Yes. That's true - if your source code is exposed to a client.
Going back to my example of Twilio apps, usually the code that interacts with Twilio is on the server side, so you couldn't find the API keys by viewing source.
Of course, people can "cheat" and put their auth token and a capability token generator in their mobile app, but we try to discourage that use.
But I don't think its possible to solve a different way. That said, there are smart people who have thought of ways of reducing server burden in ways I never thought possible (like encrypted sessions), so it might be possible ???
How does google analytics stop rogue clients registering hits on the wrong domain? It checks the domain the incoming data is on, right? (cookies?)