Correct.

If its a key that can expose your users in any way as far as personal data goes, it’s best to do that in the back-end like @georgecollier had stated.