IMHO to me, un-authed responses to the "API subdomain" sound to me like the "API subdomain" wants to delegate some of its actions to (effectively) static publishing.