invalid csrf token 🔐 Authentication

ForbiddenError: invalid csrf token (EBADCSRFTOKEN)

The request’s CSRF token is missing or doesn’t match the token tied to the user’s session/cookie.

Seen on: REST API

Meaning

Forms and AJAX must include the token; it’s bound to the session/secret cookie. Cached pages, cookies not sent (cross-site/SameSite), session store resets and missing headers cause mismatches.

Common causes

  • Token not included in form/AJAX header
  • Session or secret cookie lost (restart with memory store, SameSite)
  • Page cached with an old token
  • Multiple tabs/old forms

⚡ Quick fix

  1. Include the token (hidden input or X-CSRF-Token header)
  2. Use a persistent session store; send cookies with credentials
  3. Don’t cache pages containing tokens

Detailed fix by platform

JavaScript

  1. fetch("/api/profile", { method: "POST", credentials: "same-origin", headers: { "Content-Type": "application/json", "X-CSRF-Token": csrfToken }, body: JSON.stringify(data) });

How to diagnose

  1. Request — Token present?
  2. Cookie — Session/secret cookie sent?
  3. Cache — Page cached?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.