Require client API keys. Not strictly required for the Parsoid REST API, but it's important for later REST API work, so we may want to think about it now.
Ideally, 2-legged OAuth 2.0 bearer tokens for this particular API. Basically, a "magic cookie" provided out-of-band that identifies the client.