{"id":34635,"date":"2026-10-07T13:36:01","date_gmt":"2026-10-07T13:36:01","guid":{"rendered":"https:\/\/blog.lacnic.net\/?p=34635"},"modified":"2026-10-07T13:39:28","modified_gmt":"2026-10-07T13:39:28","slug":"canary-tokens","status":"publish","type":"post","link":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/","title":{"rendered":"Canary Tokens: An Early Warning Against Unauthorized Access"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">By <a href=\"https:\/\/blog.lacnic.net\/en\/author\/guillermo-pereyra\/\">Guillermo Pereyra<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the past, coal miners would enter underground tunnels carrying a canary in a cage. If the bird stopped singing, it was a warning that there was toxic gas in the air and it was time to escape.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We face a similar challenge in security. Many intrusions go undetected for weeks or months. By the time the attacker is discovered, they have already moved through the network, copied what they wanted, and left. Canary tokens propose a very simple idea: place small enticing traps in strategic locations and wait for someone to trigger them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we will explore what canary tokens are, how they work, how to deploy them in minutes, and the scenarios in which they can be useful.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>What Are Canary Tokens?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A canary token is a digital decoy, such as a file, credential, URL, or domain name, that has no legitimate use. No one should ever open or use it. Therefore, if someone finds and uses one, the token triggers an alert providing clear evidence of access, leaving little room for doubt.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Canary tokens are based on a simplified version of the concept behind a honeypot. There is no need to set up a complex server or simulate a service. All you have to do is place the decoy where an attacker is likely to look and configure where the alert should be sent.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>How Do They Work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Each token carries a unique identifier that triggers an action when activated. This action might be a DNS query, an HTTP request, or the use of a credential against a cloud service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a Word document might contain a reference to a remote resource hosted at a unique URL. When the document is opened in Microsoft Office, the program attempts to load that resource, and the token&#8217;s server logs information such as the IP address, date, time, and user agent. Seconds later, an alert arrives via email or webhook.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A DNS token can work even on networks that block outbound Internet access, as the query travels through the recursive resolver to the authoritative server for the token&#8217;s domain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>How to Deploy Canary Tokens<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The best-known tool is CanaryTokens, created by Thinkst. It is available at no cost through canarytokens.org and does not require user registration. Given its open-source nature, any organization can host its own instance using Docker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Creating a token takes just a few minutes:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Select the type of token you wish to create: Office documents or PDFs, URLs, DNS records, QR codes, API keys (such as AWS or SendGrid), SQL Server databases, decoy executables, or fake login pages, among others.<\/li>\n\n\n\n<li>Specify the destination where the alert will be sent, either an email address or a webhook that forwards alerts to Slack, Teams, or your SIEM.<\/li>\n\n\n\n<li>Write a descriptive reminder, for example, \u201cpayroll spreadsheet on the HR file server.\u201d When the alert arrives, this text will tell you what resource was accessed and where.<\/li>\n\n\n\n<li>Download the token and store it in a location where an attacker would actually look: code repositories, configuration files, shared folders, or CI\/CD variables.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A few best practices make a difference. It is advisable to use a different token for each location; this way, when one is triggered, you know the attacker&#8217;s point of entry. It also helps to assign them credible names (e.g., AWS_CREDENTIALS raises less suspicion than CANARY_AWS) and to test them after installation to confirm the alert is received. If a token is triggered, you should ideally preserve it for forensic analysis and replace it with a new one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This technique works in the real world: in 2025, Grafana Labs detected an intrusion when an attacker who had stolen secrets from their GitHub repositories attempted to validate an AWS key that was, in fact, a canary token. The alert was received instantly, and the incident was contained within minutes.