Token security

After looking through the accept sample app at the Authorize.Net documentation, particularly index.php, it seems to me as if the token can be available to the user (from the browser developer tools or through viewing the source) and that's not a problem. Is that correct? Or is there something else that needs done to make the token invisible to the user, even if they open the developer tools or view the source? This is probably an obvious answer but this is my first time developing with the Authorize.Net API.