so I\'m working on an API for user authentication. I want the functions to only be called by another server. I was thinking of checking the origin in the headers but it\'s n