Confusion about API Authenticated User

You should never use that API from a frontend because in that case this indeed is a risk (actually the risk is much higher because the hacker can do anything)

You should do this from the backend.

If that is not an option then you should use User API keys instead.