Thats true, but it feels safer anyway.
Do you have any suggestions to how it should be handled?
I know many apis send clientkey/client secret as parameters to get an accessToken, and that’s exactly what i do here. The only reason why I’m not so comfortable is because with this service you have to use your username and password to get the access token in return.