You can configure the proxy for your front-end. which also allows you to use same-site Lax. although API call is proxied from your front-end but it makes safe.