Summary
aura webserver can only be reached over HTTP and A2A. People working in Slack have no way to address an AURA agent: the Slack MCP server lets an agent call out to Slack, but nothing lets Slack call in. This adds a Slack ingress to the web server: with --enable-slack, the server opens a Socket Mode connection and answers @mentions and direct messages with the configured agent.
Behaviour
- A channel mention gets an eyes reaction and one reply in a thread under it. A follow-up in that thread carries the thread as history.
- A top-level DM gets an inline reply with the DM's recent messages as history. A threaded message anywhere is answered in its thread.
- A thread reply that does not mention the bot is answered only in threads the bot has already posted in, and only when the app subscribes to
message.channels and message.groups. An app without those events gets a mention-only bot in channels.
- History is rebuilt from Slack on every message, so the server stores nothing and restarts lose nothing.
- Every Socket Mode envelope is acked before processing; the bot's own messages,
bot_id messages, and system subtypes are ignored; a bounded (channel, ts) set collapses the DM mention double delivery and retries within one pod.
- Slack-driven runs count as active requests and take part in the two-phase shutdown like HTTP streams.
- Socket Mode is outbound, so no public URL is needed. Reconnects happen at once on Slack's refresh and warning disconnects and with exponential backoff on anything else.
Configuration
Deployment-scoped like A2A: --enable-slack, --slack-bot-token (xoxb-), --slack-app-token (xapp-, scope connections:write), --slack-agent, --slack-concurrency, each with an AURA_SLACK_* env var. Tokens are prefix-checked at parse time and never appear in Debug output. A config with a [hitl] block is rejected for this ingress.
The Slack app needs a bot user with app_mentions:read, chat:write, channels:history, groups:history, im:history, and reactions:write, the app_mention and message.im events (plus message.channels and message.groups for thread follow-ups), Socket Mode on, and the App Home Messages tab on and not read-only.
Out of scope, tracked separately
- Cross-pod dedupe: Slack delivers each payload to one of up to ten connections, so only the DM double delivery and unacked retries can cross pods. A durable claim in the session store is the follow-up.
- Search with the asker's permissions via
assistant.search.context and the event's action_token, replacing user-token search through the MCP server in shared workspaces.
- Hosted docs page in
mezmo/documentation.
- Markdown to mrkdwn conversion, the Slack Agents surface, streaming edits, the HTTP Events API, slash commands, interactive blocks.
Implementation
PR #748.
Summary
aura webservercan only be reached over HTTP and A2A. People working in Slack have no way to address an AURA agent: the Slack MCP server lets an agent call out to Slack, but nothing lets Slack call in. This adds a Slack ingress to the web server: with--enable-slack, the server opens a Socket Mode connection and answers @mentions and direct messages with the configured agent.Behaviour
message.channelsandmessage.groups. An app without those events gets a mention-only bot in channels.bot_idmessages, and system subtypes are ignored; a bounded(channel, ts)set collapses the DM mention double delivery and retries within one pod.Configuration
Deployment-scoped like A2A:
--enable-slack,--slack-bot-token(xoxb-),--slack-app-token(xapp-, scopeconnections:write),--slack-agent,--slack-concurrency, each with anAURA_SLACK_*env var. Tokens are prefix-checked at parse time and never appear inDebugoutput. A config with a[hitl]block is rejected for this ingress.The Slack app needs a bot user with
app_mentions:read,chat:write,channels:history,groups:history,im:history, andreactions:write, theapp_mentionandmessage.imevents (plusmessage.channelsandmessage.groupsfor thread follow-ups), Socket Mode on, and the App Home Messages tab on and not read-only.Out of scope, tracked separately
assistant.search.contextand the event'saction_token, replacing user-token search through the MCP server in shared workspaces.mezmo/documentation.Implementation
PR #748.