> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blindsight.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Csrf

> Issue/refresh the double-submit CSRF cookie and return its value.

The SPA calls this on load so a session that predates the CSRF cookie still
obtains one. Safe to call unauthenticated (it only mints a random token).



## OpenAPI

````yaml /api-reference/openapi.json get /api/auth/csrf
openapi: 3.1.0
info:
  title: Blindsight API
  version: 0.1.0
  description: >-
    The full Blindsight REST surface, generated from the running application.
    Replace the server host with your own deployment.


    For the Runtime Security integration surface (scan, proxy, tool calls) see
    the Runtime Security spec, which is hand written and carries worked
    examples.
servers:
  - url: https://api.your-blindsight.com
    description: Your Blindsight deployment
security: []
paths:
  /api/auth/csrf:
    get:
      tags:
        - auth
      summary: Get Csrf
      description: >-
        Issue/refresh the double-submit CSRF cookie and return its value.


        The SPA calls this on load so a session that predates the CSRF cookie
        still

        obtains one. Safe to call unauthenticated (it only mints a random
        token).
      operationId: get_csrf_api_auth_csrf_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                additionalProperties: true
                type: object
                title: Response Get Csrf Api Auth Csrf Get

````