# Invalid CSRF token at install

**URL:** <https://forum.mautic.org/t/invalid-csrf-token-at-install/2580>\
**Category:** Product Support\
**Created:** [October 13, 2015, 2:33pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580 "2015-10-13T14:33:03Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![adambeazley](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/adambeazley/32/494_2.png) [@adambeazley](https://forum.mautic.org/u/adambeazley)\
**Post date:** [October 13, 2015, 2:33pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/1 "2015-10-13T14:33:03Z")

</div>

When attempting to install Mautic I get the following error under Mautic Installation - Environment Check and i cannot get to the next step:  
  
The CSRF token is invalid. Please try to resubmit the form.  
  
  
  
When I check the server error log I get the following errors:  
  
20151013T112408: [www.website.com/mautic/index.php/s/ajax](http://www.website.com/mautic/index.php/s/ajax)  
  
PHP Warning: SessionHandler::read(): open(/var/php\_sessions/sess\_33028e14f2dab7e77692cf5e00c8f707, O\_RDWR) failed: No such file or directory (2) in /path/to/mautic/app/cache/prod/classes.php on line 411  
  
PHP Warning: SessionHandler::write(): open(/var/php\_sessions/sess\_33028e14f2dab7e77692cf5e00c8f707, O\_RDWR) failed: No such file or directory (2) in /path/to/mautic/app/cache/prod/classes.php on line 415  
  
  
  
any ideas on how to fix this?

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [October 15, 2015, 6:03am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/2 "2015-10-15T06:03:50Z")

</div>

So it works for 1.1.3? That’s a good lead. Now we have to figure out what has changed in 1.2.0 that could cause it.

---

<div class="post-metadata">

**Author:** ![adambeazley](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/adambeazley/32/494_2.png) [@adambeazley](https://forum.mautic.org/u/adambeazley)\
**Post date:** [October 13, 2015, 2:33pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/3 "2015-10-13T14:33:03Z")

</div>

When attempting to install Mautic I get the following error under Mautic Installation - Environment Check and i cannot get to the next step:  
The CSRF token is invalid. Please try to resubmit the form.

When I check the server error log I get the following errors:  
20151013T112408: [www.website.com/mautic/index.php/s/ajax](http://www.website.com/mautic/index.php/s/ajax)  
PHP Warning: SessionHandler::read(): open(/var/php\_sessions/sess\_33028e14f2dab7e77692cf5e00c8f707, O\_RDWR) failed: No such file or directory (2) in /path/to/mautic/app/cache/prod/classes.php on line 411  
PHP Warning: SessionHandler::write(): open(/var/php\_sessions/sess\_33028e14f2dab7e77692cf5e00c8f707, O\_RDWR) failed: No such file or directory (2) in /path/to/mautic/app/cache/prod/classes.php on line 415

any ideas on how to fix this?

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [October 14, 2015, 9:22am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/4 "2015-10-14T09:22:36Z")

</div>

Seems to me that PHP doesn’t have permission to read the session. Check that with your server provider.

---

<div class="post-metadata">

**Author:** ![adambeazley](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/adambeazley/32/494_2.png) [@adambeazley](https://forum.mautic.org/u/adambeazley)\
**Post date:** [October 14, 2015, 6:14pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/5 "2015-10-14T18:14:31Z")

</div>

Well I finally just installed an older version 1.1.3, because I, nor the hosting support guy could figure out what the issue was.

---

<div class="post-metadata">

**Author:** ![gerald-k](https://avatars.discourse-cdn.com/v4/letter/g/ed8c4c/32.png) [@gerald-k](https://forum.mautic.org/u/gerald-k)\
**Post date:** [October 30, 2015, 9:19am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/6 "2015-10-30T09:19:53Z")

</div>

Hi, still the same problem with 1.2.2 any solution in the pipline?

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [October 30, 2015, 10:11am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/7 "2015-10-30T10:11:43Z")

</div>

Sadly, no. We don’t know what is causing it. It happens only in a couple of community members servers and we (developers) are not able to replicate it on our servers.

