Is it okay to have auth0 client information accessible over a public API?