Is this running in a production environment yet? If so, do you have an email address to disclose a vulnerability?
An attacker will be able to identify valid keys, but won't be able to sign them.
You can either split the values like aws or join them with a separator.
Good idea with the slug though, makes it easier to report leaked tokens to the issuer.