Skip to main content

SlackTokens

Extract personal tokens and authentication cookie from the Slack app, to use with the Slack API.


Description

slacktokens is a tool for providing programmatic access to the Slack ecosystem.

This project is not endorsed or authorised in any way by Slack Technologies LLC.

The Slack API is how all Slack clients, including the official desktop app and third-party bots, read and write data that constitutes the Slack user experience. All clients much provide authorisation to access the API.

As of July 2021, individual user access to the Slack API (as opposed to bot access) is granted by providing a personal token (beginning with xoxc-) and a cookie called d. Each Slack Workspace has its own personal token, but the cookie is the same for all.

If you use the Slack desktop app, these details will be stored on your local machine. This script extracts them from the app's local store so you can use them for purposes not provided for by the app itself.

Usage

Calling get_tokens_and_cookie() will return the necessary authorisation details as a Python dictionary, in the following format:

{
  'tokens': [
    'Workspace name': { token: <personal-token>, url: <URL of Workspace> }
    ]
  'cookie': { 'name': 'd', 'value': <value-of-d-cookie> }
}

This data can be used for calls to the Slack API. For example:

curl 'https://slack.com/api/team.info?token=<personal-token>' --header 'Cookie: d=<value-of-d-cookie>'

Details

Your personal tokens are extracted by querying the Slack app's HTML Web Storage database. The token for each Workspace is stored in a dictionary in the localStorage object, in a LevelDB database. The useful fields extracted from the dictionary, other than the token itself, are the human readable Workspace name, and the Workspace URL.

The cookie is extracted from the Slack app's cookie store. The cookie of interest is stored encrypted, so a modified version of pycookiecheat is used to decrypt the contents. The decryption process will prompt you for your user password, which is used only to pull out the cookie store encryption secret from your keychain.

Shortcomings

  • macOS and Linux only.
    • Windows support contributions welcome.
  • Slack Desktop App only.
    • Browser support contributions welcome. Preferred implementation: failover to looking through browsers if the app access method fails.
  • Might require the app to be closed, because LevelDB is not a multi-user database and there are no read-only access options.
  • No established method for persisting the token data. Thought long and hard about this, and decided to keep the interface flexible and to leave suitable persistance methods as an exercise for the user.
    • It turns out the script is fast and read-only, so if the user is another Python script, then perhaps no persistance is required.

Metadata

Release files for slacktokens 0.2.6

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for slacktokens 0.2.6
File Size Uploaded
slacktokens-0.2.6.tar.gz 16.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for slacktokens 0.2.6
File Interpreter ABI Platform
slacktokens-0.2.6-py3-none-any.whl Python 3 none any Details

Total release size: 33.1 kB

Release files / slacktokens-0.2.6.tar.gz

Download URL slacktokens-0.2.6.tar.gz
Size 16.3 kB
Tags Source
SHA-256 checksum
How to use checksums
9f941a3663d3902613a846620fbcf631662caf732016ab34a67bd3435ac630a4
BLAKE2b-256 checksum
How to use checksums
a2355fb4f87bbc917c994e81986efd4ce26b73a107cd27911a26e7507dfa14a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.13

Release files / slacktokens-0.2.6-py3-none-any.whl

Download URL slacktokens-0.2.6-py3-none-any.whl
Size 16.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0247b7707833e260bd2c568364fd97bff4a298bde8d8c01da6401b6f95d333eb
BLAKE2b-256 checksum
How to use checksums
7e3ba56eabd7ba12d0b42b823bfcc22ad2940c4d4fbca74917e4642593f2e42a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.11.13

Release history Release notifications | RSS feed

This release

0.2.6 This release

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page