V4 Custom API Token validation

it’s a bad idea to trust client side token, don’t