# thinkst/canarytokens

Canarytokens helps track activity and actions on your network

Repository: https://github.com/thinkst/canarytokens
Canonical: https://ross.abutalabs.com/products/canarytokens
Homepage: http://canarytokens.org
Language: Python
License: NOASSERTION
License Family: other
Last push: 2026-08-20T13:20:14+00:00

## Health v2 (maintenance only)
Score: 76/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 98, release rhythm 35, longevity 100
- inputs: {"age_days": 4052, "days_push": 13, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2140, forks 294 (observed 2026-08-28T04:06:18.332814+00:00)

## What it is
Canarytokens is a self-hostable service by Thinkst that generates tripwire tokens (URLs, DNS names, AWS keys, files, etc.) which alert you when they are triggered. It helps detect unauthorized activity and lateral movement on your network.

## Use cases
- detect if someone is snooping on my network
- get alerted when a stolen AWS key is used
- track when a document is opened
- set up honeypot tripwires for breach detection
- monitor for lateral movement in my infrastructure
- self-host canary token generation and alerting

## When to choose
- you want lightweight, low-noise breach detection without a full honeypot
- you need self-hosted control over token generation and alert delivery
- you want to plant tripwires across cloud credentials, DNS, and files

## When to avoid
- you need full network intrusion detection with packet inspection
- you want a managed service without hosting your own frontend and switchboard components

## Facets
- artifact type: service
- maturity: active
- function: security, alerting, monitoring, webhook, self-hosted
- domain: security, networking, developer-tools
- platform: self-hosted, python
- tags: canarytokens, honeypot, intrusion-detection, deception-technology, breach-detection, tripwires, docker, linux

## Member repositories
- thinkst/canarytokens (main) score 76

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:18.332814+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:51:29.883288+00:00, confidence not recorded.
  - readme: https://github.com/thinkst/canarytokens (fetched 2026-08-28T04:06:18.332814+00:00, sha 929b47a62fab)
  - homepage: http://canarytokens.org (fetched 2026-08-29T10:31:28.812826+00:00, sha 5a29dab69902)
- Data as of 2026-08-30T08:39:29.467469+00:00.
