There is an env.js file in the root that contains access tokens. We should remove these. I'd suggest switching to using the `dotenv` package