IMHO the best way to do authorization if your application otherwise works completely in the frontend:
Rent a tiny VM for $5/month and set up a small "enter your email, you'll get a magic link" application you write in Python or PHP.
And proxy whatever API access you want to restrict to authorized users through a simple Python or PHP script which can just be a few lines of code. It looks up the cookie set by the magic link, checks if it is allowed to access the endpoint and if yes proxies the request.