
Canarytokens
Self-hosted honeypot tokens that alert you when accessed -- detect breaches, insider threats, and credential exposure passively.
About Canarytokens
Canarytokens is a self-hosted honeypot system by Thinkst Applied Research that lets you plant fake credentials, URLs, PDFs, API keys, and WireGuard configs across your infrastructure. When any token is accessed, you receive an instant alert. This passive detection catches attackers who have penetrated your network, insider threats snooping on files, and leaked credentials that should never have left your control.
Token types include web bugs, DNS queries, AWS API keys, PDF documents, SQL database entries, and WireGuard connection attempts. All tokens are completely fake -- no real data is put at risk. When triggered, alerts arrive via Mailgun, SendGrid, SMTP, or Slack with details of the access event. Deployed via Docker Compose with automatic Let's Encrypt SSL.
Key Features
- Plant fake credentials (AWS keys, URLs, PDFs, WireGuard) and get alerted on access
- Multiple token types: web bug, DNS, PDF, SQL, API key, and WireGuard
- Docker Compose deployment with automatic Let's Encrypt HTTPS
- Alert delivery via Mailgun, SendGrid, SMTP, or Slack webhook
Self-Hosting Notes
Docker Compose deployment. Requires domain name(s) and internet-facing Docker host. Alert via Mailgun, SendGrid, SMTP, or Slack webhook. Let's Encrypt HTTPS support. Redis-backed persistence. BSD-3-Clause license. 659 GitHub stars.
More in Security, Password, & IT Management
1Panel
Modern open-source Linux server control panel with web interface.
AdGuard Home
Network-wide software for blocking ads and tracking at the DNS level.
Authelia
Comprehensive single sign-on (SSO) and multi-factor authentication (MFA) portal.
Authentik
Flexible, open-source identity provider supporting SSO, MFA, and enterprise federation.