Canarytokens are decoy tokens placed in networks, computers, and cloud environments to alert users when someone accesses them. The hosted service lets users create tokens without installing software and receive email alerts when a token is triggered. Some token types can also send alerts to a supplied webhook address. Documented examples include HTTP, DNS, Windows directory, AWS API key, Kubernetes configuration, and WireGuard tokens. The Fake App token is a Progressive Web App that alerts when opened and may include device location if location access is allowed; it currently supports Safari and Google Chrome. For Windows monitoring, the Sensitive Command token watches for execution of a specified command and requires importing its registry file with admin permissions. Setup instructions for Microsoft Entra ID and Okta are included with the Fake IdP SAML App token. Canarytokens hosted through canarytokens.org are free. The maker also publishes the server as open-source software and recommends Docker for self-hosting.
Who it is for
Canarytokens suits people who want alerts when decoys in networks, computers, or cloud environments are accessed. It also offers a self-hosting route for users comfortable installing the server with Docker.
What is good
- Hosted token creation needs no software installation
- Email alerts are available when tokens trigger
- Supports HTTP, DNS, AWS, Kubernetes, and other token types
- Some tokens support webhook alerts
- Server is published as open-source software
What to know first
- Fake App supports only Safari and Chrome
- Sensitive Command requires admin permissions on Windows
- New Slack API Tokens cannot be created
Verdict
Canarytokens offers a free hosted way to deploy decoys and receive alerts, with a separate self-hosted option. Check the browser limit for Fake App and the setup requirements for Windows monitoring before choosing token types.
Canarytokens plans and pricing
All plansCompared on honeypot software
- Free plan
- Yes
- Deployment model
- cloud
- Decoy scope
- multi-layer
- Credential lures
- Yes
- Cloud decoys
- Yes


