Yes
Just standard security stuff, treat your AppToken, just like your AppSecret, as a Password and secure it as such.