# Homey failed authentication logs

**URL:** <https://community.homey.app/t/homey-failed-authentication-logs/125581>\
**Category:** Questions & Help\
**Created:** [December 27, 2024, 11:43am UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581 "2024-12-27T11:43:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![flaviuvlaicu](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/flaviuvlaicu/32/97113_2.png) [@flaviuvlaicu](https://community.homey.app/u/flaviuvlaicu)\
**Post date:** [December 27, 2024, 11:43am UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/1 "2024-12-27T11:43:44Z")

</div>

Is there a way to have access to the authentication logs for homey. I would like to make a parser and an attack procedure for preventing brute force on the login page using Crowdsec.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 27, 2024, 11:46am UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/2 "2024-12-27T11:46:00Z")

</div>

Authentication is done in the cloud, so you don’t have access to any logs (or can prevent any brute force attacks).

---

<div class="post-metadata">

**Author:** ![flaviuvlaicu](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/flaviuvlaicu/32/97113_2.png) [@flaviuvlaicu](https://community.homey.app/u/flaviuvlaicu)\
**Post date:** [December 27, 2024, 11:56am UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/3 "2024-12-27T11:56:07Z")

</div>

> [@robertklep](#):
>
> the cloud, so you don’t have access to any logs

Having the connection to “local secure” I suppose that you do not need internet connection thus no cloud for this.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 27, 2024, 11:59am UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/4 "2024-12-27T11:59:26Z")

</div>

> [@flaviuvlaicu](#):
>
> Having the connection to “local secure” I suppose that you do not need internet connection thus no cloud for this.

It just means that your app is using the authentication token that it received from the cloud servers to access your Homey directly through the Web API. Authentication is always done in the cloud, authorization is done locally by matching if the correct token was sent along with the API request.

---

<div class="post-metadata">

**Author:** ![flaviuvlaicu](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/flaviuvlaicu/32/97113_2.png) [@flaviuvlaicu](https://community.homey.app/u/flaviuvlaicu)\
**Post date:** [December 27, 2024, 12:01pm UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/5 "2024-12-27T12:01:55Z")

</div>

Thanks, I honestly forgot how it was, this kind of sucks. I would have been nice to make it locally and have the possibility to imply firewall rules to it.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 27, 2024, 12:02pm UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/6 "2024-12-27T12:02:43Z")

</div>

> [@flaviuvlaicu](#):
>
> honestly forgot how it was

That’s what Athom calls “everything local” 🤷🏼‍♂️

---

<div class="post-metadata">

**Author:** ![flaviuvlaicu](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/flaviuvlaicu/32/97113_2.png) [@flaviuvlaicu](https://community.homey.app/u/flaviuvlaicu)\
**Post date:** [December 27, 2024, 12:03pm UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/7 "2024-12-27T12:03:33Z")

</div>

Is there any way to see authentication failed logins even if the authentication is made in the cloud? You could trigger an automatic rule inside your home.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 27, 2024, 12:04pm UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/8 "2024-12-27T12:04:19Z")

</div>

> [@flaviuvlaicu](#):
>
> Is there any way to see authentication failed logins even if the authentication is made in the cloud?

No ☹

---

<div class="post-metadata">

**Author:** ![flaviuvlaicu](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/flaviuvlaicu/32/97113_2.png) [@flaviuvlaicu](https://community.homey.app/u/flaviuvlaicu)\
**Post date:** [December 27, 2024, 12:04pm UTC](https://community.homey.app/t/homey-failed-authentication-logs/125581/9 "2024-12-27T12:04:54Z")

</div>

🥲 ohh well…:
