I can look into it for the next release, I prefer to keep the UI locked down to only specific ip's and just keep the toec-api open for endpoint communication. Even with 2FA I would be very hesitant to open up the UI. That's a lot of power if someone gets into it.
J