Would it be a good addition to have optional basic http auth on some routes? I did that in my private fork and can clean up and send PR here