# Your public API has no login — and no identity

> Browsing without signing in is the requirement. Trusting the header was the bug.

- **Format:** short video, 8 steps, ~26 seconds
- **Topic:** Why a public API that browses without login still needs an identity, and how a short-lived guest token gives it one
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** Azure · Azure Security
- **Published:** 2026-09-28
- **Tags:** Azure, APISecurity, DotNet, AspNetCore, JWT, CloudSecurity, WebDevelopment, SoftwareEngineering, MSDEVBUILD, Firebase, AppSecurity, SoftwareArchitecture, DeveloperCommunity, LearnInPublic
- **Canonical URL:** https://blog.msdevbuild.com/shorts/public-api-without-login/

---
## What you'll learn

- An Origin or X-Client-App header is a string the caller chooses, so it authenticates a channel, not a caller.
- A short-lived guest token gives an anonymous request a countable, expiring, revocable identity without any account behind it.
- Rate-limit on the token subject rather than the IP: addresses rotate hourly on a proxy pool and a whole office shares one behind NAT.

## Understand it one step at a time

### 1. Browsing without a login was the requirement

Search and browse before sign-in is a deliberate product decision, and the right one. Nobody creates an account to see a menu.

### 2. So the API checked where it came from

An Origin header and a custom client header. It looked like a gate for about three weeks.

### 3. Then someone pressed Copy as cURL

Right-click the request in the Network tab. Every header comes with it. No app, no session, no phone.

### 4. The server cannot tell them apart

Same URL, same headers, same TLS. A request does not carry proof of which app created it.

### 5. Cosmos DB paid the bill

Single-letter searches fanned out across every partition. Real customers started getting 429s during a promotion.

### 6. Anonymous is not the same as unauthenticated

Anonymous means you do not know who the user is. Unauthenticated means you do not know anything — including how many times they called you today.

### 7. Give the caller a token of its own

Fifteen minutes, one scope, a subject you invented. The user never sees a login screen, but the call now carries an identity.

### 8. Now it is countable, and revocable

Rate-limit on the token subject, not the IP. Cache the catalogue at the edge. The scraper now costs you a CDN hit and shows up on a dashboard.

---

## The takeaway

**Anonymous is not unauthenticated.**

Give the anonymous caller a short-lived, tightly scoped identity, and the endpoint you were nervous about becomes one you can measure.
