# CSRF token error. Try to refresh the page and try again

**URL:** <https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839>\
**Category:** Product Support\
**Created:** [November 3, 2020, 10:42am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839 "2020-11-03T10:42:06Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [November 3, 2020, 10:42am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/1 "2020-11-03T10:42:06Z")

</div>

**Your software**  
My Mautic version is: 2.16x + 3.x  
My PHP version is: 7.2 & 7.3  
My Database type and version is: MariaDB

**Your problem**  
My problem is:

I have very similar installations of mautic for a number of instances and on some of them I continually get the token refresh error.

There has to be an easy fix to this that I am not aware of.

I am running NginX server on Ubuntu 18.04 & 20

So looking for someone to point me in the direction I cannot see.

These errors are showing in the log:

Steps I have tried to fix the problem:

---

<div class="post-metadata">

**Author:** ![codes9](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/codes9/32/682_2.png) [@codes9](https://forum.mautic.org/u/codes9)\
**Post date:** [November 3, 2020, 6:31pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/2 "2020-11-03T18:31:08Z")

</div>

Hi Mikew,

I’ve seen these after the session has timed out. In my browser I get this until I refresh the page and then login.

Have you tried clearing your browser’s Cache? Or moving to another Browser?

Anything showing up in the logs?

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [November 3, 2020, 7:07pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/3 "2020-11-03T19:07:02Z")

</div>

Logs don’t show anything. I have used it in different browsers, not sure if it is a web server setting or something inside Mautic. But certain instances I can be in forever and certain after a minute I get this, sometimes even 3 times in a row.

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [December 15, 2020, 6:43pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/4 "2020-12-15T18:43:00Z")

</div>

Hi fellow Mautic Guru’s - does anyone know how to fix this issue - is it a Mautic thing or a server thing ?

@joeyk ? @ekke ?

Would really appreciate some assistance here

---

<div class="post-metadata">

**Author:** ![ericf](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ericf/32/1669_2.png) [@ericf](https://forum.mautic.org/u/ericf)\
**Post date:** [February 18, 2021, 8:08am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/5 "2021-02-18T08:08:34Z")

</div>

It seems to have disappeared with the latest version 😉

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [February 18, 2021, 8:08pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/6 "2021-02-18T20:08:09Z")

</div>

Man I missed this sorry. Not like I know the answer…

---

<div class="post-metadata">

**Author:** ![markerb](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/markerb/32/4668_2.png) [@markerb](https://forum.mautic.org/u/markerb)\
**Post date:** [March 9, 2021, 12:42pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/7 "2021-03-09T12:42:52Z")

</div>

I have the same problem here, on v3.3.1. It seems to happen when I am in the configuration section, which leads me to believe it’s because of the way that section uses a page-within-a-page, via AJAX or an iframe. I might be re-logging in to the sub-page that had been loaded with AJAX/iframe, but the parent page still has my older login token.

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [December 16, 2021, 8:44am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/8 "2021-12-16T08:44:26Z")

</div>

Is there any solution here. It is such a hard thing to deal with when dealing with clients what this is all about:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/a/aa9411ed779691f1e535250690f1dc61f45b968e.png)

---

<div class="post-metadata">

**Author:** ![robm](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/robm/32/260_2.png) [@robm](https://forum.mautic.org/u/robm)\
**Post date:** [December 16, 2021, 10:49am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/9 "2021-12-16T10:49:11Z")

</div>

Second this, it has haunted my for years with multiple Mautics, different browsers, diff local machines, diff server set ups but the CSRF token issue just follows me around.

---

<div class="post-metadata">

**Author:** ![markerb](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/markerb/32/4668_2.png) [@markerb](https://forum.mautic.org/u/markerb)\
**Post date:** [December 16, 2021, 11:38am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/10 "2021-12-16T11:38:19Z")

</div>

I have a workaround that’s effectively fixed this bug in my 3.3.1 installation from March 2021. I don’t see any reason it wouldn’t work in v4.

The hack keeps the Mautic login fresh by using AJAX to fetch a Mautic page every 9 minutes, just short of the 10 minute timeout that plagues many users.

