Messaging · Secret guide

Leaked Slack API Token: what to do in the first hour

High severityDetected onlyLast verified · 5 min read

A Slack API token lets an app or script act inside a Slack workspace through the Slack API. What it can do depends on the token type and the scopes it was granted: a bot token acts as the bot user of one app, while a user token acts as the person who authorized it and sees what that person sees. With read scopes that can include private channels, direct messages and files. Revoke or rotate it first, then check which scopes it had.

Check your GitHub account for leaked secrets — free

Provider
Slack
Severity
High
Impact
SaaS account access and billing
Checked live by LeakWatch
No

What a Slack API token looks like

Slack tokens start with xox and a letter that says what kind of token it is, followed by dash-separated parts:

xoxb-…XXXX   bot token (masked)
xoxp-…XXXX   user token (masked)
xoxa-…XXXX   app-level style token (masked)

The letter matters for the response. xoxb is a bot token, scoped to the permissions the app asked for when it was installed. xoxp is a user token, acting as a real person. xoxa, xoxr and xoxs are older or specialized forms, and xoxe tokens come from Slack’s token rotation feature. LeakWatch’s Slack Token rule covers the b, a, p, r and s forms, and rotation tokens have their own rule. Slack’s app-level tokens, used for Socket Mode, start with xapp- and are managed in the app’s settings too.

This is not a Slack webhook. An incoming webhook is a URL on hooks.slack.com that can only post messages to one channel, and it has its own page: Slack webhook URL. A token is much more capable than a webhook.

How Slack API tokens get leaked

  • Bot and integration source code. A token assigned to a variable or passed to WebClient(token="…") in a bot, script or serverless function.
  • Environment and deployment files. .env, docker-compose.yml, Helm values and CI settings holding SLACK_BOT_TOKEN.
  • Legacy and personal tokens. User tokens created for a quick automation, then copied between scripts and repositories.
  • Chat exports and support threads. A token shown in a Slack message, an error log or a screenshot shared outside the workspace.
  • Example projects. A tutorial repository, template or starter app published with real configuration left in.

What to do in the first hour

  1. Identify the app. Open the Slack API apps page at api.slack.com/apps while signed in, and find the app the token belongs to. A bot token (xoxb) belongs to one app; a user token belongs to a person who authorized an app.
  2. Rotate or revoke the token. Within the app’s settings, the OAuth & Permissions page shows the installed tokens. Reinstalling the app to the workspace issues new ones, and if token rotation is turned on, the old value expires on its own schedule. If the app is not needed, uninstall it from the workspace.
  3. Replace it in your code. Put the new token in an environment variable or secret manager and redeploy.
  4. Review the scopes. On the same OAuth & Permissions page, read the list of bot and user scopes. Remove any you do not need, such as channels:history, groups:history, im:history or files:read, which determine whether message and file contents could be read.
  5. Audit access in the workspace. Workspace admins can read access logs and the audit logs available on the plan, to see API calls and app activity. Check Manage apps in the workspace’s admin settings for apps you do not recognize.

Not sure what else leaked? Run a free scan. 6. Warn people if needed. If the token could read private channels or direct messages, tell the workspace owners so they can decide who to inform. For a user token, ask the owner to review their active sessions and connected apps. 7. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

Not sure what else leaked? Run a free scan.

Revoke it at Slack

Slack has no single “revoke this string” page that works for any token. Go to api.slack.com/apps, choose the app that owns the token, and open OAuth & Permissions. From there you can reinstall the app to generate new tokens, or revoke access by uninstalling it from the workspace. A user token is also invalidated if its owner removes the app from their authorized apps. For a bot token you cannot attribute to any app you own, ask your workspace admin to look at the installed apps under the workspace’s admin settings. The exact buttons differ between Slack plans and app types, so check the labels on your screen.

How LeakWatch detects it

The rule is called Slack Token. It recognizes the xox prefix followed by a type letter and the dash-separated body that Slack uses, as a whole word. LeakWatch detects this format but does not check it live: it can tell you the token is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

FAQ

What is the difference between a bot token and a user token?

A bot token (xoxb) acts as the app’s bot user, with only the scopes the app requested. A user token (xoxp) acts as the person who authorized it, so it sees what that person can see. Treat a user token as the more serious case.

Is a Slack webhook the same thing?

No. A webhook URL can only post to a channel. If what you leaked starts with https://hooks.slack.com, follow the Slack webhook URL guide.

Does uninstalling the app remove the exposure?

It stops the tokens from working, which ends the access. It does not undo what was read or posted earlier, so the audit step still matters.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Slack.