v2

latestOpenAPI 3.1.0Source-specific upstream terms; see response catalog metadata2026-07-26139203447.9 KB
User

Get a live same-origin CSRF token

Returns the token for the caller's current browser session and whether it is authenticated. The response is private and never cacheable.

get/api/v1/csrf

Response

Session CSRF state

csrfstring
logged_inboolean