I documented my solution here: [https://github.com/mautic/mautic/issues/9804#issuecomment-806422002](https://github.com/mautic/mautic/issues/9804#issuecomment-806422002)

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [December 16, 2021, 12:18pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/11 "2021-12-16T12:18:00Z")

</div>

I applied another workaround but not sure how good it is, but it works well.  
change php.ini from

session.gc\_maxlifetime = 1440  
to  
session.gc\_maxlifetime = 14400

Whoa, 10x longer cookie lifetime.  
(restart apache of course)

---

<div class="post-metadata">

**Author:** ![markerb](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/markerb/32/4668_2.png) [@markerb](https://forum.mautic.org/u/markerb)\
**Post date:** [December 16, 2021, 1:06pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/12 "2021-12-16T13:06:58Z")

</div>

If your sessions are already working correctly, changing the session timeout like this can be useful. However, this won’t fix the problem many installations are having with being logged-out after only 10 minutes of inactivity. Please view the entire topic about this bug at [https://github.com/mautic/mautic/issues/9804](https://github.com/mautic/mautic/issues/9804)

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [December 16, 2021, 1:32pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/13 "2021-12-16T13:32:26Z")

</div>

Hmm… okay, so I guess my sessions were working fine, but I was logged out after 1440 seconds, as that was the max allowed by php?

Previously there was a REMEMBERME cookie placed by Mautic, and that is gone now. Is that a bug, or ‘remember me’ function has been changed?

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [January 19, 2022, 6:32pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/14 "2022-01-19T18:32:26Z")

</div>

Sometimes I login to Mautic and immediately I am greeted with about 20 messages going down the side of this.

I just cannot believe that I am the only one feeling this pain and that there is no fix yet.

---

<div class="post-metadata">

**Author:** ![joeyk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/joeyk/32/11164_2.png) [@joeyk](https://forum.mautic.org/u/joeyk)\
**Post date:** [January 19, 2022, 6:57pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/15 "2022-01-19T18:57:23Z")

</div>

I think many of is learned to live with the pain and forgot what a pain free life is.

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [January 19, 2022, 7:11pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/16 "2022-01-19T19:11:59Z")

</div>

I am trying out @markerb solution as posted in GitHub… going to monitor it and hopefully this will fix the issue.

will keep you updated.

---

<div class="post-metadata">

**Author:** ![markerb](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/markerb/32/4668_2.png) [@markerb](https://forum.mautic.org/u/markerb)\
**Post date:** [January 20, 2022, 4:03am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/17 "2022-01-20T04:03:33Z")

</div>

I don’t think my code will fix your problem if you are being logged out immediately after logging in. My hack workaround is for users who are logged out after 10 minutes of inactivity. Your issue sounds like something else, more akin to the entire login session being instantly discarded. I’m not entirely clear how Mautic sessions are maintained, but you might check that both the server’s and browser’s time of day are correct.

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [January 20, 2022, 7:18am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/18 "2022-01-20T07:18:58Z")

</div>

It actually kept me logged in, and even while I left an editor window open on email.

However this morning I came back - was logged out and I get all these messages when login in.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/7/7f357ac6c43d824a813b14854cd13575ee83fd2d.png)

I mean surely there must be something to do about this.

There are no errors in the console, but there are warnings and info…

---

<div class="post-metadata">

**Author:** ![markerb](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/markerb/32/4668_2.png) [@markerb](https://forum.mautic.org/u/markerb)\
**Post date:** [January 20, 2022, 11:24am UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/19 "2022-01-20T11:24:23Z")

</div>

You aren’t providing enough information for someone to debug this. What about network failures? What about cookies? Have you used your browser’s development console to monitor those things? Sometimes cookies get thrown out or blocked. My workaround won’t work if the network connection is sporadic.

Again, I am not knowledgeable about Mautic’s use of cookies and CSRF tokens. Even if you provide more information, someone else would probably need to get involved.

---

<div class="post-metadata">

**Author:** ![mikew](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mikew/32/5156_2.png) [@mikew](https://forum.mautic.org/u/mikew)\
**Post date:** [January 20, 2022, 12:55pm UTC](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839/20 "2022-01-20T12:55:28Z")

</div>

Hey @markerb - thanks for your response. Yeah I know I am not providing enough info here, I can provide whatever is needed, I just do not know what is required, and from the reponse on the forum, , there does not seem to be too many people that know what is required… I understand you are not the correct person here either… anyway as @joeyk says “maybe we just have to learn to live with this”…

Appreciate your help so far and especially the code you wrote as this is helping with other instances I have

[Next page](https://forum.mautic.org/t/csrf-token-error-try-to-refresh-the-page-and-try-again/16839.md?page=2)
