Currently, data api's only layer of security is the basic auth, without 2FA. I have to think of the architecture to implement it.