Okay...
1. Again, you could just input the key one time in a session and passing it through post ( with SSL )to a session variable.
Which implies that somewhere, that secret key is near your workstation. Either on disk, USB, on a piece of paper or in your head,
2. The thing is not to...