Consider implementing this: https://flask-wtf.readthedocs.io/en/stable/csrf.html https://sjl.bitbucket.io/flask-csrf/