
Canary Tokens
Canary Tokens is a tool that allows you to discover any unexpected access to your PC.
- Website
- canarytokens.org
- Pricing
- free · Free
Ready to try Canary Tokens?
Visit Canary TokensOverview
The idea behind Canarytokens is as simple as it is effective: scatter digital decoys through your systems and get alerted the moment someone touches one. If the alarm fires, there's a problem — and you know immediately.
How does Canary Tokens work?
Canarytokens is a free service developed by Thinkst that generates digital decoys, technically known as honeytokens. It works simply: from the site you generate a token, specifying the email address or webhook where you want alerts, and receive an apparently innocuous item to place wherever you find it useful. Many types are available: a Word or PDF document that reports when it's opened, a URL that alerts if someone visits it, a DNS record triggered on resolution, an AWS key that notifies any attempted use, a QR code, a Windows folder, an image embedded in a page. None of these items has any reason to be opened during normal work: if a token fires, it means someone is exploring where they shouldn't. Once alerted, you know which token it came from, with IP address and context information. It's a very low-noise approach, because it doesn't generate the false positives typical of rule-based systems.
Who is it for?
For system administrators, security teams and IT professionals wanting an early warning system for unauthorized access, with no cost and no infrastructure to manage.
How much does it cost?
The public Canarytokens service is completely free and requires no registration: you generate tokens from the site and receive alerts by email or webhook. The project is open source and can be self-hosted for those who prefer to keep everything internal. Thinkst, the company behind it, separately offers Canary, a commercial honeypot solution for enterprise environments, with pricing on request.
