redact-secret · Report
Workflow webhook token
Workflow webhook trigger token, prefixed xwfp-.
Research record
What blocks the research
- Issuance-gatedSection count and widths rest on one Slack docs example (one owner, so no T2); needs an R5 exception for that example or one custom-function step measured (structure only, self-revokes in 15 minutes).
2 events in the review history: 1 observed, 1 reviewed. Latest: observed on 2026-09-29 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.
Format
What it looks like
Shape not recorded.
Format facts
Provider documented ·
dossier-research· current · observed 2026-09-29Legacy dossier research (verdict issuance-gated, tier T1) cited 4 sources; the dossier does not attribute sources to individual properties.
- docs.slack.dev/reference/interaction-payloads/block_suggestion-payloadother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family
- docs.slack.dev/authentication/tokensprovider-documentation · last read 2026-10-04 · latest outcome read · supports Cited by the legacy dossier research for this family
- redact-secret/redact-secret @ 378581770a87751d72e27529796c4f790649fd00: docs/audits/evidence/1012/slack-workflow-webhook-token.mdproject-research-note · last read 2026-09-29 · latest outcome read · supports Final research evidence recorded by the legacy dossier
- slackapi/python-slack-sdk @ 1fe0b8e708251fb4d2dc9617a774f64635098e21: slack_sdk/socket_mode/logger/messages.pyother · last read 2026-09-29 · latest outcome read · supports Cited by the legacy dossier research for this family · #L4-L6
Open questions
No open question is recorded for this revision.
Benchmark dossier notes
- Shape
- prefix
xwfp-, then sections separated by-. The one full-width provider example has thexoxp-layout: three digit sections of 13 and a final 32-character lowercase-hex section (79 in total). Slack's own SDK log redactor uses an alphabet without_. Section count and widths for issued tokens are unconfirmed. Slack calls this a *workflow token*, the short-lived bot token handed to a custom function step (bot_access_token), not a workflow webhook (those arehooks.slack.com/workflows/...URLs); the 1012 record suggests the nameslack:workflow-token, but the taxonomy id is unchanged here. - Basis
- - provider docs (T1): the tokens page states workflow tokens expire after 15 minutes or when the function step ends, and "begin with
xwfp-". - provider docs example (R5, shape only): theblock_suggestionpayload reference, present by 2023-10-07 (Wayback snapshot), carries the single full-width example described above. - provider log redactor (R2 = T1 for what it states): python-slack-sdk's socket-mode message masker matchesxwfp-followed by[A-Za-z0-9-]+, with no_. - provider test placeholders (R4): shortxwfp-values in bolt-js, bolt-python, java-slack-sdk and python-slack-sdk give no length or sections. - Both the example and the redactor come from one owner, so the T2 route fails. Nothing in slack-cli, the Deno SDKs, gitleaks, trufflehog, CredSweeper, noseyparker, betterleaks or GitLab's rules. No leaked value was found, as expected for a token that dies within 15 minutes. - Issuance
- cheap but manual: run one Slack custom-function step (a Bolt
function_executedhandler or a Deno workflow app) and log only the shape ofbot_access_token: number of-sections, width of each digit section, whether the last section is exactly 32[0-9a-f], whether any_or uppercase appears. The token revokes itself within 15 minutes. - Contract in core
- an interim guard in
slack-token:xwfp-+ at least 20[A-Za-z0-9_-](#512); a value in the docs example's layout is found in full. The_is wider than any provider evidence, and dropping it is supported by provider code and the example. Living spec: detector-families.md.
In this benchmark
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Benchmark dossier questions
- Blocked by
- Section count and widths rest on one Slack docs example (one owner, so no T2); needs an R5 exception for that example or one custom-function step measured (structure only, self-revokes in 15 minutes).
- Open caveat
- ruling R5-exception: may Slack's docs example set the grammar? A yes would make this READY-T1-by-example; otherwise one issuance closes it.
Looks like it, but isn't
- Collisions
- shares the
xox*-digit-section layout withslack:user-tokenand thexapp-dash layout ofslack:app-level-token; the prefix separates them.
Scanner rules for this family
No peer rule maps to this family
None of the reviewed peer scanners has a rule that can match a credential of this family.
None mapped
No fixtures in this family yet
Nothing in the corpus targets it, so nothing is measured and no coverage is claimed.
Not measured
Sources
Documentation and code
- benchmarks/lib/assessment.ts (classifyFixture variant guard: "Variant support must not be inferred from a related family name.")
- docs.slack.dev/authentication/tokens
- docs.slack.dev/reference/interaction-payloads/block_suggestion-payload
- github.com/slackapi/python-slack-sdk/blob/1fe0b8e708251fb4d2dc9617a774f64635098e21/slack_sdk/socket_mode/logger/messages.py#L4-L6
Research log
- redact-secret/redact-secret-benchmarks#45Research issue
- redact-secret/redact-secret-benchmarks#127Research issue
- redact-secret/redact-secret#512Research issue
- redact-secret/redact-secret#1012Research issue
- Final evidence, pinned to a commit/redact-secret/redact-secret/blob/378581770a87751d72e27529796c4f790649fd00/docs/audits/evidence/1012/slack-workflow-webhook-token.md