
Canarytokens
Summary
Canarytokens are decoy tokens placed in networks, computers, and cloud environments to alert users when someone accesses them. The hosted service lets users create tokens without installing software; an email address can be supplied to receive an alert when a token is triggered. Some token types also accept a webhook address for notifications. Documented examples include HTTP, DNS, Windows directory, AWS API key, Kubernetes configuration, and WireGuard tokens. The Fake App token is a Progressive Web App that alerts when opened and can include device location if location access is allowed. It supports Safari and Google Chrome. The Sensitive Command token monitors a specified command running on Windows and requires importing its registry file with admin permissions. Microsoft Entra ID and Okta setup instructions are included for the Fake IdP SAML App token. The hosted service is free, and the maker also publishes the server as open-source software and recommends Docker for self-hosting.
Who it is for
Canarytokens suits people who want alerts when decoys in their network, devices, or cloud environments are accessed. It offers a hosted setup as well as a self-hosted server option.
What is good
- Create hosted tokens without installing software
- Email alerts when a token is triggered
- Documented decoys cover several environments and token types
- Some tokens support webhook alerts
- Open-source server can be self-hosted with Docker
What to know first
- Fake App supports only Safari and Google Chrome
- Sensitive Command requires Windows admin permissions
- New Slack API Tokens can no longer be created
Everything Xiaomi review
Canarytokens: the full review
Canarytokens offers free decoys for triggering alerts, with a range of documented token types and hosted or self-hosted deployment. Check the browser and Windows requirements for the specific tokens you plan to use.
Overview
Canarytokens are decoys you place in networks, computers, or cloud environments to surface unexpected access. Rather than blocking activity, a token is meant to alert you when someone interacts with it. The hosted service at canarytokens.org lets you create tokens without installing software, while the maker also publishes an open-source server for self-hosting and recommends Docker for installation.
The service has a multi-layer decoy scope, with credential lures and cloud decoys among its uses. Documented token types range from HTTP and DNS tokens to Windows directory tokens, AWS API keys, Kubernetes configurations, and WireGuard tokens. Each represents a different kind of decoy, so setup and behavior depend on the token chosen.
Canarytokens is made by an organization headquartered in Cape Town, South Africa. Browse more options in Honeypot Software.
Key features
- Email alerts: You can add an email address when creating a token and receive an email if it is triggered.
- Webhook alerts: Some token types, including Kubeconfig and Sensitive Command, accept a webhook address for notifications.
- Identity decoy: The Fake IdP SAML App token includes setup instructions for Microsoft Entra ID and Okta.
- Phone-oriented decoy: Fake App is a Progressive Web App that alerts when opened. It can include the device location if location access is allowed. It currently supports Safari and Google Chrome.
- Windows command monitoring: Sensitive Command monitors execution of a specified command on Windows. It requires importing its registry file with administrator permissions.
- Self-hosting: The open-source server can be installed separately, with Docker recommended by the maker.
- Legacy Slack token: New Slack API Token instances can no longer be created because the token is deprecated, though existing ones continue to work.
Pricing
Canarytokens is free. The hosted service plan is listed at 0.00 USD per free, and tokens deployed through canarytokens.org are free. There is no free trial listed; the service has a free plan.
Platforms
Listed platforms are Android, iOS, self-hosted, web, and Windows. These labels do not mean every token works in every environment: for example, Fake App currently supports Safari and Chrome, while Sensitive Command is specifically for Windows and requires an administrator-level registry import.
Who it's for
Canarytokens may suit people who want to make access to selected files, credentials, endpoints, or cloud configuration decoys visible. It can be used through the hosted service without installing software, or self-hosted when an independently deployed server is preferred. The different token types make it possible to choose decoys suited to particular environments, but users should check each token's setup requirements and notification options.
Pros and cons
Pros
- The hosted service is free and does not require software installation to create tokens.
- Email alerts are available, with webhook notifications supported by some token types.
