You can limit API access to specific actions but in order to help you further, I need to understand what is it exactly you DO want to allow your partners/clients to do.
Please describe the desired flow and what sort of data you do want to allow access to and what the desired end result is and I'll provide further guidance.