Slack agents that answer in the thread they were asked in

Create a Slack app from Qoren's manifest once, paste its bot token and signing secret, and click Verify. Qoren then wakes an agent on mentions, direct messages, channel posts and reactions, and lets it read threads and reply.

Request early accessSee pricing

Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations

How do I connect Slack to an AI agent?

Open Qoren's prefilled Slack link to create an app from its manifest, install it to your workspace, and paste the bot token and signing secret in Qoren. The connection then shows its request URL and an updated manifest: paste that in the app's App Manifest page, choose Save Changes and click Verify. Events start once Slack's check passes. Last, invite the bot with /invite @Qoren to each channel it should hear. Posting to a channel shared with another organization always asks first.

What agents do with Slack

Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.

For agencies running it for clients

  • An agent in the client's Slack

    When someone mentions the bot, the agent reads the thread and replies in it, so the client's team asks where they already work.

    Wakes on
    Bot mentioned
    Uses
    Read a thread
    Reply in a thread
  • A reaction turns a message into a task

    When someone adds a chosen emoji to a message, the agent reads the thread and files it where the work is tracked. A condition on the emoji keeps other reactions quiet.

    Wakes on
    Reaction added
    Uses
    Read a thread
    Reply in a thread

For founders running it for themselves

  • Ask your agent in a direct message

    Send the bot a direct message and the agent answers there, with the same tools and approvals it has everywhere else.

    Wakes on
    Direct message
    Uses
    Post a message

The path one event takes

5 Slack events that can wake an agent

Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.

EventWhen it fires
Bot mentionedSomeone mentions the bot (@Qoren) in a channel it was invited to.
Direct messageSomeone sends the bot a direct message.
Message in a public channelSomeone posts in a public channel the bot was invited to, mentions included.
Message in a private channelSomeone posts in a private channel the bot was invited to, mentions included.
Reaction addedSomeone adds an emoji reaction to a message in a channel the bot is in. Add a condition on event.reaction to react to one emoji.

4 tools agents can use

Curated Slack tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.

ToolWhat it doesAccessApproval
Read a threadRead one Slack thread the bot can see (the one an event came from): its first message and replies, at most 50.ReadNone
Post a messagePost a message in a channel or direct message the bot is in. Not for channels shared with another organization.WritePer autonomy setting
Reply in a threadReply in a Slack thread the bot is in. Not for channels shared with another organization.WritePer autonomy setting
Post to a shared channelPost in a channel shared with another organization (Slack Connect), optionally in a thread. Always asks a person to approve first.WriteAlways asks

How connecting Slack works

  1. 01Make a Slack key with the least access it needs, following the guide below. Only the account owner can connect a tool.
  2. 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where Slack says, when it expires.
  3. 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
  4. 04Finish the one-time Slack setup the connection shows, then pick the events that should wake the agent.

Making the Slack key

  1. 1

    Create the app from Qoren's manifest

    Open this link: Slack's create app page, prefilled with Qoren's manifest. Pick your workspace and choose Create. The manifest asks only for the scopes Qoren needs and keeps token rotation off.

    Qoren's connect dialog links straight to this page in Slack.

  2. 2

    Install it to your workspace

    Open OAuth & Permissions, choose Install to Workspace and then Allow.

  3. 3

    Copy the bot token and the signing secret

    Copy the Bot User OAuth Token (it starts with xoxb-) from OAuth & Permissions, and the Signing Secret from Basic Information > App Credentials. Paste both here. Never send them by email or chat.

  4. 4

    Turn on events after you connect

    Once connected, this connection shows its own request URL, an updated manifest and a short checklist. In the app's App Manifest page, replace everything with that manifest and choose Save Changes. When Slack asks you to verify the new request URL, click Verify: Slack events start once that check passes. Then type /invite @Qoren in each channel your agents should hear. Direct messages to the bot need no invite.

Slack setup guide, with screenshots

Connecting a client's account? Send a link

An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.

Client connect links

Security in plain words

  • Keys never reach the agent's machine

    The Slack key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to Slack. It is never written to the agent's environment, and after you connect only its last four characters are shown.

  • Read only until you say otherwise

    Each agent gets read only or read and write access, granted one agent at a time. The Slack key itself can be limited too, and the guide asks for the least it needs.

  • Risky actions always ask

    In Slack, these always wait for a person's approval, whatever the agent's autonomy setting: post to a shared channel.

  • Capped reads and a full audit log

    By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.

  • Event data is treated as data

    Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.

  • Stored events expire

    Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.

Slack limits worth knowing

When you disconnect, Qoren cannot revoke the key at Slack, so it tells you where to delete it. In Slack, open your apps, choose the Qoren app and delete it under Basic Information, or reinstall it to get a new token.

  • Slack is the one tool with a manual step: create the app from the manifest, then paste the updated manifest and click Verify. Slack does not verify the request URL by itself.
  • The bot only sees channels it was invited to.
  • Posting to a channel shared with another organization (Slack Connect) always asks, and the bot never pings @channel, @here or @everyone.

Frequently asked questions

How is this different from chatting with an agent in Slack?

A Slack chat channel lets you talk to a Hermes or OpenClaw agent through its own bot. The Slack integration wakes any agent you grant on Slack events and gives it curated Slack tools, with approvals and an audit log.

Connect Slack as a chat channel
Why do I have to click Verify in Slack?

Slack asks you to verify an app's request URL yourself once it is in the manifest. Until that check passes, Slack sends no events. Qoren answers the check only after confirming it was signed with your app's signing secret.

Does my agent ever see the Slack key?

No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to Slack. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.

Can an agent post to a shared channel without asking?

No. In Slack, these tools always wait for a person's approval, whatever the agent's autonomy setting: post to a shared channel. The approval shows the exact details the agent wants to send.

Approvals
What happens when I disconnect Slack?

Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at Slack, so it shows you where to delete it: In Slack, open your apps, choose the Qoren app and delete it under Basic Information, or reinstall it to get a new token.

What does the Slack integration cost?

Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.

Qoren pricing

Connect Slack once. Let agents handle the rest.

Integrations is in early access, turned on account by account. Request it and tell us how your agents should use Slack.