Skip to main content

Overview

Slack is not an app connection. Agents never call the Slack API as a tool, and there is no Slack credential to grant. It is a channel: a place where people talk to agents, in the same threads they already use for everything else. Two things live here. Agents answer in Slack, and they ask for approval there, so the person who has to decide gets the question where they already are instead of in a dashboard they would have to remember to open. Connecting takes one click.

Connect Slack

1

Install the OneCLI app

In OneCLI, open Settings > Channels and select Add to Slack.
The Team onboarding card in OneCLI, showing a Not installed badge, an Add to Slack button, and a link to connect with an App Configuration token instead.

Team onboarding, on the Channels page in OneCLI.

Slack’s consent page opens. If your workspace requires admin approval for new apps, the install completes on its own once an admin approves it, with nothing more to do in OneCLI.
2

Let teammates onboard themselves

Once installed, anyone in the workspace can DM the OneCLI app to get their own OneCLI account. No invitation, and no admin step per person.
Installing the app is an org-level action, so it needs someone who can install Slack apps in your workspace. After that, individual teammates need nothing.

What happens in Slack

Who may talk to an agent is still yours to set. An agent reached by someone new raises a reach request rather than answering, and you choose each time.

Controlling access

Slack changes where the conversation happens, not what an agent may do. Its grants and your organization rules apply to every message, whether it arrived from Slack or the dashboard, and anything needing approval still waits for a human. The card is the point. An agent about to send an email or spend money asks in the channel, and whoever is there answers in a click. To disconnect, open Settings > Channels and remove the installation. You can also remove the OneCLI app from Slack’s own app management page, which revokes its workspace token.

Self-hosted: use your own Slack app

Skip this section on OneCLI Cloud. The shared app is already approved and installed in one click.
A self-hosted deployment has no shared OneCLI Slack app, so it creates its own. OneCLI does the creating, and you supply one short-lived token to let it.
  1. Open api.slack.com/apps.
  2. Select Generate Token and pick your workspace.
  3. Copy the Refresh Token, not the Access Token.
Slack's App Configuration Tokens table, with the Refresh Token column's Copy button highlighted next to the Access Token's identical button.

The two Copy buttons look identical. Check the column heading.

Open Settings > Channels and paste the token. OneCLI uses it to create the Slack app for your agents, then rotates it from then on.Paste it promptly. Each refresh token works only once, and a used or expired one has to be regenerated from the same page.
An App Configuration token can create and modify Slack apps in your workspace, so treat it like a password. It is also the only part of this setup that differs from Cloud, everything above this divider works the same way once the app exists.

Listing your app on the Slack Marketplace

Only relevant if you run your own Slack app and want to distribute it beyond your workspace. Slack reviews every listing, and its guidelines ask for a few pages you have to supply yourself. For OneCLI Cloud these already exist: onecli.sh is the landing page and onecli.sh/privacy the policy.
Slack asks for an extra disclaimer when an app exposes people to a language model: say on the landing page and in the long description that outputs can be inaccurate. Slack also forbids training models on Slack data. Both matter for an agent app.
Expect scope questions during review. Slack approves only scopes tied to features it can test and asks what each one is for, so keep the list to what the app actually uses.