I am going to create a REST API for the mobile application I'm working on. Like Instagram, I am considering blocking some endpoints so that they can only be accessed from my mobile application (for example, the endpoints of their photo uploads).
Does anyone have an idea of โโhow they blocked certain endpoints just for their application? I assume that a possible solution was to use a shared secret to sign these specific requests and verify it on the server side before processing the download.
source share