> ## Documentation Index
> Fetch the complete documentation index at: https://docs.jesta.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Honeytokens we plant

> The bait types and where they go.

Honeytokens are fake credentials placed in the exact files attackers (and worms
like Shai-Hulud) scan first. Each is correct in *shape* - real prefixes like
`AKIA`, `github_pat_`, a `eyJ` JWT header, the right file format - so a scanner
believes it, while the key material is cryptographically random garbage that
authenticates to nothing. The UI accepts any path; the defaults below are
recommendations.

## Token types

| Token | Default path | Why it's bait |
| - | - | - |
| **AWS access key** | `~/.aws/credentials` | The standard credentials file the worm parses first for cloud keys |
| **GitHub PAT** | `~/.config/gh/hosts.yml` | Exfiltrated to self-replicate via the GitHub API (suggested paths include `~/.npmrc`, Shai-Hulud's primary target) |
| **GCP service account** | `~/.config/gcloud/application_default_credentials.json` | Cloud lateral movement |
| **Azure token** | `~/.azure/accessTokens.json` | Cloud lateral movement |
| **SSH private key** | `~/.ssh/id_rsa` | Any read is almost certainly malicious; host-key paths (`/etc/ssh/ssh_host_*_key`) catch server-side snooping |

Each type also ships a set of **suggested paths** - other realistic, attacker-
inspected locations (e.g. `~/.env`, `~/.netrc`, `~/.git-credentials`) - surfaced
when you create a tripwire.

## Sources

A tripwire's `source` decides how the bait content is produced for each
endpoint:

* **`template`** *(default)* - Thumper generates a fresh fake on the server, so
  every endpoint's bait is unique. Token generation lives on the server (not the
  browser) because creating a tripwire also mints a per-token HMAC secret and
  callback binding.
* **`custom`** - you supply the exact content to plant.
* **`managed`** - a monitored real credential from a managed service. *Planned.*


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.