TIL canary token
A false secret token that is monitored for usage to discover whether an account was compromised.
=> time to rotate all secrets stored on that account
Apparently that’s how the 2021 CircleCI security breach was discovered by a CircleCI user.