CSRF token error messages


  • Web

If you're seeing a CSRF error message when logging into your Todoist account, don’t panic. You can find some simple solutions below:

Invalid or missing CSRF token

This error message means that your browser couldn’t create a secure cookie, or couldn’t access that cookie to authorize your login. This can be caused by ad- or script-blocking plugins, but also by the browser itself if it's not allowed to set cookies.

To address this issue, follow these steps.


  1. Open Chrome Settings.
  2. In the Privacy and security section, click Cookies and other site data.
  3. Scroll down to Sites that can always use cookies and click Add.
    • Copy and paste [*.]todoist.com and click Add.
    • Copy and paste [*.]cloudfront.net and click Add.
  4. Click See all cookies and site data.
  5. Search for todoist.
  6. Delete all Todoist-related entries.
  7. Reload Chrome and log into Todoist.


  1. Open Firefox Settings.
  2. On the left, select Privacy & Security.
  3. Under Cookies and Site Data click on Manage Exceptions.
    1. Copy and paste https://todoist.com and click Allow.
    2. Then copy and paste https://cloudfront.net and click Allow.
  4. Click Save Changes.
  5. Click Manage Data.
  6. Search for todoist and select Remove All Shown.
  7. Click Save Changes.
  8. Click Remove to confirm.
  9. Reload Firefox and log into Todoist.


  1. Open Safari Preferences from the drop-down menu in the navigation bar or by typing Cmd + , (⌘,).
  2. Click the Privacy tab.
  3. Check that Cookies and website data is not set to Block all cookies.
  4. Click Manage Website Data to see all locally stored website data.
  5. Search for todoist and remove all Todoist-related entries.
  6. Reload Safari and log into Todoist.

CSRF tokens mismatch

This error message is caused by privacy extensions. If you are running any privacy extensions such as Ghostery or Privacy Badger, make sure to add todoist.com as a trusted website.