Developers / Detection

Observe the decrypt.
Connect the response.

Tripwires detect an armed decoy reaching a monitored deny.sh decrypt endpoint. They do not observe every use of a fake credential.

01 / Event path

From a fingerprint to your workflow.

Use the existing API reference for request shapes and authentication.

01

Arm

Register the decoy fingerprint under the appropriate account and integration.

API reference ↗
03

Respond

Connect alerts and signed webhooks to your incident workflow. Rotation is your integration’s responsibility.

Webhook settings ↗
02 / Test the boundary

Rejection is not detection.

A credential provider refusing a fake key is not a deny.sh observation. Offline decryption does not reach a monitored hosted endpoint.

Keep the real key out of context.

Tripwires supplement the boundary; they do not replace it. Compromise of the real-key resolver and misuse of an authorised tool need their own controls.

Read the threat model ↗