Full AWS Practitioner Certification Question

What security feature exists for API apps that will either allow or prevent applications running from other domains (external websites) from calling the API?