# Slack MCP DXT passes the literal text ${user_config.xoxb_token} as the token

**TL;DR:** The DXT config left ${user_config.xoxb_token} unexpanded, so the server authenticates with that literal string. Re-enter the bot token in the DXT user configuration screen so the placeholder resolves. Reinstall or re-enable the extension after fixing the value.

## The error

```
Slack API auth failure with the token value literally ${user_config.xoxb_token} in the request
```

## Fix it

1. Open the DXT user configuration for the Slack extension.
   Expected: The token field shows empty or the raw placeholder.
2. Paste your real xoxb bot token into the field and save.
   Expected: The field holds the actual token.
3. Re-enable or reinstall the extension.
   Expected: Auth succeeds and tools work.

## When this applies

The Slack MCP desktop extension fails authentication and the configured token is the literal placeholder text.

## When this does NOT apply

Manually edited JSON configs do not use DXT placeholders; check the token value directly there.

## Tool compatibility

korotovsky/slack-mcp-server DXT (desktop extension)

## Also seen as

- Slack DXT token placeholder not expanded
- user_config.xoxb_token literal
- Slack MCP desktop extension auth failed

## Why it happens

DXT user_config placeholders are expanded by the extension host at install time. If the value was never entered, the raw placeholder string is passed as the token and Slack rejects it.

## Edge cases

- Reinstalling without entering the value repeats the failure.
- The same pattern affects the xoxp user token field.
- Check extension logs to confirm the literal string is what was sent.