Error reference

csrf_failed

HTTP status
403 Forbidden
Returned by
Every endpoint (request handling)

What it means

A browser request with a Kweko session cookie did not carry the security token. This only affects the Kweko web app, never API keys.

Typical causes

  • Calling the API from a browser with a session cookie instead of an API key.

How to fix it

  • Server-to-server integrations use API keys, which need no CSRF token.

Message

English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.

  • Security check failed. Reload the page and try again.
    RU: Проверка безопасности не пройдена. Обновите страницу и попробуйте ещё раз.
    UZ: Xavfsizlik tekshiruvidan oʻtmadi. Sahifani yangilab, qayta urinib koʻring.

Example response

Response
HTTP/1.1 403 Forbidden
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55

{
  "error": {
    "code": "csrf_failed",
    "message": "Security check failed. Reload the page and try again.",
    "request_id": "req_4f2a9c1e0b7d3a55",
    "docs_url": "https://developers.kweko.uz/errors/csrf_failed"
  }
}

All error codes · The error format