Is it just me, or does it feel unacceptable that this token is exposed? There should be a way to create a middleware API endpoint that hides the token from the outside world