# BadRequest: The CSRF token is missing.

- **ID:** `python/flask-wtf-csrf-token-missing`
- **Domain:** python
- **Category:** auth_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

POST/PUT/DELETE request lacks the `csrf_token` form field or `X-CSRFToken` header, or CSRFProtect is enabled without token in template.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 1.2.x | active | — | — |

## Workarounds

1. **** (95% success)
   ```
   In template: `<form method="post">{{ csrf_token() }}...` or `<meta name="csrf-token" content="{{ csrf_token() }}">` and send as `X-CSRFToken` header from JS.
   ```
2. **** (85% success)
   ```
   For APIs using token auth, exempt only token-protected blueprints: `csrf.exempt(api_bp)`.
   ```

## Dead Ends

- **** — Removes protection; opens CSRF vulnerability. (95% fail)
- **** — Same as disabling; negates the extension. (90% fail)
