Anyone who successfully authenticates through a Google account will be able to execute the API through the API.
I would like to restrict the ability to execute the API through the API only to some users. But at the same time, the API is available to all users of my Android and iOS applications.
Security, at least for Android applications, is facilitated by the Android client ID and SHA fingerprint. So the scope here is to NOT include application access protection.
google-cloud-endpoints
sam
source share