Option A 1. My user creates an secure (with API keys or some other method) API endpoint to provide the Client secrets when I need them.
2. When my app needs to access the client secrets, I maker an API call to the users endpoint to get the Client Secret.
Option B 1. 1. When user signs up, generate an encryption key and ask the user to save it securely. (With the warning that in case this key is lost, the user would have to configure the Client Secrets again)
2. Whenever the user makes an API call (over HTTPS ofc) that involves reading/writing sensitive data, require him to provide the encryption key as well.
Which one is better?