Oh, and the default role feature of apps makes it so that they can just use the API key without logging in. You could even set the default role very permissive during development and lock it down once the app is in production so that users would have to login.
↧