Is it possible to create a secure (not easily hackable/reverse engineered) server request token from javascript code (visible to anyone) which can be validated at the server side.
To understand the question better here is the scenario depicted as an diagram: