Deploy digital tripwires across your infrastructure. Plant fake credentials, documents, and crypto keys — get alerted the instant someone touches them. Before real damage happens.
5 free tokens · No credit card · Crypto payments accepted
[2026-03-23 14:32:01] Token triggered: prod-aws-key
[2026-03-23 14:32:01] Source: 185.220.101.xx (Tor exit node)
[2026-03-23 14:32:01] Location: Unknown — VPN/Proxy detected
[2026-03-23 14:32:02] Alert sent → #security-alerts on Slack
⚠ Someone used your decoy AWS key. Breach detected.
Plant canary tokens across your infrastructure. Each one is a silent alarm that fires the moment an intruder touches it.
Unique URLs and hostnames that trigger alerts when accessed or resolved. Plant in configs, wikis, or internal docs.
Word and PDF files with embedded tracking. Know when someone opens a sensitive document they shouldn't have.
Decoy ETH/SOL private keys and seed phrases. Monitor the blockchain — alert if anyone moves funds.
Fake Binance and Coinbase API keys. Detect when stolen credentials are tested against exchanges.
Your tokens use your own domains. Undetectable by TruffleHog, GitLeaks, or any known blocklist.
Slack, Discord, webhooks, email, PagerDuty. Know within seconds, not hours. Full API for CI/CD integration.
Choose a type — URL, DNS hostname, document, crypto key, or API credential. Give it a name and deploy instructions.
Place the token where an attacker would find it. A .env file, a private repo, a shared drive, a config file.
When someone accesses the token, you get an instant alert with their IP, location, user agent, and timestamp.
Canarytokens.org is great for individuals. Teams need more.
| Feature | Free tools | CanaryGuard |
|---|---|---|
| Dashboard & search | ✗ | ✓ |
| Custom domains (undetectable) | ✗ | ✓ |
| Slack / Discord / webhook alerts | ✗ | ✓ |
| REST API for CI/CD | ✗ | ✓ |
| Team management & RBAC | ✗ | ✓ |
| Crypto wallet canaries | ✗ | ✓ |
| Token lifecycle management | ✗ | ✓ |
| Audit log | ✗ | ✓ |
Start free. Pay with crypto or card. No enterprise sales calls required.
200 tokens · 5 users
Get Started1000 tokens · 15 users
Get StartedNeed more? Enterprise plans with SSO, SLA, and dedicated infrastructure. Contact us
The average breach goes undetected for 204 days. Your first canary token takes 2 minutes to deploy.
Start Free — Deploy in 2 Minutes