# Can auth\_requests be abused for flooding?

**URL:** <https://hub.mender.io/t/can-auth-requests-be-abused-for-flooding/8020>\
**Category:** General Discussions\
**Tags:** api\
**Created:** [September 26, 2025, 7:34am UTC](https://hub.mender.io/t/can-auth-requests-be-abused-for-flooding/8020 "2025-09-26T07:34:02Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![smart4energy](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@smart4energy](https://hub.mender.io/u/smart4energy)\
**Post date:** [September 26, 2025, 7:34am UTC](https://hub.mender.io/t/can-auth-requests-be-abused-for-flooding/8020/1 "2025-09-26T07:34:02Z")

</div>

If an attacker knows our Mender auth URL, they could script thousands of `auth_requests` and create mass pending devices. Is there a way to prevent or mitigate this kind of flooding without blocking legitimate devices?
