I would recommend only allowing an open identifier in the API, as it would be difficult to implement bot prevention schemes in it (captcha ...)
In any case, even an open id isint, which is a great idea in the API. Are you sure you need registration accessible through the API?
source share