What if we do not want to open our OpenAPI schema to the world? Then we should protect our endpoints. Using IdentityServer4 and OpenId Connect protocol...