Worth saying plainly since it is the elephant in the thread: if the data behind the paid API is valuable enough to be worth protecting properly, put it behind a login.
Authentication is the thing that actually answers "who is calling". Everything else in this thread is damage limitation for the case where you have decided the page must be public. That is often the right decision for reach and conversion reasons — just make it knowingly, rather than trying to get authentication's guarantees without authentication.