gofiber/fiber · warning
csrf: token not found
Error message
csrf: token not found
What it means
Returned by middleware/csrf when no valid CSRF token can be found for an unsafe (state-changing) request. It fires in three spots: the configured Extractor returns extractors.ErrNotFound, the extracted token is the empty string, or the token is not present in storage (raw == nil) after extraction. The middleware also expires the cookie in the storage-miss case so the client rotates.
Solutions
- Ensure the client fetches the token (cookie or TokenFromContext on a prior GET) and resubmits it via the configured channel.
- Verify the Extractor config points at the header/form field your client actually sends.
- If SingleUseToken is enabled, fetch a fresh token after each mutation.
- Check that CookieName, SameSite, Secure, and Domain let the cookie reach the browser so a token exists to submit.
Example fix
// before: client sends mutation with no token
// after: fetch token on GET, echo it back
token := csrf.TokenFromContext(c.Context())
// send token in the header configured by csrf.Extractor
req.Header.Set("X-CSRF-Token", token) Defensive patterns
Strategy: try-catch
Try / catch
if err := csrfHandler(c); err != nil {
if errors.Is(err, csrf.ErrTokenNotFound) {
return c.Status(fiber.StatusForbidden).SendString("csrf token required")
}
return err
} Prevention
- Fetch a token on a GET before any mutation.
- Keep CookieName/SameSite/Secure aligned so the cookie actually reaches the browser.
- If SingleUseToken is on, refresh the token after every successful mutation.
- Make sure the Extractor reads from a field the client populates.
When it happens
Trigger: A POST/PUT/DELETE/PATCH request with no token in the configured source (header/query/param/form), a blank token value, or a token that was never stored or has expired from storage.
Common situations: Frontend forgot to send the CSRF token header; the cookie holding the token expired or was blocked by SameSite/Secure settings; the token was consumed by SingleUseToken=true on a prior request; misconfigured Extractor reading from the wrong field.
Related errors
- csrf: failed to delete token from storage
- csrf: failed to fetch token from storage
- csrf: failed to store token in storage
- csrf: token invalid
- CSRF: Chained extractor reads from the same cookie
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/7785a79e7c20f8de.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/csrf/csrf.go:24
"net/url"
"slices"
"strings"
"sync"
"time"
"github.com/gofiber/utils/v2"
utilsstrings "github.com/gofiber/utils/v2/strings"
"github.com/gofiber/fiber/v3"
"github.com/gofiber/fiber/v3/extractors"
"github.com/gofiber/fiber/v3/internal/headerlookup"
"github.com/gofiber/fiber/v3/internal/redact"
"github.com/gofiber/fiber/v3/internal/schemehost"
"github.com/gofiber/fiber/v3/middleware/logger"
)
var (
ErrTokenNotFound = errors.New("csrf: token not found")
ErrTokenInvalid = errors.New("csrf: token invalid")
ErrFetchSiteInvalid = errors.New("csrf: sec-fetch-site header invalid")
ErrRefererNotFound = errors.New("csrf: referer header missing")
ErrRefererInvalid = errors.New("csrf: referer header invalid")
ErrRefererNoMatch = errors.New("csrf: referer does not match host or trusted origins")
ErrOriginInvalid = errors.New("csrf: origin header invalid")
ErrOriginNoMatch = errors.New("csrf: origin does not match host or trusted origins")
errOriginNotFound = errors.New("origin not supplied or is null") // internal error, will not be returned to the user
dummyValue = []byte{'+'} // dummyValue is a placeholder value stored in token storage. The actual token validation relies on the key, not this value.
)
var registerLogContextTagsOnce sync.Once
// Handler for CSRF middleware
type Handler struct {
sessionManager *sessionManager
storageManager *storageManagerView on GitHub (pinned to a105acad6c)