Token management, programmatically - CSFR?

Hi,

Are all APIs returning like this, or only this API? Wrong CSFR in request usually points to a reverse proxy mucking about with cookies.

 
HTH,
Ann