Loading
Salesforce now sends email only from verified domains. Read More

Non-MFA enabled end user unable to obtain a bearer token due to 'Invalid CSRF Token' error.

Publish Date: Apr 10, 2026
Description

The user is unable to get a bearer token from https://anypoint.mulesoft.com/accounts/login beyond the first successful attempt. Every time they try, they receive an 'Invalid CSRF Token' error and a 403 forbidden status when using their REST client.

Resolution

An "Invalid CSRF Token" error occurs when a web application’s security mechanism fails to match a session token, often due to expired sessions, browser cookie issues, or blocked scripts. To fix it, refresh the page, clear browser cookies/cache for that site, disable ad-blockers, or log in again.

Knowledge Article Number

005318115

 
Loading
Salesforce Help | Article