Having some kind of lightweight auth (API key, even just email-based) is a good compromise