I'm about to implement filepicker.io for a project and really do not mind any kind of server-side integration that would avoid chances of malicious users abusing the service against our filepicker.io or S3 usage.
Even more excited to get Filepicker implemented now!
It doesn't totally solve the problem, it just moves it; but it moves it to a less vulnerable location if you never have to get your API key into a browser where anyone can check it out by viewing source, or, in extremis, opening FireBug.
Edit: The Filepicker.io email seems to indicate a PKI-style solution, but I can only sort of guess at the implementation.
That said, it's a pretty obvious problem which is inherent in the way Filepicker is doing things right now. Simple sometimes comes at the expense of secure. I'd argue that they made a fairly reasonable trade-off for the time.
Good to see Brett and the team are responding quickly.
I don't see why anyone would have integrated without this.