
Canarytokens
Self-hosted honeypot tokens that alert you when accessed. Detect breaches, insider threats, and credential exposure.
About Canarytokens
Canarytokens is a self-hosted honeypot system by Thinkst Applied Research that lets you plant fake credentials, URLs, PDFs, API keys, and WireGuard configs across your infrastructure. When any token is accessed, you receive an instant alert. This passive detection catches attackers who have penetrated your network, insider threats snooping on files, and leaked credentials that should never have left your control.
Token types include web bugs, DNS queries, AWS API keys, PDF documents, SQL database entries, and WireGuard connection attempts. All tokens are completely fake -- no real data is put at risk. When triggered, alerts arrive via Mailgun, SendGrid, SMTP, or Slack with details of the access event. Deployed via Docker Compose with automatic Let's Encrypt SSL.
Key Features
- Plant fake credentials (AWS keys, URLs, PDFs, WireGuard) and get alerted on access
- Multiple token types: web bug, DNS, PDF, SQL, API key, and WireGuard
- Docker Compose deployment with automatic Let's Encrypt HTTPS
- Alert delivery via Mailgun, SendGrid, SMTP, or Slack webhook
Self-Hosting Notes
Find another tool
More in Security & Identity
Authelia
Comprehensive single sign-on (SSO) and multi-factor authentication (MFA) portal.
Authentik
Flexible, open-source identity provider supporting SSO, MFA, and enterprise federation.
CrowdSec
Modern, collaborative intrusion prevention system built to detect bad behaviors.
Ente Auth
Free, open-source, end-to-end encrypted 2FA authenticator and password manager, a secure Authy replacement.