Another thing we (Twilio employee here) do, for our Client product, which runs on iOS and Android, we use a different form of authentication: we require a server-side component to generate a "capability token" which is signed by your main auth token. The capability token is limited in what it can do, and expires after a configurable amount of time, so if an attacker gets hold of one, the damage they can do is limited.
Of course, people can "cheat" and put their auth token and a capability token generator in their mobile app, but we try to discourage that use.