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens-1024x575.png\" alt=\"\" class=\"wp-image-34632\" srcset=\"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens-1024x575.png 1024w, https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens-300x169.png 300w, https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens-587x330.png 587w, https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens-768x432.png 768w, https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/fig2-canarytokens.png 1178w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Use Cases<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Intruder detection<\/strong>: fraudulent credentials in a ~\/.aws\/credentials file, in application configuration settings, or anywhere in a source code repository. An attacker who discovers these credentials will almost always attempt to validate them.<\/li>\n\n\n\n<li><strong>Document leaks<\/strong>: a PDF or Word document with an eye-catching filename that triggers an alert when opened, even from outside our network.<\/li>\n\n\n\n<li><strong>Unauthorized internal access<\/strong>: a file with an enticing name placed in a shared folder that should only be accessed by a specific department or team.<\/li>\n\n\n\n<li><strong>Cloned phishing sites<\/strong>: a snippet of code embedded in our site that alerts us if the page is duplicated and published on another domain.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The most frequently cited case is that of Grafana Labs. In April 2025, an attacker exploited a misconfigured GitHub Actions workflow to steal secrets. Among them was a decoy AWS key. When the attacker validated this key using an automated tool, the alert was triggered immediately, and the team contained the intrusion within minutes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Key Considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Canary tokens do not replace other security controls. When a canary token is triggered, an intruder has already gained access. Their value lies in shortening the time between intrusion and detection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They also have limitations. Publicly available token services use well-known domains, and some attacker tools can recognize canary tokens without actually triggering them. Installing a proprietary instance with a custom domain reduces this risk, although certain token types such as AWS keys require additional infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, an alert is only effective if someone reads it. It is important to route alerts to a channel the team actively monitors and to have a clear plan of action for when an alert arrives. This could be a dedicated dashboard within our SIEM or monitoring system.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>Final Thoughts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Canary tokens are based on a deceptively simple idea: if something should not be touched, viewed, or executed, any interaction is an alert signal. This simplicity is their greatest strength. With just a few minutes of work and no financial cost, we can plant a network of small alarms that generate almost no false positives and require very little maintenance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The technique itself is not new. It is the same method used by hidden pixels in marketing emails to track whether a recipient has opened a message. The difference here is that we are applying it for defensive purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Canary tokens do not prevent an attack or replace other security controls, but they introduce a key change: rather than finding out months later, they alert us while there is still time to act. Like the miner&#8217;s canary, they do not eliminate the danger, but they offer us the opportunity to react before it is too late.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A good starting point is to create an AWS credential token today and place it in an internal repository. It is the simplest type of trap and, as the Grafana Labs incident showed, one of the most effective.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><a><\/a>References<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Canarytokens (free service): https:\/\/canarytokens.org<\/li>\n\n\n\n<li>Canarytokens source code: https:\/\/github.com\/thinkst\/canarytokens<\/li>\n\n\n\n<li>Docker configuration to setup a Canarytoken: https:\/\/github.com\/thinkst\/canarytokens-docker<\/li>\n\n\n\n<li>Grafana Labs, incident announcement (April de 2025): <a href=\"https:\/\/grafana.com\/blog\/2025\/04\/27\/grafana-security-update-no-customer-impact-from-github-workflow-vulnerability\/\">https:\/\/grafana.com\/blog\/2025\/04\/27\/grafana-security-update-no-customer-impact-from-github-workflow-vulnerability\/<\/a><\/li>\n\n\n\n<li>Grafana Labs, \u201cCanary tokens: Learn all about the unsung heroes of security at Grafana Labs\u201d (August 2025): <a href=\"https:\/\/grafana.com\/blog\/2025\/08\/25\/canary-tokens-learn-all-about-the-unsung-heroes-of-security-at-grafana-labs\/\">https:\/\/grafana.com\/blog\/2025\/08\/25\/canary-tokens-learn-all-about-the-unsung-heroes-of-security-at-grafana-labs\/<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>By