HTTP endpoint securing methods Between external sites and Node-Red

I've got a NR backend wrapped with a Wordpress site that manages individual users. Anyone keen on securing NR http endpoints between these two realms? I'm looking into 0Auth or similar JWT, but can't seem to wrangle Wordpress, and it may be a question for WP forums... Anyone have any references to any content that could clear the clouds on this (new to me) topic? I also understand there are several beasts at play here, and that knowledge of http headers is increasingly important.

I know if I wasn't forced by others to develop via Wordpress, I may have an easier time with this.

Any help or tips are super appreciated!

