CSRF protection is disabled for (non-webclient) APIs such as the PMFS API and Web services API.
Consequently, this makes it possible to apply automated performance tools for testing these APIs and to mimic multiple concurrent users by sending HTTP requests.