A headless CMS comes with a REST API, and many CMSs leave it open for anyone to read. BizzCMS keeps it closed until you decide otherwise.
Closed means
Every request to /api needs a signed-in user or an API key. Outsiders cannot list your collections or read your API description. The health check stays open for uptime monitoring.
Open when you need it
Under Settings, API you can switch to Open. Published content, the collection list and the API description then become readable by anyone. Drafts, media and admin routes always need a login.
Apps and AI assistants
Create an API key under Plugins, API Keys and send it as the x-api-key header. AI assistants connect through MCP with a key too, and get read-only access to your pages and posts.