I am building an application that requires users to store their third party API key's and secret's in order to use the third party service within my application. I have safely stored these keys into the database and hashed the secret. But I do not know the best practice for how I should be using the third party service in my application. Whether it is better to use it in the front end of my application or the back end.
For the front end option I will need to call the api key and secret from my database from the front end application. Which will then need to make the third party api call in order to pull the data and information from the third party. But wouldn't this potentially expose user api key's?
Or from the back end but then I will need to make the call from the server to the third party service and then send that information to the front end to be displayed to the user. Afraid of how many calls and loading time.
This data from the third party service might be needed frequently. Would it better to setup a websocket and call from backend?
Thanks in advance