# Where can I get the correct kbn-xsrf value for my plugin HTTP requests?

**URL:** https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725
**Category:** Kibana
**Created:** [November 29, 2018, 9:56am UTC](https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725 "2018-11-29T09:56:11Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![trex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trex/32/34230_2.png) [@trex](https://discuss.elastic.co/u/trex)
#### Post date: [November 29, 2018, 9:56am UTC](https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725/1 "2018-11-29T09:56:11Z")

</div>

I develop a Kibana plugin where I try to use [axios](https://github.com/axios/axios) HTTP client. Now my code fails with

```
1. error: "Bad Request"
2. message: "Request must contain a kbn-xsrf header."
3. statusCode: 400

```

Where can I get the correct `kbn-xsrf` value?

The code which fails:

```
import axios from 'axios';
  
export default class {
  constructor() {
    this.http = axios.create({
      headers: { 'Content-Type': 'application/json' }
    });
  }

  statField(index, field, filters = []) {
    const query = {
      query: {
        bool: {
          must: [
            ...filters.map(filter => ({
              match: {
                [filter.field]: filter.value
              }
            }))
          ]
        }
      },
      aggs: {
        stat_agg: {
          stats: { field }
        }
      },
      size: 0
    };

    return this.http.post(`../elasticsearch/${index}/_search`, query)
    ...
```

---

<div class="post-metadata">

### Author: ![trex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trex/32/34230_2.png) [@trex](https://discuss.elastic.co/u/trex)
#### Post date: [November 29, 2018, 10:13am UTC](https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725/2 "2018-11-29T10:13:31Z")

</div>

I put this into the HTTP request headers and it works, I get data from Elasticsearch.

```
this.headers = {
  'Content-Type': 'application/json',
  'kbn-xsrf': 'anything',
  'Accept': 'application/json, text/plain, */*'
};

```

But I'm not sure `anything` is a good value for `kbn-xsrf`. Is it a good value?

---

<div class="post-metadata">

### Author: ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)
#### Post date: [November 29, 2018, 4:11pm UTC](https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725/3 "2018-11-29T16:11:07Z")

</div>

Currently, as long as you include a `kbn-xsrf` header, it will work. I believe Kibana usually uses "kibana" in most places, but in some places it uses a different value.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 27, 2018, 4:11pm UTC](https://discuss.elastic.co/t/where-can-i-get-the-correct-kbn-xsrf-value-for-my-plugin-http-requests/158725/4 "2018-12-27T16:11:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
