API calls from front

I installed Bold applications to enable subscriptions system for customers.

Unfortunately, some functionalities are missing, so we decided to develop an extern app witch will use Bold API. Until here, we are ok. But, the main point is, how can we call external API from front in a secure way ?

We do not want to expose token or password in front. We do not want to set variable in Shopify neither because files will be committed and token will be exposed to..

Do you have any idea how we can process those calls from front ?