Signed OAuth user identifier authentication

I’m not sure I follow your logic here, how and why would an OpenAI employee have your secret key? Would they also be working with Google? Help me to understand what your concern is.