Depends how much entropy is in your primary keys.
If your primary keys are monotonic or time based, bad actors can simply walk your API.