I would think the answer is “NO!!” and it seems google agrees. “Installed apps are distributed to individual devices, and it is assumed that these apps cannot keep secrets” from from google’s docs. Unfortunately, they still require the client token to do anything with. Is the assumption that even if they are exposed it will not be an issue?