csrf_failed
- HTTP status
- 403 Forbidden
- Returned by
- Every endpoint (request handling)
What it means
A browser request with a Kweko session cookie did not carry the security token. This only affects the Kweko web app, never API keys.
Typical causes
- Calling the API from a browser with a session cookie instead of an API key.
How to fix it
- Server-to-server integrations use API keys, which need no CSRF token.
Message
English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.
- Security check failed. Reload the page and try again.
RU: Проверка безопасности не пройдена. Обновите страницу и попробуйте ещё раз.
UZ: Xavfsizlik tekshiruvidan oʻtmadi. Sahifani yangilab, qayta urinib koʻring.
Example response
Response
HTTP/1.1 403 Forbidden
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55
{
"error": {
"code": "csrf_failed",
"message": "Security check failed. Reload the page and try again.",
"request_id": "req_4f2a9c1e0b7d3a55",
"docs_url": "https://developers.kweko.uz/errors/csrf_failed"
}
}