Should the Auth token and/or client ID be secret?

oops!
So I would have to bring users to that webpage instead of using a GET request?
Or is there another way?