I up the question because i don't really understand the protection method, of course i can assign a custom key for each method i need (create user, auth..) but its the same problem, people can decompile and have acces to each custom key.
And the READ/WRITE can be change but he need the api key so its not secured too. We can't secure our app versus decompiling ?