---

<div class="post-metadata">

**Author:** ![neronline](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/neronline/32/1497_2.png) [@neronline](https://forum.mautic.org/u/neronline)\
**Post date:** [November 3, 2015, 8:38pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/8 "2015-11-03T20:38:45Z")

</div>

Work Around: Commenting out the session cookie domain has allowed me to install v1.1.3. Any idea why this is not valid for Mautic? ; session.cookie\_domain = \*.neronlineenterprises.com

I’m also getting this “The CSRF token is invalid. Please try to resubmit the form.” error trying to install the latest version 1.2.2. Other applications like WordPress, SPIP installed on this domain are working fine so PHP session settings don’t seem to be the issue.

There wasn’t anything in my error logs when trying to install the previous version.

Now I find this:  
[03-Nov-2015 05:23:20 UTC] PHP Fatal error: Class ‘MauticAssetBundleEventListenerFormSubscriber’ not found in xxx/public\_html/mautic/app/cache/prod/classes.php on line 2250

I deleted the cache folder and installed again. No joy.

I added the security\_local.php and commented out csrf. No joy.  
‘main’ =\> array(  
‘pattern’ =\> “^/s/”,  
‘form\_login’ =\> array(  
// ‘csrf\_provider’ =\> ‘form.csrf\_provider’,  
‘success\_handler’ =\> ‘mautic.security.authentication\_handler’,  
‘failure\_handler’ =\> ‘mautic.security.authentication\_handler’,  
‘login\_path’ =\> ‘/s/login’,  
‘check\_path’ =\> ‘/s/login\_check’  
),

I installed 1.1.3 and get the same CSRF error.

FYI: PHP Version 5.5.30

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [November 4, 2015, 9:08am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/9 "2015-11-04T09:08:04Z")

</div>

@neronline the error says that a class is missing. Could you check your Mautic has this file?:

```auto
app/bundles/AssetBundle/EventListener/FormSubscriber.php
```

If not, make sure all the files were uploaded. I’d do it by removing all files you’ve uploaded and upload Mautic files freshly downloaded from [https://www.mautic.org/download/](https://www.mautic.org/download/) and unzipped.

---

<div class="post-metadata">

**Author:** ![jfgrissom](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@jfgrissom](https://forum.mautic.org/u/jfgrissom)\
**Post date:** [April 11, 2016, 12:00am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/10 "2016-04-11T00:00:58Z")

</div>

Hi,

Just wanted to say thanks for this. I was seeing this same “The CSRF token is invalid. Please try to resubmit the form.” error during the install.

Telling php to use a directory where it had permission did the trick for me.

Hopefully this is helpful to someone else:  
I have nginx/php-fpm running mautic and pointing php sessions to a location that nginx had rw access too.

Here is what I did to get it working for me.

```auto
# Centos 7
# /etc/php-fpm.d/www.conf
[www]
listen = /var/run/php5-fpm.sock
listen.owner = nginx
listen.group = web
listen.allowed_clients = 127.0.0.1
user = nginx
group = web
pm = dynamic
pm.max_children = 50
pm.start_servers = 5
pm.min_spare_servers = 5
pm.max_spare_servers = 35
slowlog = /var/log/php-fpm/www-slow.log
php_admin_value[error_log] = /var/log/php-fpm/www-error.log
php_admin_flag[log_errors] = on
php_value[session.save_handler] = files
php_value[session.save_path] = /var/www/<non-public-directory>/sessions
```

```auto
# Centos 7
chown -R nginx:web /var/www/<non-public-directory>/sessions
systemctl restart php-fpm
```

---

<div class="post-metadata">

**Author:** ![rafael.aca](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/rafael.aca/32/56_2.png) [@rafael.aca](https://forum.mautic.org/u/rafael.aca)\
**Post date:** [May 6, 2016, 12:59pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/11 "2016-05-06T12:59:01Z")

</div>

Solved!

Based on what jfgrissom said I changed my php.ini file, so I could change the session folder and give it write permission.

I’m not a PHP nor a Linux specialist but I could overpass this error.

I don’t know what will be the side effect of what I did. Hope you specialists warn me if it’s somewhat critical.

