API keys usually exist for preventing abuse. By exposing an authenticated API proxy you're allowing anyone to abuse someone else's API using your key, likely leading to them banning you. At a minimum you should implement your own rate limiting.
Likewise, with a JSONP proxy you're allowing other sites to circumvent the browsers' same origin policy to access that API, which could also lead to abuse. At a minimum you should restrict requests to ones with a recognized HTTP Referer header.
Of course with JSONP you also need to trust that the API isn't doing anything malicious, like injecting cookie or other data-stealing JavaScript instead of valid JSON. It would be a good idea to validate that the response is indeed JSON before passing it back to the clients (actually a properly restricted sanitizing JSONP proxy would be a good idea even if the API already provides JSONP)
So use these techniques cautiously...