CanarytokensCanarytokens
Home
Guide
Create
GitHub
Home
Guide
Create
GitHub
  • Create
  • Guide

    • Introduction
    • Getting Started
  • Examples

    • How to use the examples
    • Adobe PDF Canarytoken
    • AWS API Keys Canarytoken
    • AWS Infrastructure Canarytoken
    • Azure Entra ID login token
    • Azure Login Certificate Canarytoken
    • Cloned Website Canarytoken
    • Credit Card Canarytoken
    • CrowdStrike Client Credential Canarytoken
    • CSS Cloned Website Canarytoken
    • Custom EXE Canarytoken
    • DNS Canarytoken
    • Fake App Canarytoken
    • HTTP Canarytoken
    • Fake IdP SAML App Canarytoken
    • Kubeconfig Token
    • Log4shell Canarytoken
    • MCP Configuration Canarytoken
    • MS Excel Canarytoken
    • MS Word Canarytoken
    • MySQL Dump Canarytoken
    • Network Folder Canarytoken
    • QR Code Canarytoken
    • Fast Redirect Canarytoken
    • Slow Redirect Canarytoken
    • Sensitive Command Canarytoken
    • SQL Server Canarytoken
    • SVG Canarytoken
    • SVN Canarytoken
    • Unique email address Canarytoken
    • Web Image Canarytoken
    • Windows Directory Canarytoken
    • WireGuard Canarytoken

MCP Configuration Canarytoken

What is an MCP Canarytoken

This Canarytoken provides you with a JSON configuration for an MCP server. An attacker who stumbles on them will believe they provide agentic access to cloud infrastructure or other sensitive tools. You will be alerted either on an MCP client connection, or when the client calls an offered tool, depending on the token's configuration.

Creating the Canarytoken

Create a Canarytoken by choosing "MCP configuration" from the Canarytokens list.

Choose how you'd like the token to alert, either on an MCP client connecting to the server, or only when an MCP tool has been called.

Leave a reasonable comment to remind yourself where you will deploy the Canarytoken.

The JSON configuration that is displayed can be copied or downloaded into a file named mcp.json. These files are commonly found in code repositories in sub-directories that contain toolchain configurations. Common examples would be .claude/, or .cursor/. VSCode will look for a file named .mcp.json (note the prepended '.') in the root of a workspace.

Help us improve this page!
Last Updated: 6/22/26, 9:22 AM
Prev
Log4shell Canarytoken
Next
MS Excel Canarytoken