A headless content API has two kinds of callers, and it's tempting to secure them the same way. That's the mistake.

There's a human logging into an admin UI to edit content, and there's a machine — a website, a build step — pulling published content through a delivery endpoint. They authenticate with different credentials, and those credentials...