These endpoints, as expected, don't require any form of authentication. They mostly don't provide any substantial way to interact with the API as well, meaning they're exclusively for authenticating. Examples would be the login endpoint and the forgot-password endpoint.
They are rate-limited based on the requester's IP address, and the limit is 20 requests per minute.
