When the token is issued, it takes care of the URL of the request. So when the client's browser uses that token, Jenkins is testing if the referer HTTP header is matching the previous URL.