Is there a more secure way to interact with the SDK other than exposing the ApiKey and ApiSecret inside the code?