Full disclosure, I work for a company called CriticalBlue that helps customers with these types of issues. We have a recent blog article about setting up a proxy for API keys in this way that might be useful at https://www.approov.io/blog/protect-your-api-keys-with-appro... . We have a way of then locking down that proxy so only approved apps can use it - without simply circling back to the original problem of hiding secrets in apps.