Updates

What's new in Decoy.

Late March 2026

CLI v0.4 — agents, config, watch, doctor

  • -decoy agents — list connected agents with status, triggers, last seen
  • -decoy agents pause / resume — disable tripwires per-agent without uninstalling
  • -decoy config — view and set alert preferences (email, Slack, webhook) from the CLI
  • -decoy watch — live tail of triggers in your terminal
  • -decoy doctor — diagnose setup issues (config, token, server, Node version)
  • -decoy login — install with an existing token (no signup required)
  • -Local-only mode — server works without a token, logs triggers to stderr
  • -Multi-host support: Claude Desktop, Cursor, Windsurf, VS Code, Claude Code

Early March 2026

Decoy launches

  • -Tripwire MCP server with 12 decoy tools
  • -Dashboard with trigger log, agent fingerprinting, severity classification
  • -CLI: npx decoy-mcp init — 30-second setup
  • -Passkey authentication (Touch ID, Face ID, security keys)
  • -Email alerts on trigger
  • -agent.txt for machine discovery
  • -OpenAPI spec at /api/openapi.json
  • -Free tier: 30-day history, email alerts
  • -Pro tier ($9/mo): 30-day history, Slack + webhook alerts

Coming soon

Agent Monitor

  • -Daily threat intelligence cron
  • -Personalized weekly email digest
  • -REST API for agents to query threat data directly

Coming soon

Shield private beta

  • -Real-time tool call inspection
  • -Behavioral baselines per agent
  • -Corpus-informed detection rules
  • -Agent authorization layer