The source field in the message header should be populated with the client_id of the message sender.
client_id
If the header.source doesn't match the credentials return a 403.
header.source