Is using NEXT_PUBLIC secrets acceptable for server SDK auth?