should only allow queries of on on a wildcard subdomain of url used `http://novaplays.org/` if on localhost of restclient headless require a apikey. Should be fine if others have the apikey b/c should only work in combination w/ the dev urls.