Ross ROSS = Recommend OSS · open-source software intelligence for agents

thinkst/canarytokens

Canarytokens helps track activity and actions on your network observed · 2026-08-28

github.com/thinkst/canarytokens · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

76/100

  • Activity 98
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4052
  • days_rel: n/a
  • days_push: 13
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2140 stars · 294 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Canarytokens is a self-hostable service by Thinkst that generates tripwire tokens (URLs, DNS names, AWS keys, files, etc.) which alert you when they are triggered. It helps detect unauthorized activity and lateral movement on your network.

Use cases

  • detect if someone is snooping on my network
  • get alerted when a stolen AWS key is used
  • track when a document is opened
  • set up honeypot tripwires for breach detection
  • monitor for lateral movement in my infrastructure
  • self-host canary token generation and alerting

When to choose

  • you want lightweight, low-noise breach detection without a full honeypot
  • you need self-hosted control over token generation and alert delivery
  • you want to plant tripwires across cloud credentials, DNS, and files

When to avoid

  • you need full network intrusion detection with packet inspection
  • you want a managed service without hosting your own frontend and switchboard components

Facets

service · maturity active

security alerting monitoring webhook self-hosted security networking developer-tools self-hosted python canarytokens honeypot intrusion-detection deception-technology breach-detection tripwires docker linux

2 sources

Member repositories

RepositoryRoleHealth v2
thinkst/canarytokensmain76

For agents

markdown · JSON · MCP: product_card(name="thinkst/canarytokens")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem