Slack bridge for Orkestia MCP
Slack is not a direct client for this MCP server today. The production path is a Slack app or bot bridge that calls Orkestia agent-ops or the workflow MCP server with a scoped service token.
Flow
- A Slack user mentions the Orkestia app or runs a slash command.
- The bridge validates Slack's request signature.
- The bridge maps Slack team, channel, and user to an Orkestia actor and organization.
- The bridge calls agent-ops or the MCP server with a scoped service token.
- The bridge posts a concise result back to Slack.
Security requirements
- Validate Slack signing secrets on every request.
- Do not expose MCP bearer tokens to Slack clients.
- Use per-workspace or per-organization service tokens.
- Require human approval for channel-visible writes and destructive workflow actions.
- Write audit records with Slack team, channel, user, command, and Orkestia actor.
When to call MCP directly
Call MCP directly only from the bridge backend, and only when the bridge already resolved the Orkestia organization and actor. For richer conversations, route through agent-ops so policy, approval, and memory stay centralized.
