Slack
Connect your Slack workspace to Ploy to automatically discover your Slack users, the third-party apps installed in your workspace, your channels and user groups and who is in them, sign-in activity, and your Slack plan and billable seats. Once connected, Ploy can also manage access for you — adding and removing people from channels and user groups, creating channels, and inviting, updating and deactivating users.
Before you begin
You'll need a Slack administrator to authorise the connection. Ploy connects to Slack using OAuth, so there are no API keys to create — the administrator signs in to Slack and approves the requested permissions.
The permissions Ploy requests let it read your workspace's users (including email addresses), channels, user groups and billing information, and manage channel and user-group membership.
If your organization uses Slack Enterprise Grid, the wizard includes an optional second authentication with org-level admin permissions so Ploy can manage users across your whole organization. See the Enterprise Grid section below.
If you're a member of multiple Slack workspaces, double-check you're connecting the right one when Slack asks.
Connect Slack to Ploy
In Ploy, go to the Integrations page at https://app.joinploy.com/integrations, add the Slack integration and open the setup wizard.
Follow our setup instructions — that's this article, linked as Setup Instructions at the top of the first page.
Click Authenticate with Slack. A Slack administrator will need to do this. Make sure you are connecting your correct Slack workspace to Ploy, as it is common to be a member of multiple.
Approve the permissions Slack shows you. Once you're returned to Ploy, the connection is labelled with your Slack workspace's name.
In Team domain name, enter the domain name for your Slack workspace. Ploy uses it to create deeplinks to your resources — if your domain is xyz.slack.com, enter xyz here. This field is required: the page cannot be saved without it.
Save and continue to the next page of the wizard.
Enterprise Grid
The second page of the wizard has a single Enterprise Grid toggle. Enable it if you are on Slack Enterprise Grid and want Ploy to manage user access across your organization — this requires a second authentication with additional admin permissions.
If you are not on Slack Enterprise Grid, leave the toggle off and save. Your integration is now set up and Ploy will begin scanning.
If you are on Enterprise Grid, turn the toggle on and continue. The wizard adds a final page asking you to Authenticate Enterprise Grid — a second Slack authentication that grants Ploy org-level admin permissions to manage users across your organization. Follow our dedicated guide for this step: Slack Enterprise Grid. Once that authentication completes and you save, the integration is fully set up.
What data syncs
Users: everyone in your Slack workspace, with their name, email address, admin/owner status, whether the account is active, and whether they have two-factor authentication enabled.
Third-party apps: the apps installed in your Slack workspace and which users installed them — useful for discovering shadow IT.
Channels: your workspace's channels and who is a member of each one.
User groups: your Slack user groups and their members.
Sign-in activity: recent sign-ins to your workspace (Ploy looks back up to 90 days), so you can see who is actually using Slack.
Licenses: your workspace's Slack plan (Free, Pro, Business+ or Enterprise Grid) and which users are billable, powering Ploy's seat and cost insights.
Data syncs periodically to keep Ploy up to date.
What Ploy can do in Slack
Manage channel membership: add a user to, or remove a user from, a channel — for example when an access request is approved or access is revoked in Ploy.
Manage user group membership: add a user to, or remove a user from, a Slack user group.
Create channels: create a new channel, for example from a workflow.
Invite users: invite a new user to your workspace. On Enterprise Grid this uses Slack's org-level admin invite; otherwise it uses Slack's SCIM provisioning API, which Slack makes available on certain paid plans.
Update users: update a user's profile details (name, display name, timezone and similar) via Slack's SCIM API.
Deactivate users: remove a user from the workspace via Slack's SCIM API — for example as part of offboarding. On Enterprise Grid this uses the org-level authentication.
Troubleshooting
"Required" next to Team domain name
The Team domain name field must be filled in before the first page can be saved. If your workspace address is xyz.slack.com, enter xyz.
"Missing valid access token"
The Slack authentication did not complete successfully, so Ploy has no valid token for your workspace. Click Authenticate with Slack on the first page of the wizard and complete the authorisation again.
"Slack authentication failed - token may be invalid or expired" or "Slack token has been revoked - please reconnect the integration"
Slack is no longer accepting the connection's token — this can happen if the authorising admin deactivated the connection in Slack or left the workspace. Open the integration in Ploy and authenticate with Slack again.
"Integration incorrectly setup. Missing valid Team ID please re-authenticate with Slack"
The connection is missing your workspace's details. Open the integration and click Authenticate with Slack again, making sure you pick the correct workspace.
"Invalid enterprise token. Please re-authenticate with Enterprise Grid permissions." or "Insufficient permissions. Ensure the enterprise token has SCIM admin access."
An Enterprise Grid user-management action failed because the org-level authentication is missing or lacks admin access. Re-run the Authenticate Enterprise Grid step in the wizard as an org admin — see Slack Enterprise Grid.
License or seat data is missing
Ploy's billing permission was added after some connections were first set up. If your Slack connection predates it, click Authenticate with Slack again so the connection picks up the extra permission.