I see that this library is built to run entirely on the client side. If so, how can we hide the API key? Doesn't this introduce security issues?