@iwojima I'm not really sure if this reasoning applies to ActivityPub world where peers are discovered automatically.
When Mitra encounters a new actor, its home server is added to the "instance" database table. If you don't want that, you can switch to allowlist federation.
Client API endpoints that require authorization are protected with OAuth