X-CSRF-TOKEN in SAP API POST request

Also, in some cases, you additionally may need to tick the Don't send the header "Expect:100-continue" checkbox.