A few comments/suggestions:
* You have DEBUG = True in your production Django config. (eg. http://deckofcardsapi.com/api/)
* You are mutating state with HTTP GET, this is an anti-pattern for a number of reasons. The common one I use with people I coach is that browsers/proxies will happily cache GET requests unless told not to, but there are a number of other reasons if you read up on REST [1].
* Being a public API in a well known domain this is a good opportunity to make the API self documenting & navigable with a hypermedia format. (eg HAL, Siren, JSON-LD) [2]
[1] http://martinfowler.com/articles/richardsonMaturityModel.htm...
[2] http://sookocheff.com/posts/2014-03-11-on-choosing-a-hyperme...