Troubleshooting the Invalid CSRF Token error for new users
Who is this article for?
Administrators onboarding new users to Ideagen Hub.
Administrator permissions are required.
If a newly created user receives an 'Invalid CSRF Token' error when attempting to sign in for the first time, the most likely cause is that they have not yet completed the required password reset step before logging in.
Understanding why the error occurs
When a user account is created in Ideagen Hub, the system sends a welcome email to the user's registered email address. For security reasons, new users are not assigned a usable password at account creation — they must use the Reset Password link in that welcome email to set their own password before they can sign in for the first time.
Attempting to sign in before completing this step results in the 'Invalid CSRF Token' error, even though the real issue is simply that the first-login setup has not been completed.
Important: Administrators cannot set or change a password on a user's behalf. This is by design: allowing an administrator to know a user's password undermines account security and breaks audit non-repudiation. The user must complete the password reset themselves using the link in the welcome email.
Guiding the new user through first-time setup
To complete the first-time setup, the new user should:
- Check your inbox for a welcome email from app@hub.ideagen.com — also check your spam or junk folder if you don't see it.
- Open the email and click the Reset Password link.
- Set a new password following any requirements shown.
- Sign in using your new password.
Note: The Reset Password link in the welcome email expires after a set period. If the link has expired, ask your administrator to resend the welcome email.
Checking if the welcome email was not received
Work through the following checks before resending the email.
| Check | What to do |
|---|---|
| Email blocked or filtered | Ask your IT administrator to confirm that emails from app@hub.ideagen.com are not being blocked or filtered |
| Email address incorrect | In the Admin Console, go to User Management and confirm the user's email address is accurate and uses the correct domain (for example, @company.com rather than @company.co.uk). Note that email addresses are treated as case sensitive — john.doe@abc.com and JohnDoe@abc.com are different addresses. |
| User not active | Welcome emails are only sent to active users. Check the user's status in User Management and activate the account if needed |
| Welcome emails disabled for non-admin users | Check Admin Console → Settings → Communication. If the setting is configured to send welcome emails only to administrators automatically, other users must be sent the email manually |
Resending a welcome email manually
To resend the welcome email:
- Go to Admin Console → User Management.
- Search for the affected user.
- Click the Send welcome email icon next to their account.
Tip: If multiple new users are affected at once, you can select several users in User Management and use Send welcome email to send to all of them in one action, rather than resending individually. To send to all active users at once, use the Ellipses menu and select Send Welcome Email to All Users.
Escalating if the error persists after completing the password reset
If a user has completed the password reset step and is still seeing the 'Invalid CSRF Token' error, this may indicate a genuine authentication configuration issue such as an SSO misconfiguration.
To escalate the issue:
- Contact Ideagen Support.
- Provide the version number shown at the bottom of the left-hand navigation panel.
- Specify whether the error affects only new users or existing users as well.