---
title: "Implementing CSRF protection with a synchronizer token"
description: "How can you reject requests without a session-bound CSRF token?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T02.06/"
topicId: "T02.06"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you reject requests without a session-bound CSRF token?

## What we will work through

Reject requests without a session-bound CSRF token.

## Before you begin

Previously covered: How automatically sent credentials enable CSRF.

- [How automatically sent credentials enable CSRF](/en/articles/topics/T02.05/)
