ForbiddenError: invalid csrf token (EBADCSRFTOKEN)
The request’s CSRF token is missing or doesn’t match the token tied to the user’s session/cookie.
Seen on:
REST API
Meaning
Forms and AJAX must include the token; it’s bound to the session/secret cookie. Cached pages, cookies not sent (cross-site/SameSite), session store resets and missing headers cause mismatches.
Common causes
- Token not included in form/AJAX header
- Session or secret cookie lost (restart with memory store, SameSite)
- Page cached with an old token
- Multiple tabs/old forms
⚡ Quick fix
- Include the token (hidden input or X-CSRF-Token header)
- Use a persistent session store; send cookies with credentials
- Don’t cache pages containing tokens
Detailed fix by platform
JavaScript
fetch("/api/profile", { method: "POST", credentials: "same-origin", headers: { "Content-Type": "application/json", "X-CSRF-Token": csrfToken }, body: JSON.stringify(data) });
How to diagnose
- Request — Token present?
- Cookie — Session/secret cookie sent?
- Cache — Page cached?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 0x800704EC 0x800704EC: This program is blocked by group policy (Windows Defender)
- 1005 Cloudflare Error 1005: Access denied — The owner of this website has banned the autonomous system number (ASN) your IP address is in
- 1006 Cloudflare Error 1006 / 1007 / 1008: Access denied — Your IP address has been banned
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026