We can add JWT support to secure the API. Access to different resources should only be provided to requests with valid tokens