Canarytokens

Web · Windows · Android · iPhone · Self-hosted

Freedom report

Three barsScore 6.6

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely4 of 6 device platforms
  • DocumentedPlans, terms and facts published

Canarytokens are decoys placed in networks, computers, or cloud environments to alert users when someone accesses them. The hosted service lets users create tokens without installing software, and an email address can be supplied to receive an alert when a token fires. Some token types also accept a webhook address for notifications. Documented examples include HTTP, DNS, Windows directory, AWS API key, Kubernetes configuration, and WireGuard tokens. The Fake IdP SAML App token includes setup guidance for Microsoft Entra ID and Okta. The Fake App token is a Progressive Web App that alerts when opened and can include a device’s location if location access is allowed; it currently works with Safari and Google Chrome. On Windows, Sensitive Command watches for execution of a specified command and requires importing its registry file with admin permissions. The hosted service is free. The maker also publishes the server as open-source software and recommends Docker for self-hosting. One older option, the Slack API Token, is deprecated: new tokens cannot be created, though existing ones continue to work.

Who it is for

Canarytokens suits people who want decoys in networks, computers, or cloud environments to generate alerts when accessed. It may also suit teams seeking hosted setup or a self-hosted server option.

What is good

  • Hosted token creation requires no software installation.
  • Email alerts are available when tokens are triggered.
  • Some token types support webhook alerts.
  • Documented decoys cover network, cloud, and Windows examples.
  • Hosted service is free.

What to know first

  • Fake App supports only Safari and Google Chrome.
  • Sensitive Command requires admin permission to import its registry file.
  • New Slack API Tokens cannot be created.

Freedom251 review

Canarytokens: the full review

Canarytokens offers a range of decoys and alert options, with both hosted and self-hosted approaches. Check browser support and Windows setup requirements for the token types you plan to use.

Overview

Canarytokens is a free decoy-token service for security-conscious administrators who want unexpected access to stand out across computers, networks, and cloud environments. Its breadth of token types is the main draw; it is less suited to anyone expecting the tokens to block activity rather than alert on it.

The hosted service creates tokens without requiring a software installation, while the maker also publishes an open-source server for self-hosting and recommends Docker. Tokens can be deployed across multiple layers, including credential lures and cloud decoys, so Canarytokens can cover more than one kind of environment.

Documented token types include HTTP and DNS, Windows directories, AWS API keys, Kubernetes configurations, and WireGuard. Canarytokens is made by an organization headquartered in Cape Town, South Africa. Browse Honeypot Software for more options in this category.

Key features

  • Email alerts: Add an email address when creating a token to receive an alert when it is triggered. This is a straightforward option for individual monitoring, though the alert depends on the email address provided.
  • Webhook alerts: Some token types, including Kubeconfig and Sensitive Command, accept a webhook address. This gives those tokens an alert path beyond email, but webhook support is not universal across token types.
  • Identity decoy: The Fake IdP SAML App token includes setup instructions for Microsoft Entra ID and Okta, making it relevant to organizations using either identity provider.
  • Phone-oriented decoy: Fake App is a Progressive Web App that alerts when opened. It can include the device location if location access is allowed, which makes it useful when location context matters but dependent on the user granting that access.
  • Windows command monitoring: Sensitive Command monitors execution of a specified command on Windows. Setup requires importing its registry file with administrator permissions, an operational hurdle for users without the necessary access.
  • Legacy Slack token: Slack API Token is deprecated; new tokens cannot be created, although existing ones continue to work.

Pricing

Canarytokens hosted service costs 0.00 USD per free. Tokens deployed through canarytokens.org are free, and there is no free trial because the hosted offering is already free. There is no paid tier or published seat or quota limit in this offering, so it suits users who want hosted decoys without a subscription commitment. Self-hosting is also an option through the maker's open-source server, with Docker recommended for installation.

Platforms

Canarytokens lists Android, iOS, web, Windows, and self-hosted support. The Fake App token currently supports Safari and Google Chrome, so readers relying on another browser should not choose that token on the assumption it will work there. Sensitive Command is specifically a Windows monitoring token and requires administrator permissions to import its registry file.

Who it's for

Canarytokens is a strong fit for administrators who want low-cost, varied decoys across cloud and local environments, especially when they can use the hosted service or run the open-source server themselves. Its email alerts and selected webhook options suit users who need notifications when a token is touched. It is not a substitute for software intended to prevent access, and some token types impose browser, identity-provider, or Windows setup constraints.

Pros and cons

  • Pro: Hosted tokens are free and can be created without installing software, lowering the barrier to trying decoys.
  • Pro: The documented range spans web, DNS, Windows, cloud credentials, Kubernetes, and WireGuard, useful for monitoring different parts of an environment.
  • Pro: The maker publishes an open-source server and recommends Docker, giving users a self-hosting route.
  • Con: Webhook alerts apply only to some tokens, so users cannot assume every decoy can notify the same way.
  • Con: Fake App is currently limited to Safari and Chrome, while Sensitive Command requires Windows administrator permissions.
  • Con: New Slack API Token decoys are unavailable because that token type is deprecated.

Alternatives

Choose OpenCanary if you want free, open-source self-hosted honeypot software for Linux or macOS. Choose Beelzebub if a free self-hosted core framework for Linux and API environments, with a free trial, better matches your needs.

Cowrie, Heralding, T-Pot, Conpot, Honeyd, and Honeytrap are other free alternatives.

Verdict

Choose Canarytokens if you want free decoys with both hosted and self-hosted approaches and a range spanning cloud, network, and device contexts. Its main advantage is that varied token types can surface unexpected access without requiring hosted users to install software. Look elsewhere if you need a blocking tool, rely on an unsupported browser for Fake App, or cannot meet the setup requirements of a token you need.

Canarytokens plans and pricing

All plans
Canarytokens hosted service Free Tokens deployed through canarytokens.org are free docs.canarytokens.org · 28 Sept 2026

Compared on honeypot software

Free plan
Yes
Deployment model
cloud
Decoy scope
multi-layer
Credential lures
Yes
Cloud decoys
Yes

Best Canarytokens alternatives

See all 12