Strapi public api route securit question

Lets say I make an api route public and auth set to false, I could still achieve the same behaviour by passing in my jwt token and using the JWT SECRET to decode it in the controller right? Am I missing something, it cant be that easy right?

This topic has been created from a Discord post (1266522032536031242) to give it more visibility.
It will be on Read-Only mode here.
Join the conversation on Discord