It's telling to me that, a large, heavily funded company, puts very simple static auth on their private API because they just don't expect anyone to use it. Contrast that to an indie company of about 20 people that uses a private key with a nonce and signature for theirs.

