Arm
Register the decoy fingerprint under the appropriate account and integration.
API reference ↗Tripwires detect an armed decoy reaching a monitored deny.sh decrypt endpoint. They do not observe every use of a fake credential.
Use the existing API reference for request shapes and authentication.
Register the decoy fingerprint under the appropriate account and integration.
API reference ↗A monitored decrypt endpoint must see the armed decoy for a hosted detection event.
Decoy alerts dashboard ↗Connect alerts and signed webhooks to your incident workflow. Rotation is your integration’s responsibility.
Webhook settings ↗A credential provider refusing a fake key is not a deny.sh observation. Offline decryption does not reach a monitored hosted endpoint.
Tripwires supplement the boundary; they do not replace it. Compromise of the real-key resolver and misuse of an authorised tool need their own controls.
Read the threat model ↗