> It's the erosion of trust in the api calls themselves.

and that's why security thru obscurity fails. It just hasn't so far.

And if this is the current state of affairs, then the change and pain is what needs to happen for the system to improve.

For example, all api calls would have some form of authentication and attestation.