There are issues with keys. Hopefully Thor or Chris or Enoch or Luke
will chime in at some point.
However, you can't hide the key in the source: the browser needs it to
add to the GET request for the API. You *may* be able to use something
like tinyurl to reduce the entire url to something a little more
covert; but (a) the redirection involved may break it; (b) it's hardly
secure.