- Documented examples cover several environments, including cloud credentials, Windows, Kubernetes, and network protocols.
- An open-source server is available for self-hosting.
Cons
- Token capabilities and setup requirements vary; Sensitive Command requires an administrator-permission registry import.
- Fake App has limited browser support, currently Safari and Google Chrome, and location information depends on permission being granted.
- The deprecated Slack API Token cannot be created anew.
Alternatives
Other options in this category include OpenCanary, Beelzebub, Cowrie, Heralding, DentiGrid, Thinkst Canary, T-Pot, and Conpot.
Verdict
Canarytokens is a free decoy-token service with both hosted and self-hosted deployment paths. Its documented token range and email alerts give users several ways to make unexpected access observable, while webhook support applies only to some tokens. The main considerations are choosing token types that fit the intended environment and accounting for their specific requirements, such as browser compatibility, location permission, or Windows administrator access.
Canarytokens plans and pricing
All plansCompared on honeypot software
- Free plan
- Yescanarytokens.org
- Deployment model
- cloudcanarytokens.org
- Decoy scope
- multi-layercanarytokens.org
- Credential lures
- Yescanarytokens.org
- Cloud decoys
- Yescanarytokens.org
Facts
- Purpose
- Canarytokens are decoy tokens placed in networks, computers, and cloud environments to alert when accessed.docs.canarytokens.org · 28 Sept 2026
- Setup
- The hosted service lets users create tokens without installing software.docs.canarytokens.org · 28 Sept 2026
- Alerts
- Users can provide an email address when creating a token and receive an email when it is triggered.docs.canarytokens.org · 28 Sept 2026
- Token types
- Documented examples include HTTP, DNS, Windows directory, AWS API key, Kubernetes configuration, and WireGuard tokens.docs.canarytokens.org · 28 Sept 2026
- Webhook alerts
- Some tokens, including Kubeconfig and Sensitive Command, accept a webhook address for alerts.docs.canarytokens.org · 28 Sept 2026
- Identity integrations
- The Fake IdP SAML App token includes setup instructions for Microsoft Entra ID and Okta.docs.canarytokens.org · 28 Sept 2026
- Phone use
- The Fake App token is a Progressive Web App that alerts when opened and can include the device location if location access is allowed.docs.canarytokens.org · 28 Sept 2026
- Browser support limit
- The Fake App token currently supports Safari and Google Chrome.docs.canarytokens.org · 28 Sept 2026
- Windows monitoring
- The Sensitive Command token monitors execution of a specified command on Windows and requires importing its registry file with admin permissions.docs.canarytokens.org · 28 Sept 2026
- Self-hosting
- The maker publishes the Canarytokens server as open-source software and recommends installing it with Docker.github.com · 28 Sept 2026
- Legacy token limit
- The Slack API Token is deprecated, and new ones can no longer be created; existing tokens continue to work.github.com · 28 Sept 2026
Company
- Headquarters
- Cape Town, South Africacanarytokens.org · 28 Sept 2026
Best Canarytokens alternatives
See all 12Where it ranks on Everything Xiaomi
- Best Honeypot Software in 2026#1 of 18
Is Canarytokens yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- docs.canarytokens.org/guide/· checked 28 Sept 2026
- docs.canarytokens.org· checked 28 Sept 2026
- docs.canarytokens.org/guide/getting-started· checked 28 Sept 2026
- docs.canarytokens.org/guide/examples.html· checked 28 Sept 2026
- docs.canarytokens.org/guide/kubeconfig-token.html· checked 28 Sept 2026
- docs.canarytokens.org/guide/idp-app-token· checked 28 Sept 2026
- docs.canarytokens.org/guide/fake-app-token· checked 28 Sept 2026
- docs.canarytokens.org/guide/sensitive-cmd-token· checked 28 Sept 2026
- github.com/thinkst/canarytokens· checked 28 Sept 2026
- canarytokens.org· checked 28 Sept 2026




