you can get token by simply calling /libs/granite/csrf/token.json
Does it work in lower environment? the login cookie is created when user is able to login successfully. Can you see login-token cookie? if yes then check if dispatcher is removing cookie header
Arun Patidar