Approach to restrict access to API?

I am building a site which exposes a few api calls for me to call from our in house software. What’s the best approach to secure these api endpoints? I just really needs something like an api key that we keep secret and our in house app uses.

Community Page
Last updated: