Swagger Do's and don'ts


Hey, quick question about Swagger.

I have all of my endpoints in my 'public' xano APi group, so all of my endpoints are in the public Swagger.

It seems I wouldn't want some endpoints available to the public. Like Stripe and other endpoints that can do some damage in the wrong hands.

Is that correct? Is it best practice to only put some endpoints public and protect others?

Fogive the newby question. Thanks for any responses.
