I forget that if not done by a browser, this can be fakeable. Whitelisting Bubble IP could be better? If the request come from Bubble IP, allowed, if not, api key requested?