@ge0rg They appeared to be doing something slightly more interesting, but an allowlist is part of what I would have done.
I would have, in fact, migrated the system to one that uses opaque random bearer tokens, but difficult to do that in a single day.