As I can read from your _todos_ (Per-action options (Auth, ACL, Prefix, ...)), I can't set API which allow requests only for authenticated users, right?