#astronouth7303I advocate the use of HTTP signatures of all S2S, so you can verify who is making requests. You can apply it more tactfully for pushes (if it's the provider that owns the originating content or otherwise would be reasonable that they'd do the pushing)