Your client secret must never be in a page like this. Your server exchanges
the secret for a token by calling /v1/auth-token, and hands only the token to the
browser. Paste a token below to try this sample. A token lasts three minutes.
Output appears here.