Updates
What's new in Decoy.
Late March 2026
CLI v0.4 — agents, config, watch, doctor
- -decoy agents — list connected agents with status, triggers, last seen
- -decoy agents pause / resume — disable tripwires per-agent without uninstalling
- -decoy config — view and set alert preferences (email, Slack, webhook) from the CLI
- -decoy watch — live tail of triggers in your terminal
- -decoy doctor — diagnose setup issues (config, token, server, Node version)
- -decoy login — install with an existing token (no signup required)
- -Local-only mode — server works without a token, logs triggers to stderr
- -Multi-host support: Claude Desktop, Cursor, Windsurf, VS Code, Claude Code
Early March 2026
Decoy launches
- -Tripwire MCP server with 12 decoy tools
- -Dashboard with trigger log, agent fingerprinting, severity classification
- -CLI: npx decoy-mcp init — 30-second setup
- -Passkey authentication (Touch ID, Face ID, security keys)
- -Email alerts on trigger
- -agent.txt for machine discovery
- -OpenAPI spec at /api/openapi.json
- -Free tier: 30-day history, email alerts
- -Pro tier ($9/mo): 30-day history, Slack + webhook alerts
Coming soon
Agent Monitor
- -Daily threat intelligence cron
- -Personalized weekly email digest
- -REST API for agents to query threat data directly
Coming soon
Shield private beta
- -Real-time tool call inspection
- -Behavioral baselines per agent
- -Corpus-informed detection rules
- -Agent authorization layer