If the API is public, anyone could use it to trigger builds. This should look for a `SECRET` env var and validate that against requests to avoid abuse.