dotnet/aspnetcore · error · NotSupportedException
The authorization data specifies an authentication scheme…
Error message
The authorization data specifies an authentication scheme with value '{0}'. Authentication schemes cannot be specified for components. What it means
Thrown by AuthorizeViewCore.EnsureNoAuthenticationSchemeSpecified when the authorization metadata (an IAuthorizeData, e.g. from [Authorize] or <AuthorizeView Roles=...>) carries a non-empty AuthenticationSchemes value. Blazor components already operate on a resolved ClaimsPrincipal, so specifying which auth scheme to use is meaningless and is rejected.
Solutions
- Remove the AuthenticationSchemes argument from [Authorize] on Blazor components.
- Use a policy/roles instead: [Authorize(Roles = "admin")] or [Authorize(Policy = "...")].
- If you genuinely need a scheme, resolve the principal at the host/hub level and let it cascade into the component rather than declaring a scheme in component metadata.
Example fix
<!-- before: scheme on a component --> @attribute [Authorize(AuthenticationSchemes = "Bearer")] <!-- after: use roles/policy only --> @attribute [Authorize(Policy = "CanViewDashboard")]
Defensive patterns
Strategy: validation
Validate before calling
// At startup, scan component attributes for IAuthorizeData with a non-empty AuthenticationSchemes and fail fast.
foreach (var a in componentAuthorizes) { if (!string.IsNullOrEmpty(a.AuthenticationSchemes)) throw new InvalidOperationException("Components cannot specify schemes."); } Prevention
- Keep MVC controller auth attributes and Blazor component auth attributes in separate folders/imports.
- Use [Authorize(Policy=...)] / [Authorize(Roles=...)] for components.
- Code review [Authorize(...)] usages on .razor files.
When it happens
Trigger: Applying [Authorize(AuthenticationSchemes = "...")] to a Blazor component (page/route), or setting AuthorizeView.AuthenticationSchemes, or any IAuthorizeData where AuthenticationSchemes is non-empty in the component authorization pipeline.
Common situations: Reusing an MVC-style [Authorize(AuthenticationSchemes = "Bearer")] attribute on a Razor component; pasting controller authorization attributes onto a Blazor page; mapping a policy that implies a scheme.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Authorization requires a cascading parameter of type Task
- Do not specify both 'Authorized' and 'ChildContent'.
- ' ' is flagged with SingleDelivery, but the selected…
- The parameter ' ' for component ' ' does not allow null or…
- The type ' ' does not have an associated TypeConverter that…
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/726246468c8e928a.
Report an issue: GitHub.
Appendix: source
Thrown at src/Components/Authorization/src/AuthorizeViewCore.cs:135
{
// The metadata contained nothing that contributes to a policy.
return true;
}
var result = await AuthorizationService.AuthorizeAsync(user, Resource, policy);
return result.Succeeded;
}
private static void EnsureNoAuthenticationSchemeSpecified(object[] metadata)
{
// It's not meaningful to specify a nonempty scheme, since by the time Components
// authorization runs, we already have a specific ClaimsPrincipal (we're stateful).
// To avoid any confusion, ensure the developer isn't trying to specify a scheme.
for (var i = 0; i < metadata.Length; i++)
{
if (metadata[i] is IAuthorizeData entry && !string.IsNullOrEmpty(entry.AuthenticationSchemes))
{
throw new NotSupportedException($"The authorization data specifies an authentication scheme with value '{entry.AuthenticationSchemes}'. Authentication schemes cannot be specified for components.");
}
}
}
}
View on GitHub (pinned to 3600ca084e)