1. Add a way for users/admins to create API access tokens 2. Make the API more user friendly - Public API docs like with swagger or scala in the docs - Check if the routes are following the REST standard