---
title: "createHoneytoken"
description: "Register a honeytoken"
canonical: "https://pgbeam.com/docs/ts-sdk/honeytokens/createHoneytoken"
last-updated: "2026-09-09T11:37:53.000Z"
---

# createHoneytoken

> Register a honeytoken

URL: https://pgbeam.com/docs/ts-sdk/honeytokens/createHoneytoken

Registers a decoy (canary) relation for the project. Any agent statement that references it is blocked and recorded as a canary\_tripped audit event.

## Usage

## Parameters

Parameter

Type

Required

Description

pathParams.project\_id

`string`

Yes

Unique project identifier (prefixed, e.g. prj\_xxx).

body.schema\_name

`string`

No

Optional schema. Null or empty matches the unqualified/public form.

body.relation\_name

`string`

Yes

Relation (table or view) name of the decoy.

body.action

`"audit_only" \| "kill"`

Yes

Response when the honeytoken is tripped.

## Response

`Promise<Honeytoken>`: honeytoken registered.

## Example

## Errors

Status

Description

400

The request was rejected. `code` is `INVALID_INPUT`, and `errors` names the offending fields when the failure was a validation one.

401

Missing or invalid authentication. `code` is `UNAUTHORIZED`.

403

The caller is authenticated but not allowed to perform this operation. `code` is `FORBIDDEN` when the caller's role is insufficient, and `PLAN_LIMIT_REACHED` when the organization's plan is what stands in the way. The two are answered differently, so branch on the code rather than the status.

404

The resource does not exist, or the caller is not entitled to know that it does. `code` is `NOT_FOUND`.

409

The request conflicts with the current state. `code` distinguishes the cases: `RESOURCE_EXISTS` for a name or value already in use, `INVALID_STATE` for a resource that is no longer in a state that allows the operation, and `IDEMPOTENCY_KEY_REUSED` for a retry whose body does not match the request the key was first used for.

413

The request body exceeds the 2 MB limit. `code` is `PAYLOAD_TOO_LARGE`.

415

The request body is not JSON, or carries a body without declaring a Content-Type. `code` is `UNSUPPORTED_MEDIA_TYPE`.

429

Rate limited. `code` is `RATE_LIMITED`.

500

The request failed for a reason on our side. `code` is `INTERNAL_ERROR`. Quote `request_id` when reporting it.