Preventing manual backend calls with JWT auth token

You don’t

Is the short answer.

You can put code in place to stop your JS logic making multiple calls. But people can just throw open chrome inspector and throw their own calls.

A Twitch extension also self reloads/generates a new auth, once per hour, which can create another call to your backend depending on how you program your JS Logic

1 Like