dotnet/aspnetcore · error · NotSupportedException

The authorization data specifies an authentication scheme…

Error message

The authorization data specifies an authentication scheme with value '{0}'. Authentication schemes cannot be specified for components.

What it means

Thrown by AuthorizeViewCore.EnsureNoAuthenticationSchemeSpecified when the authorization metadata (an IAuthorizeData, e.g. from [Authorize] or <AuthorizeView Roles=...>) carries a non-empty AuthenticationSchemes value. Blazor components already operate on a resolved ClaimsPrincipal, so specifying which auth scheme to use is meaningless and is rejected.

Solutions

  1. Remove the AuthenticationSchemes argument from [Authorize] on Blazor components.
  2. Use a policy/roles instead: [Authorize(Roles = "admin")] or [Authorize(Policy = "...")].
  3. If you genuinely need a scheme, resolve the principal at the host/hub level and let it cascade into the component rather than declaring a scheme in component metadata.

Example fix

<!-- before: scheme on a component -->
@attribute [Authorize(AuthenticationSchemes = "Bearer")]

<!-- after: use roles/policy only -->
@attribute [Authorize(Policy = "CanViewDashboard")]
Defensive patterns

Strategy: validation

Validate before calling

// At startup, scan component attributes for IAuthorizeData with a non-empty AuthenticationSchemes and fail fast.
foreach (var a in componentAuthorizes) { if (!string.IsNullOrEmpty(a.AuthenticationSchemes)) throw new InvalidOperationException("Components cannot specify schemes."); }

Prevention

When it happens

Trigger: Applying [Authorize(AuthenticationSchemes = "...")] to a Blazor component (page/route), or setting AuthorizeView.AuthenticationSchemes, or any IAuthorizeData where AuthenticationSchemes is non-empty in the component authorization pipeline.

Common situations: Reusing an MVC-style [Authorize(AuthenticationSchemes = "Bearer")] attribute on a Razor component; pasting controller authorization attributes onto a Blazor page; mapping a policy that implies a scheme.

Understand the failure class

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/726246468c8e928a. Report an issue: GitHub.

Appendix: source

Thrown at src/Components/Authorization/src/AuthorizeViewCore.cs:135

        {
            // The metadata contained nothing that contributes to a policy.
            return true;
        }

        var result = await AuthorizationService.AuthorizeAsync(user, Resource, policy);
        return result.Succeeded;
    }

    private static void EnsureNoAuthenticationSchemeSpecified(object[] metadata)
    {
        // It's not meaningful to specify a nonempty scheme, since by the time Components
        // authorization runs, we already have a specific ClaimsPrincipal (we're stateful).
        // To avoid any confusion, ensure the developer isn't trying to specify a scheme.
        for (var i = 0; i < metadata.Length; i++)
        {
            if (metadata[i] is IAuthorizeData entry && !string.IsNullOrEmpty(entry.AuthenticationSchemes))
            {
                throw new NotSupportedException($"The authorization data specifies an authentication scheme with value '{entry.AuthenticationSchemes}'. Authentication schemes cannot be specified for components.");
            }
        }
    }
}

View on GitHub (pinned to 3600ca084e)