They used to require authorization, but at some point we made them anonymous to avoid blocking the frontend. Now that we have a working auth, they should be secured again.