This is misguided. As you note, the system is anonymous and
can't have any registration or authentication. Moreover, an Apple or Google specific API for validation would prevent interoperability of other (future) implementations including any free and open source (ie actually verifiable) ones.
Therefore, all authentication must be done on the receiving end by deciding which data sources to trust. This should be fairly straightforward because when a healthcare provider performs testing they are in a position to collect any keys from you at the same time. They are then the ones trusted to accurately report keys, which should be fine since we already trust them both to accurately report test results and to safeguard patient privacy.
Importantly, such a decentralized design allows for cooperative framework implementations, competing app implementations, and multiple data sources. Google or Apple could run a data server, your local government could run a data server, etc. Even more interestingly, such a framework could be repurposed for other less critical uses later as a form of privacy-preserving mutually opt-in contact discovery. Non-essential use of the framework might even ensure that people keep it running all the time, so that the data is ready and waiting the next time a novel pathogen appears.