Skip to content
Benchmarks

redact-secret · Report

Bot token

Bot user OAuth token, prefixed xoxb-.

  • Slack
  • Detectors: slack-token
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-17

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-17

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Descriptive pattern
^xoxb-[0-9]{12}-[0-9]{12}-[A-Za-z0-9]{24}$

Parts are shown as recorded. Evidence classes belong to the facts below; no class is assigned to a part.

Format facts

  • Provider documented · provider-source · current · observed 2026-10-04

    xoxb- bot token prefix; the page states that Slack tokens are dash-separated sections with the secret last (shown for an xoxp- user token) and states no section widths, secret width or alphabet for xoxb-

    • docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Bot token strings begin with xoxb-; tokens are divided into sections separated by a dash and the final section is the secret (stated in the user-token secret-rotation section, example xoxp-111-222-333-...)
  • Tool corroborated · tool-corroboration · current · observed 2026-09-17

    Pinned scanner rules are consistent with the contract grammar (2 artifacts: gitleaks 8.30.1; trufflehog 3.97.4).

  • Unresolved · field-numeric-section-widths-and-secret · current · observed 2026-10-04

    numeric section widths and secret width or alphabet: no Slack page read states them for xoxb-; the only provider-stated widths are for user tokens (32-character secret in the page's example; pre-August-2016 user-token secrets of 6 or 10 characters), and the only xoxb- strings shown are elided (xoxb-1234-...). The 12/12/24 grammar rests on scanner rules only.

  • Provider documented · field-rotating-xoxe-xoxb-access-token · current · observed 2026-10-04

    rotating bot access token: oauth.v2.exchange on a granular bot token returns an access token that the page says has a new xoxe. prefix, shown as xoxe.xoxb-1-... (elided), with a refresh token shown as xoxe-1-...; the access token expires after 43,200 seconds and the original long-lived access token expires after the first refresh. The page states no widths, no meaning of the digit after the prefix and no alphabet for these forms. Outside descriptivePattern until scope is decided; never a benign control.

    • docs.slack.dev/authentication/using-token-rotation/provider-documentation · last read 2026-10-04 · latest outcome read · supports oauth.v2.exchange sample response: access_token xoxe.xoxb-1-... (elided), refresh_token xoxe-1-..., expires_in 43200, token_type bot; access_token now has a new xoxe. prefix
  • Unresolved · field-rotating-form-version-digit · current · observed 2026-10-04

    digit after xoxe.xoxb-: the page shows 1 in an elided example; no source read states the range or meaning of this digit

  • Provider documented · field-workflow-token-prefix-distinct · current · observed 2026-10-04

    workflow tokens are described as a subset of bot tokens but begin xwfp-, and the page contrasts them with xoxb- tokens; the page states no relation between the two secret formats

    • docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Workflow token strings begin with xwfp-; unlike xoxb- tokens, workflow tokens can sometimes access private channels
  • Unresolved · field-legacy-bot-token · current · observed 2026-10-04

    legacy bot tokens: the page says they were obtained through an older OAuth flow and are discouraged, and states no prefix or format for them

    • docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Legacy token types section, Legacy bot tokens: no prefix stated
  • Unresolved · field-token-like-public-identifiers · current · observed 2026-10-04

    identifiers shown beside bot tokens in OAuth responses (team id T123456, bot_user_id U123456, app_id A123456, client_id 60503450.61416): shown only as placeholders; no source read states their widths or that they are non-secret, and the relation of the xoxb- numeric sections to team or bot ids is not stated

  • Provider documented · dossier-research · current · observed 2026-09-17

    Legacy dossier research (verdict ready, tier T1) cited 2 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
xoxb- + 10 to 13 digits + - + 10 to 13 digits + - + at least 18 alphanumerics, as frozen by #371.
Basis
T1 for the prefix and the dash-separated sections (docs.slack.dev tokens page); section widths are tool agreement and the 18-byte floor is a policy choice.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
46
Left readable
0
Redacted too much
0
False alarms
0

46 fixtures: 13 expect a redaction, 18 must stay quiet, 15 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented10000
T2Tool-corroborated16000
T3Project policy17000
T0Pending review3000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it461504
gitleaksRepository scanner · 8.30.1 · Directory scan · default rules2 rules target it46902
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped46000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled1 rule targets it461202

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Open caveat
The prefix and dash-separated sections are provider-documented; the 10 to 13 digit section widths are tool agreement and the 18-byte secret floor is a support-policy choice.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1slack_tokenxoxb- or xoxp- + 10-64 characters
gitleaks · rules 8.30.1slack-bot-tokenxoxb- + 10-13 digits + 10-13 digits
gitleaks · rules 8.30.1slack-legacy-bot-tokenxoxb- + 8-14 digits + 18-26 characters
openredaction · rules 1.1.5SLACK_TOKENxoxb- or xoxp- + 10 or more characters
trufflehog · rules 3.97.4slackxoxb- or xoxp- + 10-13 digits + 10-13 digits
46 of 46 rows

Fixtures in this family

46 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Bot token
FixtureKind and evidenceredact-secret
short-slackslack · bare-prefixes-and-truncated-tokensMust not flagT2 · Tool-corroboratedQuiet
slack-token-bot-plain-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-bot-unicode-crlf-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-dash-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-shape-2-bareslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-2-quotedslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-2-unicode-crlfslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-3-bareslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-3-quotedslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-3-unicode-crlfslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-5-bareslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-5-quotedslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-5-unicode-crlfslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-6-bareslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-6-quotedslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-6-unicode-crlfslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-7-bareslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-7-quotedslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-token-shape-7-unicode-crlfslack · documented-format-literalProject policyT3 · Project policyRedacted
slack-1slack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-2slack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-3slack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-bearer-headerslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-bolt-app-pythonslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-bot-plainslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-bot-prefix-plain-twinslack · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-bot-prefix-unicode-crlf-twinslack · prefix-near-missMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-bot-team-boundary-plain-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-bot-team-boundary-unicode-crlf-twinslack · boundary-violationMust not flagT2 · Tool-corroborated · twinQuiet
slack-token-bot-unicode-crlfslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-leading-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-maskslack · benign-lookalikeMust not flagT3 · Project policyQuiet
slack-token-prefix-onlyslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-referenceslack · benign-lookalikeMust not flagT3 · Project policyQuiet
slack-token-rotation-dash-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-rotation-leading-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-rotation-trailing-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-shape-1-bareslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-shape-1-quotedslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-shape-1-unicode-crlfslack · documented-format-literalMust redactT1 · Provider-documentedRedacted
slack-token-shape-4-bareslack · unsettled-evidence-inputPending reviewT0 · PendingUnscored
slack-token-shape-4-quotedslack · unsettled-evidence-inputPending reviewT0 · PendingUnscored
slack-token-shape-4-unicode-crlfslack · unsettled-evidence-inputPending reviewT0 · PendingUnscored
slack-token-short-bodyslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-trailing-identifier-embeddingslack · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet
slack-token-workspace-identifiers-public-idslack · public-identifierMust not flagT2 · Tool-corroboratedQuiet

Sources

Researched 2026-09-17.

Documentation and code

Research log

Other Slack families