Whitelist domain for my api

Hello guys,
Wondering if there is a way to allowlist certain domains that can have access/ping my workers API?
I’ve tried using header origin and referer, but both seems to be unreliable, it returns blank when I tried it, only worked when I used it via the playground editor.