Answer
Token handling must prioritize security. Best practices include:
- Store tokens in memory or sessionStorage (avoid localStorage for sensitive apps).
- Use HttpOnly cookies when backend supports them.
- Add tokens only through interceptors.
- Avoid placing tokens in URLs.
- Implement token refresh + logout on refresh failure.
- Never expose secrets in frontend code.