How to Create a Custom API Endpoint in Strapi

This is useful, is there a way I can lock this down so it’s only accessible by people logged in to the admin area?