Guillermo Pereyra In the past, coal miners would enter underground tunnels carrying a canary in a cage. If the bird stopped singing, it was a warning that there was toxic gas in the air and it was time to escape. We face a similar challenge in security. Many intrusions go undetected for weeks or [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":34626,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[499],"tags":[1271],"archivo":[1345,1451],"taxonomy-authors":[1245],"tipo_autor":[],"class_list":["post-34635","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cibersecurity","archivo-editions","archivo-highlights-2023","taxonomy-authors-guillermo-pereyra-en"],"acf":{"author":"","related_notes":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.lacnic.net\/en\/canary-tokens\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access\" \/>\n<meta property=\"og:description\" content=\"By Guillermo Pereyra In the past, coal miners would enter underground tunnels carrying a canary in a cage. If the bird stopped singing, it was a warning that there was toxic gas in the air and it was time to escape. We face a similar challenge in security. Many intrusions go undetected for weeks or [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.lacnic.net\/en\/canary-tokens\/\" \/>\n<meta property=\"og:site_name\" content=\"LACNIC Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/facebook.com\/lacnic\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-07T13:36:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-07T13:39:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png\" \/>\n\t<meta property=\"og:image:width\" content=\"680\" \/>\n\t<meta property=\"og:image:height\" content=\"330\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Gianni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@lacnic\" \/>\n<meta name=\"twitter:site\" content=\"@lacnic\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/\"},\"author\":{\"name\":\"Gianni\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/person\\\/1338d9cfdb0137e8bc5581f3771f39ab\"},\"headline\":\"Canary Tokens: An Early Warning Against Unauthorized Access\",\"datePublished\":\"2026-10-07T13:36:01+00:00\",\"dateModified\":\"2026-10-07T13:39:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/\"},\"wordCount\":1195,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/canarytokens.png\",\"keywords\":[\"Cibersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/\",\"name\":\"LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/canarytokens.png\",\"datePublished\":\"2026-10-07T13:36:01+00:00\",\"dateModified\":\"2026-10-07T13:39:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#primaryimage\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/canarytokens.png\",\"contentUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/canarytokens.png\",\"width\":680,\"height\":330,\"caption\":\"Canario en una jaula junto a una computadora que muestra una alerta de seguridad\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/canary-tokens\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Canary Tokens: An Early Warning Against Unauthorized Access\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#website\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/\",\"name\":\"LACNIC Blog\",\"description\":\"En el Blog de LACNIC encontrar\u00e1s art\u00edculos t\u00e9cnicos vinculados al desarrollo de Internet en la regi\u00f3n de Am\u00e9rica Latina y el Caribe.\",\"publisher\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blog.lacnic.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#organization\",\"name\":\"LACNIC Blog\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/lacnic-blog.svg\",\"contentUrl\":\"https:\\\/\\\/blog.lacnic.net\\\/wp-content\\\/uploads\\\/2023\\\/03\\\/lacnic-blog.svg\",\"caption\":\"LACNIC Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/facebook.com\\\/lacnic\",\"https:\\\/\\\/x.com\\\/lacnic\",\"https:\\\/\\\/www.instagram.com\\\/lacnic\\\/?hl=es-la\",\"https:\\\/\\\/uy.linkedin.com\\\/company\\\/lacnic\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/lacnicstaff\",\"https:\\\/\\\/www.lacnic.net\\\/podcast\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blog.lacnic.net\\\/#\\\/schema\\\/person\\\/1338d9cfdb0137e8bc5581f3771f39ab\",\"name\":\"Gianni\",\"url\":\"https:\\\/\\\/blog.lacnic.net\\\/en\\\/author\\\/gianni\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/","og_locale":"en_US","og_type":"article","og_title":"LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access","og_description":"By Guillermo Pereyra In the past, coal miners would enter underground tunnels carrying a canary in a cage. If the bird stopped singing, it was a warning that there was toxic gas in the air and it was time to escape. We face a similar challenge in security. Many intrusions go undetected for weeks or [&hellip;]","og_url":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/","og_site_name":"LACNIC