I don't think it's a good idea either, your API token will be exposed and anyone can query whatever

I don't think it's a good idea either, your API token will be exposed and anyone can query whatever they want with your database, eg deleting all tables.
Was this page helpful?