dotnet/aspnetcore · error · InvalidOperationException

The provided identity of type

Error message

The provided identity of type '{0}' is marked {1} = {2} but does not have a value for {3}. By default, the antiforgery system requires that all authenticated identities have a unique {3}. If it is not possible to provide a unique {3} for this identity, consider extending {4} by overriding the {5} or a custom type that can provide some form of unique identifier for the current user.

What it means

Thrown when generating an antiforgery token for an authenticated user whose identity has no username (IIdentity.Name empty), no ClaimUid (no anti-forgery claim-based identifier), and no AdditionalData supplied by a custom provider. The system requires every authenticated identity to have a unique identifier so tokens can be bound to the user.

Solutions

  1. Ensure the ClaimsIdentity has a Name claim populated (set NameClaimType or add a Claim of that type) so IIdentity.Name is non-empty.
  2. Or configure AntiforgeryOptions to use a unique claim via a custom IAntiforgeryAdditionalDataProvider that fills AdditionalData.
  3. Set the identity's NameClaimType to a claim that is guaranteed present (e.g. ClaimTypes.NameIdentifier) when constructing the ClaimsIdentity.
  4. If the user truly has no stable identifier, mark the identity as not authenticated for that resource so the username requirement is bypassed.

Example fix

// before: identity with no Name claim
var id = new ClaimsIdentity(claims, "MyAuth"); // Name is null

// after: declare the unique claim as the name source
var id = new ClaimsIdentity(claims, "MyAuth", ClaimTypes.NameIdentifier, ClaimTypes.Role);
Defensive patterns

Strategy: validation

Validate before calling

var identity = httpContext.User.Identity as ClaimsIdentity;
if (identity?.IsAuthenticated == true && string.IsNullOrEmpty(identity.Name)) { /* ensure a Name claim or register an IAntiforgeryAdditionalDataProvider before generating the token */ }

Type guard

static bool HasAntiforgeryIdentity(IIdentity? id) => !(id?.IsAuthenticated == true && string.IsNullOrEmpty(id.Name));

Prevention

When it happens

Trigger: A signed-in ClaimsIdentity reaches the token generator with IsAuthenticated==true, but Name claim is unset, the claim used to build ClaimUid is missing, and no IAntiforgeryAdditionalDataProvider is registered to fill AdditionalData.

Common situations: Custom authentication that sets IsAuthenticated without a Name claim (or without ClaimTypes.NameIdentifier); cookie/auth configured without setting a NameClaimType; a federated login that doesn't map a unique id claim; upgrading to a claims identity without configuring UniqueClaimTypeIdentifier.

Understand the failure class

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/015fc69e41b7cb32. Report an issue: GitHub.

Appendix: source

Thrown at src/Antiforgery/src/Internal/DefaultAntiforgeryTokenGenerator.cs:86

            if (requestToken.ClaimUid == null)
            {
                requestToken.Username = authenticatedIdentity.Name;
            }
        }

        // populate AdditionalData
        if (_additionalDataProvider != null)
        {
            requestToken.AdditionalData = _additionalDataProvider.GetAdditionalData(httpContext);
        }

        if (isIdentityAuthenticated
            && string.IsNullOrEmpty(requestToken.Username)
            && requestToken.ClaimUid == null
            && string.IsNullOrEmpty(requestToken.AdditionalData))
        {
            // Application says user is authenticated, but we have no identifier for the user.
            throw new InvalidOperationException(
                Resources.FormatAntiforgeryTokenValidator_AuthenticatedUserWithoutUsername(
                    authenticatedIdentity?.GetType() ?? typeof(ClaimsIdentity),
                    nameof(IIdentity.IsAuthenticated),
                    "true",
                    nameof(IIdentity.Name),
                    nameof(IAntiforgeryAdditionalDataProvider),
                    nameof(DefaultAntiforgeryAdditionalDataProvider)));
        }

        return requestToken;
    }

    /// <inheritdoc />
    public bool IsCookieTokenValid(AntiforgeryToken? cookieToken)
    {
        return cookieToken != null && cookieToken.IsCookieToken;
    }

View on GitHub (pinned to 3600ca084e)