Hey this blog post answers this exact question in great detail.
https://zayntheprogrammer.com/how-to/how-to-secure-spring-boot-apis-from-non-browser-requests-like-postmancurl