Here the steps:

- I created a new folder on my host environment called phpsessions
- Set the writeble permissions
- Changed the php.ini file:

;session.save\_path = “/var/lib/php-cgi/session”  
session.save\_path = “/home/storage/7/9c/c2/mylogin/phpsessions”

Hope it helps…

---

<div class="post-metadata">

**Author:** ![davidneedham](https://avatars.discourse-cdn.com/v4/letter/d/5fc32e/32.png) [@davidneedham](https://forum.mautic.org/u/davidneedham)\
**Post date:** [June 2, 2016, 11:52am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/12 "2016-06-02T11:52:25Z")

</div>

I wasn’t seeing this error at install, but instead the first time I was logging in after install.

I followed the directions from rafael.aca to get it working (on shared hosting, no less), but I created the phpsessions directory at home instead.

Thank you!

---

<div class="post-metadata">

**Author:** ![Plarcher](https://avatars.discourse-cdn.com/v4/letter/p/7bcc69/32.png) [@Plarcher](https://forum.mautic.org/u/Plarcher)\
**Post date:** [July 1, 2016, 10:45am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/13 "2016-07-01T10:45:32Z")

</div>

> [@4392:@escopecz](#):
>
> Sadly, no. We don’t know what is causing it. It happens only in a couple of community members servers and we (developers) are not able to replicate it on our servers.

I will proudly provide one occurence in cloud Mautic ! (please help 😉 )

---

<div class="post-metadata">

**Author:** ![ian](https://avatars.discourse-cdn.com/v4/letter/i/bb73d2/32.png) [@ian](https://forum.mautic.org/u/ian)\
**Post date:** [March 26, 2016, 4:16am UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/14 "2016-03-26T04:16:55Z")

</div>

Hi @escopecz , I was able to replicate this issue from a fresh install of Mautic 1.3.1.

“The CSRF token is invalid. Please try to resubmit the form.”

I tried to install Mautic on FortRabbit. And I get this error after clicking on the Next Step button of the very first page.

If it helps, I can give you access to the FortRabbit account which I specifically created for testing Mautic.

Thanks!  
Ian

---

<div class="post-metadata">

**Author:** ![Svet\_Zitrka](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@Svet\_Zitrka](https://forum.mautic.org/u/Svet_Zitrka)\
**Post date:** [February 27, 2016, 12:53pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/15 "2016-02-27T12:53:51Z")

</div>

Hello,  
We have the same problem, glad to help with the solution.

We updated PHP PHP 5.6.17 and uploaded PDO ovladaře, otherwise Mautic nspustil. Now it all goes only in the logo pops up this error, but the function of Mauticu seems that it has no significant effect.

`[02/27/2016 12:33:44] mautic.WARNING: PHP Warning: SessionHandler :: write (): open (/ var / lib / php5 / sessions / sess_v5p6745802pilu7sprn3bkvp71, O_RDWR) failed: No such file or directory (2 ) - in file /xxx/mtc/app/cache/prod/classes.php - at line 415 [] []
[02/27/2016 12:33:44] mautic.WARNING: PHP Warning: SessionHandler :: read (): open (/ var / lib / php5 / sessions / sess_s8cv418psqbol5ug2r678fu382, O_RDWR) failed: No such file or directory (2 ) - in file /xxx/subdomains/mtc/app/cache/prod/classes.php - at line 411 [] []`

`app / Bundles / AssetBundle / EventListener / FormSubscriber.php` I checked and it is present.

I help in finding errors in some other way?

---

<div class="post-metadata">

**Author:** ![artaxerxes99](https://avatars.discourse-cdn.com/v4/letter/a/ea666f/32.png) [@artaxerxes99](https://forum.mautic.org/u/artaxerxes99)\
**Post date:** [May 29, 2017, 2:20pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/16 "2017-05-29T14:20:07Z")

</div>

We had the same problem when using Safari, but switching to Chrome or Firefox when accessing Mautic resolved the problem. (This could be due to cookies present in Safari as other users reported that clearing cookies resolved the problem temporarily at least.)

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 2, 2020, 10:57pm UTC](https://forum.mautic.org/t/invalid-csrf-token-at-install/2580/17 "2020-02-02T22:57:24Z")

</div>


