Right now, all data is fetched from Python directly, and then the data moves from Python to JS. This means that JS doesn't need any security credentials to know how to fetch the data. This may change in the future with tile layers that fetch data directly from JS