I am working with an api that sends you a code that can be used to authenticate with their server and give you requests, however if a malicious user were to get their hands