Sorry for the delayed response here, but wanted to be sure and get back to you - The following topic does a great job outlining the steps needed to instantiate the management client:
event.secrets.REDIRECT_SECRET is just a random string that you create - Check out options.secret of api.redirect.encodeToken(options)here.