If you want to share secure ArcGIS Server web service items with a wide audience, for example, as part of a public web app, store the credentials with the item so the public is not required to sign in to access the app. You may also want to limit usage to control how many times and by whom the service is accessed. You can specify the rate limit, and to further restrict usage, designate the specific referrer URLs or IPs that can access the service, for example, the URL of your portal organization. For example, if you have public kiosks in your lobby that run a web app that contains a secure service, you can designate the URL of your organization and the IP addresses of those kiosks so that they are the only machines allowed to access it.
Note:
Designating specific referrers ensures that the specified URLs or IP addresses can connect to the service, but it does not prevent someone from intercepting the proxy call to the secure service and changing it.
Once you add your secure service as an item and store credentials, but before you share it, follow these steps to limit use of the item:
- Open the item page for the secure service or app.
- Click the Settings tab and scroll down to the Limit Usage section. Click Limit Usage.
- Check the Enable rate limiting check box and set up the limits: a maximum number of requests allowed for a specific period of time or the referrer URLs and IPs that can access your service.For example, you can specify the URL to your portal, such as https://webadaptorhost.domain.com/myportal. You can also limit the rate and the referrer. Your referrer URLs and IPs can be fully qualified URLs, wildcards to include all subdomains (https://*.domain.com), or the IP address (https://10.4.3.4). You need to specify ports and add http and https if you want to allow access to both. For sharing services in apps hosted in your portal, you can provide either the URL to your app, or if you plan to have multiple apps that use the service, the URL to the portal's app directory (for example, https://webadaptorhost.domain.com/apps). 
- Click OK.
Now you can share the item with those intended to have access to it: your organization, everyone (public), or specific groups to which you belong.