White/black listing on Key level (OSS)

Nope. Just white listing with “allowed_urls”, but for big APIs would be better to just black list few endpoints or resources under E.g. /admin/*.