Shipped an API key inside a bundle and found out when the provider emailed me about usage from an address I did not recognise. The audit in the third comment is not theoretical.
The thing worth internalising: anything the app can read, someone with the app can read. There is no client-side hiding place, only obscurity, and obscurity is a delay rather than a defence.