See this post: http://blog.dreamfactory.com/share-api-docs-securely
The most recent DreamFactory release (2.8.1) improved this functionality even more, so that the API Docs will not show users endpoints they don’t have access to.
(Previously, it would show them, but you wouldn’t be able to operate them.)