redact-secret · Report
Bot token
Bot user OAuth token, prefixed xoxb-.
Research record
3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
- Descriptive pattern
^xoxb-[0-9]{12}-[0-9]{12}-[A-Za-z0-9]{24}$
Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.
Format facts
Provider documented ·
provider-source· current · observed 2026-10-04xoxb- bot token prefix; the page states that Slack tokens are dash-separated sections with the secret last (shown for an xoxp- user token) and states no section widths, secret width or alphabet for xoxb-
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Bot token strings begin with xoxb-; tokens are divided into sections separated by a dash and the final section is the secret (stated in the user-token secret-rotation section, example xoxp-111-222-333-...)
Tool corroborated ·
tool-corroboration· current · observed 2026-09-17Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).
- gitleaks/gitleaks @ v8.30.1: config/gitleaks.tomlscanner-rule-source · last read 2026-10-04 · latest outcome read · supports gitleaks 8.30.1: gitleaks.toml
- trufflesecurity/trufflehog @ v3.97.4: pkg/detectors/slack/slack.goscanner-rule-source · last read 2026-09-24 · latest outcome read · supports trufflehog 3.97.4: slack/slack
Unresolved ·
field-numeric-section-widths-and-secret· current · observed 2026-10-04numeric section widths and secret width or alphabet: no Slack page read states them for xoxb-; the only provider-stated widths are for user tokens (32-character secret in the page's example; pre-August-2016 user-token secrets of 6 or 10 characters), and the only xoxb- strings shown are elided (xoxb-1234-...). The 12/12/24 grammar rests on scanner rules only.
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports No xoxb- widths stated; user-token secret widths 6, 10 and 32 characters stated for xoxp- examples
- docs.slack.dev/authentication/using-token-rotation/provider-documentation · last read 2026-10-04 · latest outcome read · supports Example request token=xoxb-1234-... is elided and gives no widths
Provider documented ·
field-rotating-xoxe-xoxb-access-token· current · observed 2026-10-04rotating bot access token: oauth.v2.exchange on a granular bot token returns an access token that the page says has a new xoxe. prefix, shown as xoxe.xoxb-1-... (elided), with a refresh token shown as xoxe-1-...; the access token expires after 43,200 seconds and the original long-lived access token expires after the first refresh. The page states no widths, no meaning of the digit after the prefix and no alphabet for these forms. Outside descriptivePattern until scope is decided; never a benign control.
- docs.slack.dev/authentication/using-token-rotation/provider-documentation · last read 2026-10-04 · latest outcome read · supports oauth.v2.exchange sample response: access_token xoxe.xoxb-1-... (elided), refresh_token xoxe-1-..., expires_in 43200, token_type bot; access_token now has a new xoxe. prefix
Unresolved ·
field-rotating-form-version-digit· current · observed 2026-10-04digit after xoxe.xoxb-: the page shows 1 in an elided example; no source read states the range or meaning of this digit
- docs.slack.dev/authentication/using-token-rotation/provider-documentation · last read 2026-10-04 · latest outcome read · supports Examples show xoxe.xoxb-1-... and xoxe-1-... only
Provider documented ·
field-workflow-token-prefix-distinct· current · observed 2026-10-04workflow tokens are described as a subset of bot tokens but begin xwfp-, and the page contrasts them with xoxb- tokens; the page states no relation between the two secret formats
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Workflow token strings begin with xwfp-; unlike xoxb- tokens, workflow tokens can sometimes access private channels
Unresolved ·
field-legacy-bot-token· current · observed 2026-10-04legacy bot tokens: the page says they were obtained through an older OAuth flow and are discouraged, and states no prefix or format for them
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Legacy token types section, Legacy bot tokens: no prefix stated
Unresolved ·
field-token-like-public-identifiers· current · observed 2026-10-04identifiers shown beside bot tokens in OAuth responses (team id T123456, bot_user_id U123456, app_id A123456, client_id 60503450.61416): shown only as placeholders; no source read states their widths or that they are non-secret, and the relation of the xoxb- numeric sections to team or bot ids is not stated
- docs.slack.dev/authentication/using-token-rotation/provider-documentation · last read 2026-10-04 · latest outcome read · supports oauth.v2.exchange and oauth.v2.access sample requests and responses
Provider documented ·
dossier-research· current · observed 2026-09-17Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 54c9ab35cb693e0cd3aedc8f858ca19ab77e4363: docs/decisions/2026-09-17-freeze-slack-bot-token-segment-grammar.mdproject-research-note · last read 2026-09-17 · latest outcome read · supports Final research evidence recorded by the legacy dossier
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
xoxb-+ 10 to 13 digits +-+ 10 to 13 digits +-+ at least 18 alphanumerics, as frozen by #371.- Basis
- T1 for the prefix and the dash-separated sections (docs.slack.dev tokens page); section widths are tool agreement and the 18-byte floor is a policy choice.
