# CRSF Token in IIQ Web Services Connector?

**URL:** <https://developer.sailpoint.com/discuss/t/crsf-token-in-iiq-web-services-connector/4145>\
**Category:** IIQ Discussion and Questions\
**Created:** [May 9, 2022, 5:33pm UTC](https://developer.sailpoint.com/discuss/t/crsf-token-in-iiq-web-services-connector/4145 "2022-05-09T17:33:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ericlawson](https://avatars.discourse-cdn.com/v4/letter/e/6a8cbe/32.png) [@ericlawson](https://developer.sailpoint.com/discuss/u/ericlawson)\
**Post date:** [May 9, 2022, 5:33pm UTC](https://developer.sailpoint.com/discuss/t/crsf-token-in-iiq-web-services-connector/4145/1 "2022-05-09T17:33:42Z")

</div>

I’m looking for some advice on retrieving a CRSF token and using the token for connector operations. The token is retrieved using basic auth username/password. Then if using postman the token is placed into a header x-crsf-token.

> **[How to send a Odata Batch Request to SAP Cloud for Customer system using...](https://blogs.sap.com/2020/04/06/how-to-send-a-odata-batch-request-to-sap-cloud-for-customer-system-using-postman-tool/)**
>
> Overview: In this blog post,we are going to see how to send a Odata Batch Request to the SAP Cloud for Customer system using POSTMAN Tool. Answers to expect from this post? How to use batch request in the

---

<div class="post-metadata">

**Author:** ![Paul\_Meyer](https://avatars.discourse-cdn.com/v4/letter/p/f9ae1b/32.png) [@Paul\_Meyer](https://developer.sailpoint.com/discuss/u/Paul_Meyer)\
**Post date:** [May 25, 2022, 1:05pm UTC](https://developer.sailpoint.com/discuss/t/crsf-token-in-iiq-web-services-connector/4145/2 "2022-05-25T13:05:28Z")

</div>

You can use the Custom Authentication option. For an example of how to set the “accesstoken” attribute in the application see the “No/Custom Authentication” section in the Web Services Connector Guide.

That said, the configuration of the Custom Authentication operation might be interesting and might require a

1. Before Operation rule:

2. After Operation rule:

Note that the UI does not present a config option for the Before/After rules for the Custom Authentication operation. You can however set the rules in the application XML under the operations config section.

Use the stored token value in the other Operations config as a headers

- “x-csrf-token” ← $application.accesstoken$
- “Authorization” ← either a stored application attribute value or one that is calculated in each operation’s before operation rule.

The Basic Auth’s username and password can be stored in the application config using the “\_CA” mechnanism and retrieved in the Before Operation rules; $application.username\_CA$ and $application.password\_CA".

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [July 19, 2023, 2:25pm UTC](https://developer.sailpoint.com/discuss/t/crsf-token-in-iiq-web-services-connector/4145/3 "2023-07-19T14:25:35Z")

</div>


