http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/digging-into-the-behaviour-of-a-self-authenticating-mastodon-scraper-bot.html
And yet, the logs show that the bot is getting a positive response: they've either got a secret, or have found a way to exploit the endpoint. Looking at the request in the packet capture, we can see that it's the former: The bot is providing both client_id and client_secret , Mastodon obviously considers them valid, because it's returning a token.