redact-secret · Report
App-level token
App-level token, prefixed xapp-.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^xapp-[0-9]+-[A-Za-z0-9]+-[0-9]+-[A-Za-z0-9]+$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Unresolved ·
candidate-source· current · observed 2026-09-24Candidate provider source, not accepted as the provider source by the legacy contract (xapp- app-level token prefix): the xapp- prefix only; no section widths, alphabet or length
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports the xapp- prefix only; no section widths, alphabet or length
Tool corroborated ·
tool-corroboration· current · observed 2026-09-24Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; osv-scalibr veles).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: slack-app-token
- google/osv-scalibr @ main: veles/secrets/slacktoken/detector.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports osv-scalibr veles: slacktoken
Provider documented ·
field-prefix· current · observed 2026-09-24prefix: App-level tokens begin with the literal xapp-.
- docs.slack.dev/apis/events-api/using-socket-modeprovider-documentation · last read 2026-09-29 · latest outcome read · supports Placeholders only (SLACK_APP_TOKEN='xapp-***', Authorization: Bearer xapp-1-123); the token goes in the Authorization header.
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports "App-level token strings begin with xapp-." No section widths, alphabet, length or example.
Provider documented ·
field-section-structure· current · observed 2026-09-24section-structure: After the prefix: a digit section, then three more dash-separated sections (digit, alphanumeric, digit, alphanumeric). (Provider-authored placeholders disagree on whether the version section exists; no provider page states section count. The contract pattern uses this 4-section order with open widths only so positives are well-formed; no twin or control removes the version section or asserts silence on the python-mock order.)
- gitleaks/gitleaks @ master: cmd/generate/config/rules/slack.goprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports gitleaks SlackAppLevelToken (?i)xapp-\d-[A-Z0-9]+-\d+-[a-z0-9]+, "based on a limited number of examples".
- github.com/slackapi/java-slack-sdkprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Java SDK socket-mode guide/sample placeholder xapp-1-<A+3>-<3 digits>-<3 x>: version digit first. Placeholder widths are not real.
- github.com/slackapi/python-slack-sdkprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Contradiction: the python SDK socket-mode mock uses xapp-<A+3>-<3 digits>-<3 lower> with no version section.
- github.com/slackapi/slack-cliprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports internal/goutils/strings_test.go placeholder xapp-1-<A+3>-<4 digits>-<4 upper>.
Unresolved ·
field-section-widths· current · observed 2026-09-24section-widths: Section widths 1 / 11 / 13 / 64 (97 characters total). (Not frozen. Positives use 1/11/13/64 so they satisfy gitleaks, veles/kingfisher, the product's interim xapp-[A-Za-z0-9_-]{20,} floor and Slack CLI's prefix-only redaction; they cannot also satisfy Nosey Parker's 2-section shape, which is recorded, never asserted against: no fixture uses a 42-character xapp- value.)
- google/osv-scalibr @ main: veles/secrets/slacktoken/detector.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports veles xapp-\d{1,10}-[A-Za-z0-9]{11}-[0-9]{13}-[a-fA-F0-9]{64}; "presumably" hedges the version width.
- github.com/mongodb/kingfisherscanner-rule-source · last read 2026-09-24 · latest outcome read · supports Kingfisher imports the identical regex (not independent).
- praetorian-inc/noseyparker @ main: crates/noseyparker/data/default/builtin/rules/slack.ymlprovider-documentation · last read 2026-09-24 · latest outcome read · supports Contradiction: np.slack.5 \b(xapp-[0-9]{12}-[a-zA-Z0-9/+]{24})\b — two sections, 42 characters.
Unresolved ·
field-alphabet· current · observed 2026-09-24alphabet: Section 2 uppercase alphanumeric (app-ID-like); final section lowercase hex. (Not frozen; the pattern accepts any alphanumeric in sections 2 and 4. No fixture twins on tail case or width.)
- gitleaks/gitleaks @ master: cmd/generate/config/rules/slack.goprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Case-insensitive; TP samples use lowercase hex tails. Two of three cited samples do not start section 2 with "A", so "section 2 is the App ID" is not consistently supported.
- google/osv-scalibr @ main: veles/secrets/slacktoken/detector.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports Accepts [a-fA-F0-9] for the tail.
Unresolved ·
field-app-id-embedding· current · observed 2026-09-24app-id-embedding: Whether section 2 equals the public App ID. (An App ID alone is a public identifier and is used as a public-id control; nothing asserts it is or is not embedded.)
- google/osv-scalibr @ main: veles/secrets/slacktoken/detector.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports Calls section 2 "an app ID" without a source.
Unresolved ·
listed-references· current · observed 2026-09-24The legacy contract lists 3 references without stating which property each supports.
- docs.slack.dev/apis/events-api/using-socket-modeprovider-documentation · last read 2026-09-29 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/redact-secret/redact-secret-benchmarks/issues/222issue-or-discussion · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
- github.com/slackapi/slack-cliprovider-sdk-source · last read 2026-09-24 · latest outcome read · supports Listed as a reference by the legacy contract
Tool corroborated ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict ready, tier T2) cited 5 sources; the dossier does not attribute sources to individual properties.
- docs.slack.dev/apis/events-api/using-socket-modeprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ add1188fed9993723c59fbce8c867086b9d2049a: docs/audits/evidence/1013/slack-app-level-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- slackapi/java-slack-sdk @ 49b62a6b866bf43eb4c3bfe9c8423a65400d2928: docs/english/guides/socket-mode.mdprovider-documentation · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L180
- slackapi/slack-cli @ 20dd73092a65d3797180f95f0ee765053d7ef634: internal/goutils/strings_test.goprovider-sdk-source · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L198-L202
Unresolved ·
taxonomy-sources· current · observed 2026-09-29The legacy taxonomy lists 1 source for this family. The taxonomy records no date; the dossier researchedAt is used as the observed-at date.
