The idea being that if the fake token leaks from my sandbox - it would be completely useless for an attacker