There are many ways to do this, but one way is to use Vapor as a proxy. Vapor server takes care of the authorization/authentication, and it routes the requests to an internal auth-less API endpoint not exposed to the outside world.
Basically you can build a CRUD app without authentication at all (only accessible by your own API clients). And then allow only Vapor to write to the API internally.
This would be the most basic approach. I think it will become more clear once I release the implementation, just wanted to get the protocol out there first.