I have REST API service. I am using api-key for client validation and then JWT for user validation. I store GET requests in CloudFlare cache (without validation of api-key,