# "BAD CSRF" when executing PUT using API, curl, and PHP

**URL:** <https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [May 31, 2020, 10:31pm UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422 "2020-05-31T22:31:46Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![hjalali](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hjalali/32/181824_2.png) [@hjalali](https://meta.discourse.org/u/hjalali)\
**Post date:** [May 31, 2020, 10:31pm UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422/1 "2020-05-31T22:31:46Z")

</div>

I have a very simple function that “should” work but it is not for some reason. Can someone help me understand what we are doing wrong.

We keep getting the “BAD CSRF” error.

```
public function changeName()
{
  $url = 'https://www.website.com/{username}.json';
  $data = ['name'=>'James', 'api_key'=>DISCOURSE_API, 'api_username'=>'system'];

  $ch = curl_init($url);
  curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  curl_setopt($ch, CURLOPT_CUSTOMREQUEST, "PUT");
  curl_setopt($ch, CURLOPT_HTTPHEADER, array('Content-Type:multipart/form-data'));
  curl_setopt($ch, CURLOPT_POSTFIELDS,http_build_query($data));

  echo $response = curl_exec($ch);

  if (!$response)
  {
      return false;
  }

}

```

By the way I already tried moving the api\_key and api\_username to the URL above as GET but no difference.

---

_[View the full topic](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422)._
