-10+): slack create agent templates (Bolt JS/Python × Claude Agent SDK / OpenAI Agents SDK / Pydantic AI, MCP pre-wired); slack env commands, slack docs search, file-watch live reload; generic slack api <method> (4.1.0) and --no-auth (4.2.0, 2026-06-03); Bolt JS 4.7.x / Bolt Python 1.28.0 add sayStream + listener setStatus. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Auth deltas: PKCE GA (2026-03-30) - public-client flag is one-way; custom-URI installs always receive rotating tokens; PKCE refresh tokens expire after 30 days; desktop redirects can't request bot scopes. Optional OAuth scopes GA (2026-03-16) via oauth_config.scopes.bot_optional/user_optional - handle missing_scope. assistant.threads.setStatus now prefers chat:write; assistant:write on that method will eventually be dropped (2026-03-05). [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - New Web API params (2026-06-03): authorship (icon_emoji/icon_url/username) on assistant.threads.setStatus + chat.startStream; highlight_type on files.completeUploadExternal/filesUploadV2. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Events API: Delayed Events retry (2026-02-05) replays events missed during app outages. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Rate limits: the 1 req/min / 15-object conversations.history/replies limit for commercially distributed non-Marketplace apps reportedly extended to EXISTING unlisted installs on 2026-03-03, ending grandfathering (practitioner-corroborated; the live doc page wording lags - [MEDIUM]). Internal apps and Marketplace apps remain exempt. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - SUPERSEDES §15 row: the classic-app sunset (table above says Nov 16, 2026) was paused indefinitely on 2025-12-08 - classic apps continue to work; no new ones can be created. [HIGH] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Deno SDK: alive (2.15.2, 2026-02-26) but de-emphasized - agent templates are Bolt-only; Bolt is the strategic path. [MEDIUM] — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)
  - Ecosystem sentiment [MEDIUM]: prominent criticism (Fivetran "Anthropic, please make a new Slack"; HN 2026-06) that rate limits + RTS no-store/no-train terms wall customer data off from external AI; Marketplace listing is the only viable path for history-reading commercial apps. — [source](https://llms-explorer.com/sources/mdb-context-hub/slack-dev/#17-2026-q1q2-platform-delta-added-2026-06-10)

## Where this helps

- Building a Slack app that posts messages via chat.postMessage and needs to handle the ok:true/false response pattern correctly. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Choosing between the Events API (public URL plus verification challenge) and Socket Mode (WebSocket, no public URL) for receiving Slack events. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Building an interactive Block Kit modal flow, where trigger_id expires in 3 seconds and the view stack (open → push → update) is limited to 3 levels deep. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Deciding whether to build against the Slack MCP server (JSON-RPC 2.0 over Streamable HTTP) for an AI agent integration versus the classic Web API for a traditional app. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Build a Bolt for JavaScript app that subscribes to an event, handles the URL verification challenge, and posts a threaded reply using chat.postMessage. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a Socket Mode app (App-Level Token with connections:write) for a use case that can't expose a public HTTP endpoint, and test its multi-connection behavior (up to 10 simultaneous connections). — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a multi-step Block Kit modal (views.open then views.push) that passes structured state through the 3000-character private_metadata field. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Wire an AI agent to the Slack MCP server's tool surface (e.g. add_reaction, create_conversation, list_channel_members) and test its behavior against a real workspace. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Antipatterns

- Not checking ok: true on every Web API response before using the returned data, silently propagating a failed call as if it succeeded. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Passing the auth token in the query string instead of the Authorization: Bearer header, which is both discouraged and a credential-leakage risk. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Not implementing exponential backoff on HTTP 429 responses and Slack's Retry-After header, hammering the API and getting further rate-limited. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Publishing a Socket Mode app to the Slack Marketplace, which is not supported — Socket Mode apps are workspace-internal by design. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- trigger_id expires in 3 seconds, so any modal-opening flow has to call views.open almost immediately after receiving the interaction payload — no room for a slow intermediate step. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Block Kit imposes hard limits (50 blocks per message, 100 per modal/Home tab), so a data-dense UI can hit the ceiling and need pagination or a different layout. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- The classic-apps-to-granular-permissions migration means older integrations built on classic scopes need each scope re-mapped to its granular equivalent, and new apps are required to use OAuth with granular xoxb- tokens. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Several newer surfaces (Real-Time Search API, Work Objects, Block Kit agent components) are recent 2025-2026 additions with narrower availability — e.g. Real-Time Search requires a directory-published or internal app and a user token, not a bot token. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Where this helps

- Building a Slack app that posts messages via chat.postMessage and needs to handle the ok:true/false response pattern correctly. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Choosing between the Events API (public URL plus verification challenge) and Socket Mode (WebSocket, no public URL) for receiving Slack events. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Building an interactive Block Kit modal flow, where trigger_id expires in 3 seconds and the view stack (open → push → update) is limited to 3 levels deep. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Deciding whether to build against the Slack MCP server (JSON-RPC 2.0 over Streamable HTTP) for an AI agent integration versus the classic Web API for a traditional app. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Build a Bolt for JavaScript app that subscribes to an event, handles the URL verification challenge, and posts a threaded reply using chat.postMessage. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a Socket Mode app (App-Level Token with connections:write) for a use case that can't expose a public HTTP endpoint, and test its multi-connection behavior (up to 10 simultaneous connections). — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Build a multi-step Block Kit modal (views.open then views.push) that passes structured state through the 3000-character private_metadata field. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Wire an AI agent to the Slack MCP server's tool surface (e.g. add_reaction, create_conversation, list_channel_members) and test its behavior against a real workspace. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Antipatterns

- Not checking ok: true on every Web API response before using the returned data, silently propagating a failed call as if it succeeded. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Passing the auth token in the query string instead of the Authorization: Bearer header, which is both discouraged and a credential-leakage risk. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Not implementing exponential backoff on HTTP 429 responses and Slack's Retry-After header, hammering the API and getting further rate-limited. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Publishing a Socket Mode app to the Slack Marketplace, which is not supported — Socket Mode apps are workspace-internal by design. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- trigger_id expires in 3 seconds, so any modal-opening flow has to call views.open almost immediately after receiving the interaction payload — no room for a slow intermediate step. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Block Kit imposes hard limits (50 blocks per message, 100 per modal/Home tab), so a data-dense UI can hit the ceiling and need pagination or a different layout. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- The classic-apps-to-granular-permissions migration means older integrations built on classic scopes need each scope re-mapped to its granular equivalent, and new apps are required to use OAuth with granular xoxb- tokens. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Several newer surfaces (Real-Time Search API, Work Objects, Block Kit agent components) are recent 2025-2026 additions with narrower availability — e.g. Real-Time Search requires a directory-published or internal app and a user token, not a bot token. — [source](https://llms-explorer.com/tree/slack-developer-platform/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [Slack Developer Platform](https://llms-explorer.com/downloads/sources/mdb-context-hub/slack-dev.md)
