Admin credentials and verification are exchanged only through server route handlers. Tokens are held in secure HttpOnly cookies.