Skip to content

Slack

Connect Slack to vScope to inventory the user accounts in your Slack workspace, including admins, bots, and deactivated users.

  • A standard Slack workspace where you can create and install an app. Slack Enterprise Grid, where apps are installed at the organization level, is not covered by this page.
  • A Slack app with a token that has the users:read and users:read.email OAuth scopes (added in Create a Slack app and token).
  • Network access from the vScope server or Discovery Proxy to https://slack.com over HTTPS (port 443).
  1. Go to Slack API: Your Apps and sign in.
  2. Click Create New App > From scratch.
  3. Name the app, for example vScope, select your workspace, and click Create App.
  4. In the app, go to OAuth & Permissions.
  5. Under Scopes > Bot Token Scopes, add:
    • users:read
    • users:read.email
  6. Click Install to Workspace and approve the requested permissions.
  7. Copy the Bot User OAuth Token (it starts with xoxb-).
  1. In vScope, go to Discovery > Credentials.
  2. Click Create credential and choose Slack.
  3. In OAuth Token, paste the Bot User OAuth Token you copied (for example xoxb-...). Enter only the token. vScope adds the Bearer prefix automatically.
  4. Optional: add a Note to describe the credential.
  5. Optional: assign a Proxy if vScope should connect to Slack through a Discovery Proxy.
  6. Click Test Credential.
  7. Save the credential and run discovery.

After discovery completes, the Slack accounts appear under User Account in vScope.

Slack returns invalid_auth or not_authed when the token is wrong or expired. Confirm that the OAuth Token is a current, valid token (for example xoxb-...) and has not been revoked in Slack.

Permission or scope errors, or missing email addresses

Section titled “Permission or scope errors, or missing email addresses”

Slack returns missing_scope when the token lacks a required scope. Confirm the app has both users:read and users:read.email, then reinstall the app so the scopes take effect.

If accounts are inventoried but emails are empty, the token is missing users:read.email. Add the scope, reinstall the app, and run a new discovery.

If the credential test succeeds but the inventory is incomplete:

  1. Confirm the token has the required scopes (see above).
  2. Confirm the vScope server or Discovery Proxy can reach https://slack.com on HTTPS (port 443).
  3. Run a new discovery.