Canary Tokens
Generates lightweight, embedded honeypot triggers called canary tokens for detecting unauthorized access.
Activity has dropped noticeably. Check the repository before committing to it.
Commit activity more than 16% of tracked projects; popularity more than 58%. How this is calculated.
Commits, last 11 months
| Stars | 3k |
|---|---|
| Latest release | v0.9.10 · 21 Sept 2026 |
| Repo updated | 21 Sept 2026 |
| Licence | BSD-3-Clause |
| Built with | Docker, Python |
Is Canary Tokens actively maintained?
Canary Tokens is under active development: 38 commits landed over the last 11 months, averaging roughly 2 commits a month in the most recent quarter.
Activity is cooling: commits are down 67% against the previous quarter. One slow quarter is normal; two in a row is a signal.
The most recent tagged release, v0.9.10, shipped within the last month — a current, installable version exists today.
Canary Tokens ranks #7 of 11 in Network Utilities, placing it mid-table for maintenance activity.
What Canary Tokens actually does
Canary Tokens generates lightweight, embedded honeypot triggers that alert you when unauthorized access occurs. By deploying these tokens across your network or documents, you can detect intruders attempting to read files or probe services. It provides a straightforward mechanism for early intrusion detection.
Best fit: This tool is well-suited for security engineers and system administrators who want to set up tripwires across internal networks or sensitive document stores to catch lateral movement.
Worth knowing: Maintenance health is moderate, meaning you should keep an eye on upstream updates and dependency management. Relying solely on tokens for security is insufficient without proper monitoring and incident response workflows.
Deployment notes
Since it runs via Docker and Python, you will typically need to configure persistent storage for your generated tokens and logs, alongside a reverse proxy to handle incoming TLS connections securely.
Links
Canary Tokens as a replacement for
Alternatives to Canary Tokens
Projects in the same categories, ordered by health score.
All in one IP Toolbox. Easy to check what's your IPs, IP geolocation, check for DNS leaks, examine WebRTC connections, speed test, ping test, MTR test, check website availability and more.
Network intruder and presence detector. Scans for devices connected to your network and alerts you if new and unknown devices are found.
Monitor the performance and uptime of your internet connection.
A simple Wake on LAN (WOL) dashboard app. Wake up devices on your network and see current status.
Honeypot framework designed to provide a highly secure environment for detecting and analyzing cyber attacks.
WHOIS/RDAP query API for domains, IP addresses, CIDR prefixes and ASNs, with unified JSON output, caching, API key authentication, batch queries and MCP support for AI assistants.