currently its just direct GET rules.
that way, we can add sensitive API keys when fetching it. but that's also loggable from TM like via sentry. is there a safe way to make calls that doesn't involve yall (owners) storing/logging our API keys etc like network requests?