proposal #2: We extend API key creation (e.g. via offer templates) with the ability to specify certain OPTIONS headers that should be returned unauthenticated. We could even let you specify static responses to certain routes, which would solve mnutt__'s problem with ownCloud wanting to hit /status.php unauthenticated.