RedBeryl interview question

How to hide API keys from end user?? How to avoid SQL Injuction ??