Blog","article_publisher":"https:\/\/facebook.com\/lacnic","article_published_time":"2026-10-07T13:36:01+00:00","article_modified_time":"2026-10-07T13:39:28+00:00","og_image":[{"width":680,"height":330,"url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","type":"image\/png"}],"author":"Gianni","twitter_card":"summary_large_image","twitter_creator":"@lacnic","twitter_site":"@lacnic","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#article","isPartOf":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/"},"author":{"name":"Gianni","@id":"https:\/\/blog.lacnic.net\/#\/schema\/person\/1338d9cfdb0137e8bc5581f3771f39ab"},"headline":"Canary Tokens: An Early Warning Against Unauthorized Access","datePublished":"2026-10-07T13:36:01+00:00","dateModified":"2026-10-07T13:39:28+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/"},"wordCount":1195,"commentCount":0,"publisher":{"@id":"https:\/\/blog.lacnic.net\/#organization"},"image":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","keywords":["Cibersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blog.lacnic.net\/en\/canary-tokens\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/","url":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/","name":"LACNIC Blog | Canary Tokens: An Early Warning Against Unauthorized Access","isPartOf":{"@id":"https:\/\/blog.lacnic.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#primaryimage"},"image":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#primaryimage"},"thumbnailUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","datePublished":"2026-10-07T13:36:01+00:00","dateModified":"2026-10-07T13:39:28+00:00","breadcrumb":{"@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.lacnic.net\/en\/canary-tokens\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#primaryimage","url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","contentUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","width":680,"height":330,"caption":"Canario en una jaula junto a una computadora que muestra una alerta de seguridad"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.lacnic.net\/en\/canary-tokens\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/blog.lacnic.net\/en\/"},{"@type":"ListItem","position":2,"name":"Canary Tokens: An Early Warning Against Unauthorized Access"}]},{"@type":"WebSite","@id":"https:\/\/blog.lacnic.net\/#website","url":"https:\/\/blog.lacnic.net\/","name":"LACNIC Blog","description":"En el Blog de LACNIC encontrar\u00e1s art\u00edculos t\u00e9cnicos vinculados al desarrollo de Internet en la regi\u00f3n de Am\u00e9rica Latina y el Caribe.","publisher":{"@id":"https:\/\/blog.lacnic.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.lacnic.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/blog.lacnic.net\/#organization","name":"LACNIC Blog","url":"https:\/\/blog.lacnic.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.lacnic.net\/#\/schema\/logo\/image\/","url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2023\/03\/lacnic-blog.svg","contentUrl":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2023\/03\/lacnic-blog.svg","caption":"LACNIC Blog"},"image":{"@id":"https:\/\/blog.lacnic.net\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/facebook.com\/lacnic","https:\/\/x.com\/lacnic","https:\/\/www.instagram.com\/lacnic\/?hl=es-la","https:\/\/uy.linkedin.com\/company\/lacnic","https:\/\/www.youtube.com\/user\/lacnicstaff","https:\/\/www.lacnic.net\/podcast"]},{"@type":"Person","@id":"https:\/\/blog.lacnic.net\/#\/schema\/person\/1338d9cfdb0137e8bc5581f3771f39ab","name":"Gianni","url":"https:\/\/blog.lacnic.net\/en\/author\/gianni\/"}]}},"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/blog.lacnic.net\/wp-content\/uploads\/2026\/10\/canarytokens.png","wpml_current_locale":"en_US","wpml_translations":[{"locale":"es_ES","id":34618,"post_title":"Canary tokens: la alarma temprana ante accesos no autorizados","slug":"canary-tokens","href":"https:\/\/blog.lacnic.net\/canary-tokens\/"},{"locale":"pt_BR","id":34637,"post_title":"Canary tokens: alerta precoce contra acessos n\u00e3o autorizados","slug":"canary-tokens","href":"https:\/\/blog.lacnic.net\/pt-br\/canary-tokens\/"}],"_links":{"self":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/comments?post=34635"}],"version-history":[{"count":2,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34635\/revisions"}],"predecessor-version":[{"id":34648,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/posts\/34635\/revisions\/34648"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/media\/34626"}],"wp:attachment":[{"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/media?parent=34635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/categories?post=34635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/tags?post=34635"},{"taxonomy":"archivo","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/archivo?post=34635"},{"taxonomy":"taxonomy-authors","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/taxonomy-authors?post=34635"},{"taxonomy":"tipo_autor","embeddable":true,"href":"https:\/\/blog.lacnic.net\/en\/wp-json\/wp\/v2\/tipo_autor?post=34635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}