Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Next.js can provide a Backend for Frontend (BFF): a server-side API layer that receives requests from your UI, applies access and data rules, and calls other services. Use App Router Route Handlers for custom HTTP endpoints, Server Actions mainly for UI-triggered mutations, and Proxy or rewrites for suitable routing. In an existing Pages Router app, use API Routes. This pattern complements backend services; Next.js documentation cautions that its backend capabilities are not a full backend replacement.

What does a Next.js BFF do?

A BFF sits between a frontend and the systems that provide its data or perform its work. It can aggregate or transform responses, keep service credentials on the server, and expose a frontend-oriented API without putting internal service URLs and secrets in browser code. The exact boundary depends on the application: a BFF can call existing APIs or data sources, but it does not automatically replace their durable business logic, data storage, or operational responsibilities.

Think of every server-side entry point as a boundary that must enforce its own rules. Code running on the server is not necessarily private: a Route Handler is a public HTTP endpoint, and a Server Action can be invoked from a client.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Next.js feature should you use?

Need Use Key consideration
Custom HTTP endpoint, response, aggregation, or transformation App Router Route Handler It is a public API surface and needs input checks and access controls.
Route requests to another backend Proxy or rewrites; use a Route Handler when validation or response logic is needed Keep a deliberate boundary for forwarded headers and validate requests where appropriate.
Mutation triggered by a frontend interaction Server Action Authorize each action; built-in protections do not replace permission checks.
API endpoint in an existing Pages Router app API Route App Router projects use Route Handlers instead.
Data for a server-rendered page Call the data source directly from the Server Component A self-request to your own Route Handler adds an HTTP hop and can fail during build-time prerendering.

How to create an App Router Route Handler

Create a route.ts or route.js file in the App Router at the URL path where the endpoint should live. Export functions named for the HTTP methods the endpoint supports. Next.js supports GET, POST, PUT, PATCH, DELETE, HEAD, and OPTIONS.

app/api/profile/route.ts

For example, a handler that updates a profile should parse and validate the request, identify the caller, check that caller’s permission to change the requested profile, and return only information that caller may access. The endpoint remains callable outside the visible UI, so hiding a button or relying on a prior navigation check is not an access-control strategy.

When Server Actions fit—and when they do not

Server Actions are useful for mutations initiated by UI interactions, such as submitting a form. Treat each exported action as an externally triggerable operation: authenticate the caller, authorize the specific change, validate input, and avoid returning data the caller should not see.

They are not a general-purpose shortcut for fetching data. The BFF guide notes that Server Actions are queued, so using them for data fetching can make requests run sequentially. For page data, call the underlying source directly from the Server Component. A build-time prerender has no running application server available for a self-request to a Route Handler; during on-demand rendering, that self-request adds a redundant HTTP round trip.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure every request boundary

A BFF can protect internal details only if it enforces the boundary consistently. Validate request type, size, and values; authenticate callers and authorize each sensitive operation; and return only the fields each caller is permitted to receive. Avoid exposing sensitive error details to clients, and remove unnecessary sensitive data from responses and logs. Rate limits and timeouts can help constrain abuse and unbounded work.

  • Do not treat Proxy as authorization. A Proxy check may help route or filter traffic, but the operation that reads or changes protected data must still check permissions.
  • Keep secrets out of client bundles. The Next.js data security guide warns that environment variables prefixed with NEXT_PUBLIC_ are exposed to the client. Keep credentials in server-only configuration.
  • Use Server Action protections as defense in depth. Next.js documents non-deterministic action IDs and Origin-to-Host checks. These do not establish who the caller is or whether they may perform an operation. Do not rely on encryption alone to protect values captured by closures.
  • Set a deliberate payload limit. The Server Actions reference, last updated February 27, 2026, gives a default maximum request body size of 1 MB. It can be configured; raising it increases resource consumption, so set it to match expected payloads rather than treating a higher limit as harmless.

If requests pass through a reverse proxy or multiple backend layers, review Server Actions’ origin configuration. Do not broaden allowed origins casually: configure only the origins your deployment requires.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choose deployment based on runtime requirements

The framework label alone does not determine whether a BFF will work in production. The Next.js deployment guide says Node.js server and Docker deployments support all Next.js features; static export has limitations, and adapter support varies. Check the specific deployment target against the features your handlers need.

Some hosts execute handlers as lambdas. In that model, requests may not share process state; filesystem writes may be unavailable; long-running work may hit timeouts; and WebSockets may not work. Confirm the chosen host’s limits before designing a handler around persistent memory, local disk, long tasks, or open connections. Use an external store or a different service when the feature depends on capabilities the host does not provide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Official Next.js documentation

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.