In the plug-in world, how can we better protect our API?

With the plug-in market, more and more third-party plug-ins are born. When we use third-party plug-ins, how can we better protect our API and incompletely expose the background display of plug-ins? Recently, read a lot of user suggestions, some say, through the environment variables can be changed, can it really be done?