For example, A user can easily know your service endpoint as the code is deployed on the client side and send a request to that URL from their application as well, So you need to differentiate between the request from your application and other applications. (I personally use Google plus sign in API's, along with server side token validation to ensure that any back-end requests are originating fro