Comment by nijave
Even then you can MITM if you have elevated access to the platform and can tinker with the certificate store.
Games like Pokemon Go use a highly obfuscated algorithm to sign requests which makes it much harder to actually use the key if you can retrieve it