Slack MCP DXT passes the literal text ${user_config.xoxb_token} as the token
Fixes the Slack MCP desktop extension failing auth because the token placeholder was never expanded. Use when the DXT install fails with auth errors and logs show the literal placeholder. Not for manually configured servers.
Slack MCP DXT passes the literal text ${userconfig.xoxbtoken} as the token
TL;DR: The DXT config left ${userconfig.xoxbtoken} unexpanded, so the server authenticates with that literal string. Re-enter the bot token in the DXT user configuration screen so the placeholder resolves. Reinstall or re-enable the extension after fixing the value.
The error
Slack API auth failure with the token value literally ${user_config.xoxb_token} in the requestFix it
- Open the DXT user configuration for the Slack extension.
Expected: The token field shows empty or the raw placeholder.
- Paste your real xoxb bot token into the field and save.
Expected: The field holds the actual token.
- Re-enable or reinstall the extension.
Expected: Auth succeeds and tools work.
When this applies
The Slack MCP desktop extension fails authentication and the configured token is the literal placeholder text.
When this does NOT apply
Manually edited JSON configs do not use DXT placeholders; check the token value directly there.
Tool compatibility
korotovsky/slack-mcp-server DXT (desktop extension)
Also seen as
- Slack DXT token placeholder not expanded
- userconfig.xoxbtoken literal
- Slack MCP desktop extension auth failed
Why it happens
DXT user_config placeholders are expanded by the extension host at install time. If the value was never entered, the raw placeholder string is passed as the token and Slack rejects it.
Edge cases
- Reinstalling without entering the value repeats the failure.
- The same pattern affects the xoxp user token field.
- Check extension logs to confirm the literal string is what was sent.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.