use tokens rather than basic auth make the endpoints available check to see if they apply based on the actions
use tokens rather than basic auth
make the endpoints available check to see if they apply based on
the actions