Typically you add it to the page you’re generating, either as a form hidden field, or inside a script element where the anti-forgery token is assigned to a variable.