Skip to main content
Tracebit is currently in beta. Detections ingest normally, but are categorized as informational (non-escalating) while categorization rules are refined from production data. Auto-remediation is not performed for beta integrations.
  1. Log in to your Tracebit portal.
  2. Open your profile menu → User settingsManage API tokens.
  3. Click Create new token, add a description, choose an expiry, and enable alerts:all:list (Allows listing alerts). Copy the token when shown — it is only displayed once.
  4. In Wirespeed, go to Integrations → Add Integration and select Tracebit.
  5. Confirm the API URL matches your Tracebit environment (community.tracebit.com by default; Enterprise customers should use the hostname Tracebit provided), paste your API token, and connect the integration.
Tracebit deception alerts will begin syncing into Wirespeed on the next detection poll.
CLI OAuth tokens (for example from tracebit auth) do not include alerts:all:list and cannot be used for this integration. Create a dedicated API token from User settings → Manage API tokens instead.
On first sync, Wirespeed ingests up to the newest 1,000 alerts returned by the Tracebit list API.
Tracebit API tokens expire (Community defaults to one year). Wirespeed warns in integration logs when a token is within 30 days of expiry — create a replacement token in Tracebit and update the integration credentials before the current token expires.