Slack MCP Integration

You can integrate Slack MCP with ThreatStream Next Gen to send PIR updates and results directly to Slack channels and direct messages. This allows you to share intelligence, notify stakeholders, and keep teams aligned without leaving ThreatStream Next Gen.

Activating Slack MCP Integration

To start using Slack integration in ThreatStream Next Gen, you need to activate the Slack MCP Endpoint integration on the Integrations Marketplace page.

Before You Begin

Before configuring Slack MCP integration, you must:

  1. Navigate to https://api.slack.com/apps and create an OAuth app from scratch to authenticate to the remote MCP server from Threatstream Next Gen. For details, see Creating an app.

  2. After creating an app, add the following permission scopes to your app:

    • search:read.public
    • search:read.private
    • users:read
    • chat:write

  3. Add the following MCP server URL to your app configuration:
    • https://api.threatstream.com/api/v1/mcp_integration/oauth_callback/ (US Cloud)
    • https://api-eu.threatstream.com/api/v1/mcp_integration/oauth_callback/ (EU Cloud)
  4. Generate a User OAuth Token.
    Note that a Bot User OAuth Token will not work. If a User OAuth Token is not available, you must reinstall the app to generate a User OAuth Token.
Note: If you plan to use the OAuth 2.0 method of authentication, copy and save Client ID and Client Secret for the app you created.

To configure Slack MCP integration:

  1. Navigate to ThreatStream Next Gen > Integrations Marketplace.
  2. Locate the Slack MCP tile.
  3. Click the three-dot vertical menu and then click Configure.

  4. Provide a Slack MCP Name.
  5. Enter the MCP Server URL:
    https://mcp.slack.com/v1
  6.  Select an Authentication TypeUser Token or OAuth 2.0 - Manual Client Registration.
  7.  Enter one of the following:

    • If you selected User Token as your authentication type, enter your user OAuth token.
    • If you selected OAuth 2.0 - Manual Client Registration as your authentication type, enter your Client ID and Client Secret.

  8. Click Save.


    The Slack MCP Integration is configured and is now ready for use. You can now configure your PIRs to send their results to public Slack channels or direct messages. For details on enabling Slack integration in PIRs, see Configuring Slack Output.