play.filters.csrf
Get the header token, that is, the token that should be validated.
Tag incoming requests with the token in the header