Skip to content

Controller

authenticityToken()

authenticityToken() — returns string

Available in: controller Category: Miscellaneous Functions

Returns the raw CSRF authenticity token

// 1. Embed the CSRF token in a manually-built form hidden field
token = authenticityToken();
writeOutput('<input type="hidden" name="authenticityToken" value="' & token & '">');

// 2. Pass the token as a request header for an AJAX call (e.g. in a JavaScript data island)
writeOutput('<meta name="csrf-token" content="' & authenticityToken() & '">');
// JavaScript can then read this and send it as the X-CSRF-Token header with each POST request.

// 3. Include the token in a JSON API response body so a client can replay it
tokenValue = authenticityToken();
writeOutput(serializeJSON({authenticityToken = tokenValue}));