Skip to content
Benchmarks

redact-secret · Report · Detector

slack-user-token

  • 27 fixtures
  • Format evidence: T1 · Provider-documented
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

  • Provider documentation xoxp- user token, dash-separated sections, secret last · observed 2026-09-24 · the provider states user tokens begin with xoxp-, that tokens are dash-separated sections with the secret last, and shows a three-numeric-section example; it states no section widths or secret alphabet, says pre-August-2016 user tokens may carry 6- or 10-character secrets, and the 2016 token-lengthening changelog warns against relying on perceived token semantics
  • gitleaks 8.30.1
  • trufflehog 3.97.4
  • Reference 1
  • Reference 2

Lexical separability decided before authoring (#212): the provider-documented xoxp- prefix and the provider example's three dash-separated numeric sections followed by a secret section separate a user token from the recorded confusables (public T/U/B ids, masked sections, references, placeholders). The pattern deliberately freezes no numeric width and no secret alphabet or width: those are tool claims (gitleaks slack-user-token 10-13 digits and 28-34 [a-zA-Z0-9-]; noseyparker exactly 12 digits and 32 lowercase hex; trufflehog two sections and an open tail) and Slack says tokens may reach 255 characters. Twins therefore mutate only provider-documented properties (the xox stem and the p letter, the dash separator, the secret section itself). Kept separate and not claimed: rotating xoxe.xoxp- user/config tokens (scope undecided), the Slack CLI service-token xoxp-1-... shape, and the xoxc- browser session token. All three are real secrets and none is a control. The registry's detector-coverage slack-token shape-2 fixtures already carry xoxp- positives built to the product's frozen grammar; they target slack-token and are not this family's evidence.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of slack-user-token fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated10False alarmsat most 27.8%0 of 10 controls flagged10 quiet · 0 flagged
  • flare-redact at most 51.0%
  • gitleaks at most 40.4%
  • trufflehog at most 40.4%
Must not flag · Project policy6False alarmsat most 39.0%0 of 6 controls flagged6 quiet · 0 flagged
  • flare-redact at most 70.0%
  • gitleaks at most 39.0%
  • trufflehog at most 39.0%
Must redact · Provider-documented11Secret spans left readableat most 25.9%0 of 11 spansNear-twins told apartinsufficient-coverage5 of 5 pairs11 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 94.9%
  • gitleaks at most 25.9%
  • trufflehog at most 25.9%
27 of 27 rows
Fixtures
27
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

27 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in slack-user-token
FixtureKind and evidenceredact-secret
slack-user-token-audit-envslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-bearer-curlslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-bolt-installation-storeslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-curl-form-tokenslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-docs-placeholder-placeholderslack · documentation-placeholderMust not flagT3 · Project policyQuiet
slack-user-token-dotenvslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-dotted-sections-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-user-token-legacy-query-tokenslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-masked-sections-placeholderslack · documentation-placeholderMust not flagT3 · Project policyQuiet
slack-user-token-missing-secret-twinslack · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
slack-user-token-oauth-v2-accessslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-python-scim-clientslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-python-webclientslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-slack-loginslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-underscore-delimiter-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-user-token-auth-test-public-idslack · public-identifierMust not flagT2 · Tool-corroboratedQuiet
slack-user-token-base64-workspace-encoded-valueslack · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
slack-user-token-channel-ids-public-idslack · public-identifierMust not flagT2 · Tool-corroboratedQuiet
slack-user-token-env-reference-referenceslack · templated-referenceMust not flagT3 · Project policyQuiet
slack-user-token-legacy-short-secretslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-user-token-masked-log-placeholderslack · documentation-placeholderMust not flagT3 · Project policyQuiet
slack-user-token-prefix-only-near-missslack · format-near-missMust not flagT2 · Tool-corroboratedQuiet
slack-user-token-sdk-environ-referenceslack · templated-referenceMust not flagT3 · Project policyQuiet
slack-user-token-stem-prefix-twinslack · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
slack-user-token-token-guidance-proseslack · prose-mentionMust not flagT3 · Project policyQuiet
slack-user-token-uppercase-prefix-twinslack · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
slack-user-token-webhook-host-only-public-idslack · public-identifierMust not flagT2 · Tool-corroboratedQuiet