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Listed as a source for this family in the legacy taxonomy
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
xapp-. Tools and provider placeholders suggest a one-digit version section, an app-id-like section, a 13-digit section and a 64-hex secret (97 characters), but no provider text states any of it. The contract freezes only four sections in digit, alphanumeric, digit, alphanumeric order with open widths. - Basis
- T1 for the prefix and role (tokens page, Socket Mode guide, which shows
Authorization: Bearer xapp-1-123). Everything else is T2 or weaker. gitleaks' rule ((?i)xapp-\d-[A-Z0-9]+-\d+-[a-z0-9]+, 2023-06-15, "based on a limited number of examples") fixes the four-section order with open widths; 1/11/13/64 is only its test samples, taken from a third-party repository, not a width it enforces (an earlier reading said gitleaks and osv-scalibr agree on 1/11/13/64; corrected by redact-secret#1013). osv-scalibr is the rule that fixes those widths, Kingfisher's rule is an import of it, Docker portcullis (2026-05-08) states the four-segment shape with its own ranges, and Nosey Parker's rule is two sections and 42 characters. Slack's own placeholders disagree: four sections in the Java SDK guide and sample and the Slack CLI tests, one to three elsewhere (Socket Mode page, bolt fixtures). - Issuance
- Basic Information > App-Level Tokens, scope chosen at creation (
connections:write,authorizations:read,app_configurations:write). Not attempted. - Contract in core
- detector-families.md (Beta.8 wave 1, empirical route).
In this benchmark
- Fixtures
- 40
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
40 fixtures: 17 expect a redaction, 23 must stay quiet. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T2Tool-corroborated | 32 | 0 | 0 | 0 |
| T3Project policy | 8 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engineNo rule maps to it | 40 | 15 | 1 | 1 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules1 rule targets it | 40 | 0 | 0 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 40 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabledNo rule maps to it | 40 | 17 | 0 | 0 |
Benchmark dossier questions
- Open caveat
- Only the xapp- prefix is provider-documented; the four-section order rests on peer rules and Slack placeholders that disagree with other Slack placeholders, and widths stay open (osv-scalibr 1/11/13/64, Docker 1/8-16/8-16/32-128 hex, Nosey Parker two sections). READY-T2 only if ruling Q-SL accepts the four-section placeholders; otherwise one issued token (#222 checklist, restated in #1013).
Looks like it, but isn't
- Collisions
xoxa-2-and other sectioned Slack prefixes share the skeleton;xapp-storeand similar words are not tokens; app config tokens (xoxe.xoxp-) are a different credential; app ids are public.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| gitleaks · rules 8.30.1 | slack-app-token | xapp- + digits and identifiers |
No rule maps to this family in flare-redact, openredaction, trufflehog.
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
slack-app-level-token-actions-socket-mode-envslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-agent-env-echoslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-agent-yamlslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-agent-yaml-boundary-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-bolt-js-app-tokenslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-bolt-python-handlerslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-chat-messageslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-cli-install-jsonslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-connections-open-headerslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-connections-open-header-boundary-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-curl-connections-openslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-dockerfile-envslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-docs-sentence-proseslack · prose-mention | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-dotenv-app-tokenslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-export-app-tokenslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-fish-setslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-helm-valuesslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-java-socket-mode-appslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-printenv-grepslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-socket-mode-debugslack · documented-format-literal | Must redactT2 · Tool-corroborated | Redacted |
slack-app-level-token-actions-secret-referenceslack · templated-reference | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-agent-yaml-alphabet-twinslack · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-angle-dotenv-placeholderslack · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-angle-placeholder-placeholderslack · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-app-and-enterprise-ids-public-idslack · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-app-id-url-public-idslack · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-bolt-python-handler-separator-twinslack · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-bolt-python-handler-short-prefix-twinslack · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-cli-install-json-digit-section-twinslack · wrong-alphabet | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-compose-interpolation-referenceslack · templated-reference | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-dotenv-app-token-prefix-twinslack · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-dotenv-app-token-underscore-prefix-twinslack · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-app-level-token-environ-lookup-referenceslack · templated-reference | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-masked-env-placeholderslack · documentation-placeholder | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-package-name-near-missslack · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-prefix-only-near-missslack · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-scopes-paragraph-proseslack · prose-mention | Must not flagT3 · Project policy | Quiet |
slack-app-level-token-scopes-variable-near-missslack · format-near-miss | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-team-and-client-id-public-idslack · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
slack-app-level-token-token-digest-log-encoded-valueslack · benign-encoded-value | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.slack.dev/authentication/tokens
- docs.slack.dev/apis/events-api/using-socket-mode
- github.com/slackapi/java-slack-sdk/blob/49b62a6b866bf43eb4c3bfe9c8423a65400d2928/docs/english/guides/socket-mode.md#L180
- github.com/slackapi/slack-cli/blob/20dd73092a65d3797180f95f0ee765053d7ef634/internal/goutils/strings_test.go#L198-L202
Research log
- redact-secret/redact-secret-benchmarks#222Research issue
- redact-secret/redact-secret-benchmarks#367Research issue
- redact-secret/redact-secret#726Research issue
- redact-secret/redact-secret#729Research issue
- redact-secret/redact-secret#1013Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/add1188fed9993723c59fbce8c867086b9d2049a/docs/audits/evidence/1013/slack-app-level-token.md