I would test this out with the browser’s dev tools’s network tab open. I might have misunderstood your workflow, but I’ve got a hunch that the value gets assigned in the backend, but the actual call is done via the user’s browsers. Meaning that you could be leaking this secret.