Skip to content
Benchmarks

redact-secret · Report

Workflow webhook token

Workflow webhook trigger token, prefixed xwfp-.

  • Slack
  • Detectors: none mapped
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictIssuance-gated
  • Dossier evidence levelT1 · Provider-documented
  • Dossier researched2026-09-29
classifyFixture explicitly routes xwfp- values to the "needs a separate format contract" guard.

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · proposed, none current
  • ResearchResearched
  • Researched2026-09-29

What blocks the research

  • Issuance-gatedSection count and widths rest on one Slack docs example (one owner, so no T2); needs an R5 exception for that example or one custom-function step measured (structure only, self-revokes in 15 minutes).

2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
prefix xwfp-, then sections separated by -. The one full-width provider example has the xoxp- layout: three digit sections of 13 and a final 32-character lowercase-hex section (79 in total). Slack's own SDK log redactor uses an alphabet without _. Section count and widths for issued tokens are unconfirmed. Slack calls this a *workflow token*, the short-lived bot token handed to a custom function step (bot_access_token), not a workflow webhook (those are hooks.slack.com/workflows/... URLs); the 1012 record suggests the name slack:workflow-token, but the taxonomy id is unchanged here.
Basis
- provider docs (T1): the tokens page states workflow tokens expire after 15 minutes or when the function step ends, and "begin with xwfp-". - provider docs example (R5, shape only): the block_suggestion payload reference, present by 2023-10-07 (Wayback snapshot), carries the single full-width example described above. - provider log redactor (R2 = T1 for what it states): python-slack-sdk's socket-mode message masker matches xwfp- followed by [A-Za-z0-9-]+, with no _. - provider test placeholders (R4): short xwfp- values in bolt-js, bolt-python, java-slack-sdk and python-slack-sdk give no length or sections. - Both the example and the redactor come from one owner, so the T2 route fails. Nothing in slack-cli, the Deno SDKs, gitleaks, trufflehog, CredSweeper, noseyparker, betterleaks or GitLab's rules. No leaked value was found, as expected for a token that dies within 15 minutes.
Issuance
cheap but manual: run one Slack custom-function step (a Bolt function_executed handler or a Deno workflow app) and log only the shape of bot_access_token: number of - sections, width of each digit section, whether the last section is exactly 32 [0-9a-f], whether any _ or uppercase appears. The token revokes itself within 15 minutes.
Contract in core
an interim guard in slack-token: xwfp- + at least 20 [A-Za-z0-9_-] (#512); a value in the docs example's layout is found in full. The _ is wider than any provider evidence, and dropping it is supported by provider code and the example. Living spec: detector-families.md.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Benchmark dossier questions

Things the sources do not settle. They are listed so nobody reads them as settled.
Blocked by
Section count and widths rest on one Slack docs example (one owner, so no T2); needs an R5 exception for that example or one custom-function step measured (structure only, self-revokes in 15 minutes).
Open caveat
ruling R5-exception: may Slack's docs example set the grammar? A yes would make this READY-T1-by-example; otherwise one issuance closes it.

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
shares the xox*- digit-section layout with slack:user-token and the xapp- dash layout of slack:app-level-token; the prefix separates them.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.

No peer rule maps to this family

None of the reviewed peer scanners has a rule that can match a credential of this family.

None mapped

0 of 0 rows

No fixtures in this family yet

Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.

Not measured

Sources

Researched 2026-09-29.

Documentation and code

Research log

Other Slack families