It would be nice to be able to configure the CSRF validation so it can be read from a particular HTTP header. Let me know if this is something that would fit into the project, I would be happy to contribute. 🙂