Could be as simple as no auth in debug builds and then deployed it by accident.
Lazy API that did not vet a simple backdoor?
Good coders but accidentally pushed the debug version of the API?
I am going to have to say the second option feels less likely (yes, I have been called cynical).
It was just an example. Maybe they knew.