I was wondering if there are any steps a developer of a small app can take to add such a header and lock down the API so it only answers to said header.
This level of obfuscation doesn’t seem doable for smaller shops. Is there something simpler, that is “good enough”?