I have written several PHP web services where I pass in arguments via the URL. To prevent unauthorized access, I pass in a unique key as one of the arguments. I call the PHP
if(empty($_SERVER['HTTPS'])) { // .... exit; }