You already do the hard part of this. You authenticate your production APIs. You treat anything from the public internet as hostile until proven otherwise.
Source: [Dev.to](https://dev.to/neerazz/the-web-page-couldnt-reach-localhost-your-agent-carried-it-there-2ip6)