@matigo What's wrong with having the client ID in the binary, as long as it isn't the only factor being used for service authentication (the client_credentials grant type in OAuth 2 terms)? This happens all the time especially with client-side JS apps. I'll have to take a deeper look in to the docs.
// @height8