The short answer is no , you have to protect this server side. Everything that the client can run, they can see ... and anyone who tries to be evil can definitely find out.
Even if you hid it under 15 levels of obfuscation, ultimately the browser still makes a request to the URL, and any debugging tool can see that FireBug, Fiddler, etc.
A session-based approach, or cookies, anything, anything to authenticate / authorize a user on a server, is the best approach.
source share