After researching CSRF tokens and django, it's clear that the React app has to be rendered via django in order to retrieve the CSRF token normally (i.e. injected into the DOM)
The only reason I take issue with this I know instagram is using Django and React for their web app; I find it highly unlikely it's being rendered -- at least in a traditional way -- by django.
I realize it will be difficult to find an answer to how they are handling it, but perhaps someone knows a way of doing this without rendering a very large enterprise-level react app with django.
To give some perspective, our react application is in a separate repo & directory on a different subdomain to our django powered API.
We've looked for advice in every area I can think of and have yet to find a proper solution, so I appreciate any feedback you can give