# "BAD CSRF" when executing PUT using API, curl, and PHP

**URL:** <https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [May 31, 2020, 10:31pm UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422 "2020-05-31T22:31:46Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![brospars](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/brospars/32/235841_2.png) [@brospars](https://meta.discourse.org/u/brospars)\
**Post date:** [October 5, 2021, 9:32am UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422/5 "2021-10-05T09:32:26Z")

</div>

Since when it’s mandatory ?  
Didn’t find it in the changelog. I made a tool 2-3 years ago to create categories in batch that worked perfectly fine and now I get this error…

---

_[View the full topic](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422)._
