# "BAD CSRF" when executing PUT using API, curl, and PHP

**URL:** https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422
**Category:** Development
**Tags:** rest-api
**Created:** [May 31, 2020, 10:31pm UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422 "2020-05-31T22:31:46Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![blake](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/blake/32/157322_2.png) [@blake](https://meta.discourse.org/u/blake)
#### Post date: [October 5, 2021, 3:39pm UTC](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422/6 "2021-10-05T15:39:09Z")

</div>

> [@brospars](#):
>
> Since when it’s mandatory ?  
> Didn’t find it in the changelog. I made a tool 2-3 years ago

> [@Discourse REST API Documentation](https://meta.discourse.org/t/discourse-rest-api-documentation/22706/1):
>
> ## ⚠ Deprecation Warning!
> 
> **On April 6th, 2020 we dropped support for all non-HTTP header based authentication (excluding some rss, mail-receiver, and ics routes).** This means that API requests that have an `api_key` and `api_username` in the query params or in the HTTP body of the request will soon stop working.

Sorry about any issues this caused, we did do a slow roll out of this change and notified people the best we could, but its hard to catch every deprecation use.

---

_[View the full topic](https://meta.discourse.org/t/bad-csrf-when-executing-put-using-api-curl-and-php/153422)._
