Setting the API to require a token and adding a honeypot to the pages themselves seems like a decent solution.