Security concern about exposed token 🍳

Two types of users:

  1. Buyers don’t auth when browsing the catalog which is public. Yet the app needs to use some token credentials to access and publish the data, right?
  2. Service providers do CRUD ops to create an account and publish services, so app needs to use a specific token for such ops. It’s where temp user-specific token comes into play - any doc about how I do this?

Yes, all, no table-specific, in a json format.