CANARY TRAPS
Tripwires for your files, folders, docs and links. When ANYONE touches one — opens the link, loads the pixel, pastes the credential into a checker — you get an instant alert with their IP, city, ISP and device. Nobody trips a canary by accident: that's the point.
New trap
Log in (no KYC) to see your traps.
API: POST /canary (tag, kind, rearm) · GET /api/canary/list (login) · GET /api/canary/hits?token= (login) — full hit log with geo.
EXAMPLE FLOW — catch someone opening your stolen files
- you create a trap tagged laptop-backups, type stealth link.
- you save the link as
RESTORE_THIS.txtinside your backup folder. - months later a thief copies the folder and opens the file out of curiosity.
- them the link opens — a blank 404, nothing suspicious — but the tripwire fires.
- you your INBOX lights up: laptop-backups hit from 203.0.113.7 — Rotterdam, NL · KPN · Windows Chrome · their timezone.
- open /canary → the trap row shows hit count + view hits → full log: time, IP, geo, device, language.
HOW IT WORKS
- A trap is a unique URL that belongs to you alone — one trap per hiding place.
- Stealth link returns a plain 404 page so the opener suspects nothing; the pixel is a 1×1 image that loads invisibly inside docs and emails.
- The credential type gives you a realistic-looking fake AWS key or DB password — attackers who find it run it through a checker, and the check itself is the tripwire.
- Every hit logs IP, city/region/country, ISP, device, language, referrer — and pings your site INBOX instantly.
- Leave rearm OFF for one-shot traps (the trap flips to TRIGGERED), ON when you want to keep counting hits silently.
JARGON — hover any chip:
tripwire honeytoken rearm pixel
FOR AGENTS ?
GET /api/canary/list · GET /api/canary/hits?token=curl "https://dark0rbits.thetempleofdoom.com/api/canary/hits?token=AbC123" -H "Cookie: dark0rbits_tok=…"Hits include ts, ip, ua, lang, ref. Create traps with POST /canary (form: tag, kind, rearm). · spec: /openapi.json · catalog: /llms.txt