Skip to main content
Honeytokens are fake credentials placed in the exact files attackers (and worms like Shai-Hulud) scan first. Each is correct in shape - real prefixes like AKIA, github_pat_, a eyJ JWT header, the right file format - so a scanner believes it, while the key material is cryptographically random garbage that authenticates to nothing. The UI accepts any path; the defaults below are recommendations.

Token types

Each type also ships a set of suggested paths - other realistic, attacker- inspected locations (e.g. ~/.env, ~/.netrc, ~/.git-credentials) - surfaced when you create a tripwire.

Sources

A tripwire’s source decides how the bait content is produced for each endpoint:
  • template (default) - Thumper generates a fresh fake on the server, so every endpoint’s bait is unique. Token generation lives on the server (not the browser) because creating a tripwire also mints a per-token HMAC secret and callback binding.
  • custom - you supply the exact content to plant.
  • managed - a monitored real credential from a managed service. Planned.