Jici
3
If you store an API for a user, and this user provide the API key and only this user have access to this data (using privacy rules), this is not a problem to use the call because the API key belong to the user.
In other case, like @Zeroic, the only solution is to use backend WF.