Better security with fine grained API permissions

The feature is implemented now: