I have discovered a lot more about API, but I want to publish it gradually in case DE doesn't like it. I mean taking down partial API doc is easy but If I'd post everything I think It would be pretty messy :S
Altought, you can't rely on your application security just because you doesn't make things public. Application security is about doing secure programing aswell as implementing passive so as active security measures. One day DE will understand that...