google cloud platform – Security of keys while keeping my code clean

I’m using a Google Cloud function to call a 3rd party API in my application. The API key/secret will depend on the user in my application.

I would like to send a request from the cloud function to my application using a Bearer token and unique identifier to grab the key and secret on my side before sending it to the cloud function where the API request is made. If either of these are incorrect, an error will be thrown. If the call from Google Cloud to my app is made over https, is this a secure method of retrieving the key and secret?

Alternatively, I can just use environment variables within my cloud function, but I’d prefer to keep that function as clean as possible.

Read more here: Source link