# setting csrf token in front-end framework forms (such as react forms)

**URL:** <https://forum.djangoproject.com/t/setting-csrf-token-in-front-end-framework-forms-such-as-react-forms/18161>\
**Category:** Forms & APIs\
**Created:** [January 12, 2023, 5:27pm UTC](https://forum.djangoproject.com/t/setting-csrf-token-in-front-end-framework-forms-such-as-react-forms/18161 "2023-01-12T17:27:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![famdude](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/famdude/32/11725_2.png) [@famdude](https://forum.djangoproject.com/u/famdude)\
**Post date:** [January 12, 2023, 5:27pm UTC](https://forum.djangoproject.com/t/setting-csrf-token-in-front-end-framework-forms-such-as-react-forms/18161/1 "2023-01-12T17:27:44Z")

</div>

There is a way of creating a view with `@ensure_csrf_token` to add a csrf token in cookies, and then calling this view before submitting forms every time, to add given token in form or request header.

But the problem of this approach is that we should do a request before submitting every form, which is not a good idea.

So is there any other way, like using `{% csrf_token %}` in front-end form, to add a csrf automatically, without any extra request?

---

<div class="post-metadata">

**Author:** ![KenWhitesell](https://sea2.discourse-cdn.com/flex026/user_avatar/forum.djangoproject.com/kenwhitesell/32/280_2.png) [@KenWhitesell](https://forum.djangoproject.com/u/KenWhitesell)\
**Post date:** [January 13, 2023, 1:28am UTC](https://forum.djangoproject.com/t/setting-csrf-token-in-front-end-framework-forms-such-as-react-forms/18161/2 "2023-01-13T01:28:43Z")

</div>

My understanding is that the csrf token cookie will continue to be exchanged with every POST request and response. You can (usually) get the token from the cookie.

In other words, instead of:  
GET  
POST  
GET  
POST  
GET  
POST,

the sequence becomes:  
GET  
POST  
POST  
POST

See [How to use Django’s CSRF protection | Django documentation | Django](https://docs.djangoproject.com/en/4.1/howto/csrf/#acquiring-the-token-if-csrf-use-sessions-and-csrf-cookie-httponly-are-false)
