# CSRF token InvalidAuthenticityToken

**URL:** <https://discuss.hotwired.dev/t/csrf-token-invalidauthenticitytoken/91>\
**Category:** General\
**Created:** [February 15, 2018, 5:01am UTC](https://discuss.hotwired.dev/t/csrf-token-invalidauthenticitytoken/91 "2018-02-15T05:01:44Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![javan](https://yyz1.discourse-cdn.com/flex027/user_avatar/discuss.hotwired.dev/javan/32/594_2.png) [@javan](https://discuss.hotwired.dev/u/javan)\
**Post date:** [February 15, 2018, 1:44pm UTC](https://discuss.hotwired.dev/t/csrf-token-invalidauthenticitytoken/91/3 "2018-02-15T13:44:01Z")

</div>

You can query your `<meta name="csrf-token">` element for the token and include it in the request’s headers:

```auto
fetch(…, {
  method: "PUT",
  credentials: "same-origin",
  headers: {
    "X-CSRF-Token": getMetaValue("csrf-token")
  },
  …
})

function getMetaValue(name) {
  const element = document.head.querySelector(`meta[name="${name}"]`)
  return element.getAttribute("content")
}

```

---

_[View the full topic](https://discuss.hotwired.dev/t/csrf-token-invalidauthenticitytoken/91)._
