---
title: "Keeping credentials out of browser JavaScript with a BFF"
description: "How can you route browser requests through a BFF without exposing tokens to JavaScript?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T02.10/"
topicId: "T02.10"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you route browser requests through a BFF without exposing tokens to JavaScript?

## What we will work through

Route browser requests through a BFF without exposing tokens to JavaScript.

## Before you begin

Previously covered: The lifecycle of a server-side session; Inside a JWT: header, payload, and signature.

- [The lifecycle of a server-side session](/en/articles/topics/T02.02/)
- [Inside a JWT: header, payload, and signature](/en/articles/topics/T03.01/)
