http://e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsyrwrygq27yd.onion/posts/blog/security/digging-into-the-behaviour-of-a-self-authenticating-mastodon-scraper-bot.html
Although the new controls rejected other bots with the reason mastoapi-no-auth (which indicates that they hadn't included an authentication token in their request) the bot in question was instead rejected with the reason mastoapi-token-invalid . This bot , unusually, was providing a token, just not a valid one. This, as you might expect, elicited an almost irresistable sense of curiosity: what was being provided as a token, and why was it being presented?