If the user can access the data through privacy rules, they can access it easily in the browser.
If the API key belongs to that user, that might be fine. Otherwise, it needs to be protected in the backend.