Slack credentials in both families: the xox bot, user, app, legacy and refresh tokens, and the newer app-level xapp token with its counter, application id, timestamp and hex layout. The xox prefix belongs to no one else, so noise is negligible. Incoming webhook URLs are a different shape and are not covered here, the existing url pattern catches them only weakly. No whole-span collision, but the long digit runs inside a token trigger credit-card, uk-nhs and us-phone on sub-spans, so slack-token must be resolved before those.
Label: SLACK_TOKEN
\b(?:xox[abeoprs]-[A-Za-z0-9-]{10,256}|xapp-\d-[A-Za-z0-9]{5,20}-\d{8,20}-[a-f0-9]{32,80})(?![A-Za-z0-9-])
SLACK_BOT_TOKEN=xoxb-2345678901-2345678901-AbCdEfGhIjKlMnOpQrStUvWx → xoxb-2345678901-2345678901-AbCdEfGhIjKlMnOpQrStUvWxLe jeton applicatif xapp-1-A01BCDEFGHI-1234567890123-a1b2c3d4a1b2c3d4a1b2c3d4a1b2c3d4a1b2c3d4 a ete revoque. → xapp-1-A01BCDEFGHI-1234567890123-a1b2c3d4a1b2c3d4a1b2c3d4a1b2c3d4a1b2c3d4xoxz-2345678901-2345678901-abcxoxb-shortTags: international, secrets, software-dev