In this benchmark
- Fixtures
- 46
- Left readable
- 0
- Redacted too much
- 0
- False alarms
- 0
46 fixtures: 13 expect a redaction, 18 must stay quiet, 15 record project policy. See every row
| Evidence level | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| T1Provider-documented | 10 | 0 | 0 | 0 |
| T2Tool-corroborated | 16 | 0 | 0 | 0 |
| T3Project policy | 17 | 0 | 0 | 0 |
| T0Pending review | 3 | 0 | 0 | 0 |
Every scanner on the same fixtures
In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.
| Scanner | Fixtures | Left readable | Too much | False alarms |
|---|---|---|---|---|
| flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it | 46 | 15 | 0 | 4 |
| gitleaksRepository scanner · 8.30.1 · Directory scan · default rules2 rules target it | 46 | 9 | 0 | 2 |
| redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped | 46 | 0 | 0 | 0 |
| trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it | 46 | 12 | 0 | 2 |
Benchmark dossier questions
- Open caveat
- The prefix and dash-separated sections are provider-documented; the 10 to 13 digit section widths are tool agreement and the 18-byte secret floor is a support-policy choice.
Scanner rules for this family
| Scanner | Rule | What the rule matches |
|---|---|---|
| flare-redact · rules 1.6.1 | slack_token | xoxb- or xoxp- + 10-64 characters |
| gitleaks · rules 8.30.1 | slack-bot-token | xoxb- + 10-13 digits + 10-13 digits |
| gitleaks · rules 8.30.1 | slack-legacy-bot-token | xoxb- + 8-14 digits + 18-26 characters |
| openredaction · rules 1.1.5 | SLACK_TOKEN | xoxb- or xoxp- + 10 or more characters |
| trufflehog · rules 3.97.4 | slack | xoxb- or xoxp- + 10-13 digits + 10-13 digits |
Fixtures in this family
| Fixture | Kind and evidence | redact-secret |
|---|---|---|
short-slackslack · bare-prefixes-and-truncated-tokens | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-bot-plain-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-bot-unicode-crlf-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-dash-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-shape-2-bareslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-2-quotedslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-2-unicode-crlfslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-3-bareslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-3-quotedslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-3-unicode-crlfslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-5-bareslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-5-quotedslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-5-unicode-crlfslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-6-bareslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-6-quotedslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-6-unicode-crlfslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-7-bareslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-7-quotedslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-token-shape-7-unicode-crlfslack · documented-format-literal | Project policyT3 · Project policy | Redacted |
slack-1slack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-2slack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-3slack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-bearer-headerslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-bolt-app-pythonslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-bot-plainslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-bot-prefix-plain-twinslack · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-bot-prefix-unicode-crlf-twinslack · prefix-near-miss | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-bot-team-boundary-plain-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-bot-team-boundary-unicode-crlf-twinslack · boundary-violation | Must not flagT2 · Tool-corroborated · twin | Quiet |
slack-token-bot-unicode-crlfslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-leading-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-maskslack · benign-lookalike | Must not flagT3 · Project policy | Quiet |
slack-token-prefix-onlyslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-referenceslack · benign-lookalike | Must not flagT3 · Project policy | Quiet |
slack-token-rotation-dash-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-rotation-leading-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-rotation-trailing-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-shape-1-bareslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-shape-1-quotedslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-shape-1-unicode-crlfslack · documented-format-literal | Must redactT1 · Provider-documented | Redacted |
slack-token-shape-4-bareslack · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
slack-token-shape-4-quotedslack · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
slack-token-shape-4-unicode-crlfslack · unsettled-evidence-input | Pending reviewT0 · Pending | Unscored |
slack-token-short-bodyslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-trailing-identifier-embeddingslack · benign-lookalike | Must not flagT2 · Tool-corroborated | Quiet |
slack-token-workspace-identifiers-public-idslack · public-identifier | Must not flagT2 · Tool-corroborated | Quiet |
Sources
Documentation and code
- docs.slack.dev/authentication/tokens
Research log
- redact-secret/redact-secret#371Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/54c9ab35cb693e0cd3aedc8f858ca19ab77e4363/docs/decisions/2026-09-17-freeze-slack-bot-token-segment-grammar.md