I'm using smartystreets to verify address, etc.,. The only setting I'm giving them is the referrer URL.
When I request with postman by passing the correct referrer it works fine.
What if someone supplies the same header from AWS CloudFront and steals my account subscription limits.
Trying to understand how my subscription is protected.
Thanks.
Here is how I could query without a subscription from smartystreets,
URL Used GET with (Referrer: https://smartystreets.com/) Header:
Exposed Authentication TokenID: 21102174564513388