Later versions of boringproxy allow you to create tokens scoped to specific boringproxy clients, but overall access control is pretty rudimentary. It sounds like maybe what you’re looking for is something more like Tailscale (or selfhosting Headscale)?