very simple solution to the keys issue that took about 5 minutes to implement. There's now a DISPLAY_KEYS env var. If it's on, the API will return the real key values / tokens . If it's off, it will return the key name and uses, but sensitive info will be placeholder text: KEY_VALUE and ACCESS_TOKEN