Every-time I need to use them, I utilize the https.createSecureString in combination with setting the 'credentials' parameter on the https.get. BOOM! Therefore, the clientid/secret are NEVER exposed. Further, I can ensure they are only used with my scripts and only against the correct domain