If we have any thought of making this open source we should remove all traces of the old API keys and tokens (As they will live permanently in the Git History). Once we change the keys we can PGP encrypt them so they can remain in the repo. We just need to include the PGP key in the on-boarding docs (which will somewhere private on google docs).