We use CSRF tokens to prevent cross-site request forgeries. If you're seeing the error message "Invalid or missing CSRF token" when logging into your Sagitto account, don’t panic. This error message means that your browser couldn’t create a secure cookie, or couldn’t access that cookie to authorize your login. This can be caused by ad- or script-blocking plugins, but also by the browser itself if it's not allowed to set cookies.


To address this issue, follow these steps.


Chrome
Open Chrome Settings.
Scroll to the bottom and click on Advanced.
In the Privacy and security section, click the Content Settings button.
Click on Cookies.
Next to Allow, click Add.
Type [*.]sagitto.com and click Add.
Under All cookies and site data, search for sagitto, and delete all Sagitto-related entries.
Reload Chrome and log into Sagitto.

Firefox
Open the Firefox Options menu.
On the left, select Privacy & Security.
Under Cookies and Site Data click the Exceptions button.
Type https://sagitto.com and click Allow.
Click Save Changes.
Next, click on the Manage Data… button.
Search for "sagitto" and select Remove All Shown.
Click Save Changes and confirm in the pop-up window by clicking Remove.
Reload Firefox and log into Sagitto.


Note
If this alone won't help, please go to Cookies and Site Data, and set “Accept third-party cookies and site data” to either "From Visited" or "Always".

Safari

Open Safari Preferences from the drop-down menu in the navigation bar or by typing Cmd + , (⌘,).
Click the Privacy tab and make sure that "Cookies and website data" is set to either "Always allow" or "Allow from websites I visit".
Click on the Manage Website Data button to see all locally stored website data.
Search for “Sagitto” and remove all Sagitto-related entries.
Reload Safari and log into Sagitto.


CSRF tokens mismatch
This error message is caused by privacy extensions. If you are running any privacy extensions such as Ghostery or Privacy Badger, make sure to add sagitto.com as a trusted website.