Protected Routes is an important part of building production-ready single-spa systems. This lesson explains what protected routes means, how it works, and how to apply it with practical examples you can reuse.
Protected Routes Overview
Protected Routes lets you structure single-spa work so it stays readable, testable, and easy to scale. Instead of ad-hoc code, you follow a clear pattern that other developers can recognise immediately.
The key is to keep protected routes focused and predictable. Start from the minimal example here, then layer in only the complexity your feature actually needs.
Start from a minimal Protected Routes example and grow it only as needed.
Keep configuration explicit so Protected Routes behaves the same in every environment.
Name things clearly so teammates understand your Protected Routes at a glance.
Add tests around Protected Routes early to lock in expected behaviour.
Single-SPA Cheatsheet
Core single-spa APIs related to protected routes.
API
Example
Purpose
registerApplication
registerApplication({ name, app, activeWhen })
Register a micro frontend
activeWhen
activeWhen: ['/checkout']
Route ownership
start
start()
Begin routing
bootstrap
export async function bootstrap()
One-time setup
mount
export async function mount(props)
Render the app
unmount
export async function unmount(props)
Clean up the app
import map
systemjs-importmap
Locate app bundles
How Protected Routes Works in Single-SPA
Protected Routes is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.
activeWhen decides which route ranges a micro frontend owns.
A root config registers apps and calls start().
Each app exports bootstrap, mount, and unmount lifecycles.
activeWhen decides which routes each app owns.
Import maps resolve each app's bundle at runtime.
Practical Guidance for Protected Routes
For reliable micro frontends, protected routes should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.
Concern
Recommendation
Isolation
One app's crash should not break others
Shared state
Prefer shared utility modules over globals
Routing
Keep activeWhen rules explicit and non-overlapping
Deployment
Release via import-map updates per app
Common Mistakes
Copying protected routes snippets without understanding what each line does.
Skipping error handling and edge cases when wiring up protected routes.
Leaving protected routes untested, so regressions slip into production.
Over-engineering protected routes before you actually need the extra flexibility.
Key Takeaways
Protected Routes is a core part of working effectively with single-spa.
Start small and keep protected routes focused on a single responsibility.
Apply consistent patterns so protected routes scales across your project.
Test and document protected routes to keep it maintainable over time.
Pro Tip
When you get stuck on protected routes, reduce it to the smallest reproducible example first — most single-spa issues become obvious once the noise is gone.
You now understand protected routes in single-spa and how to apply it in real projects. Next, continue with Authorization to keep building your skills.