dotnet/aspnetcore · error · InvalidOperationException
The provided identity of type
Error message
The provided identity of type '{0}' is marked {1} = {2} but does not have a value for {3}. By default, the antiforgery system requires that all authenticated identities have a unique {3}. If it is not possible to provide a unique {3} for this identity, consider extending {4} by overriding the {5} or a custom type that can provide some form of unique identifier for the current user. What it means
Thrown when generating an antiforgery token for an authenticated user whose identity has no username (IIdentity.Name empty), no ClaimUid (no anti-forgery claim-based identifier), and no AdditionalData supplied by a custom provider. The system requires every authenticated identity to have a unique identifier so tokens can be bound to the user.
Solutions
- Ensure the ClaimsIdentity has a Name claim populated (set NameClaimType or add a Claim of that type) so IIdentity.Name is non-empty.
- Or configure AntiforgeryOptions to use a unique claim via a custom IAntiforgeryAdditionalDataProvider that fills AdditionalData.
- Set the identity's NameClaimType to a claim that is guaranteed present (e.g. ClaimTypes.NameIdentifier) when constructing the ClaimsIdentity.
- If the user truly has no stable identifier, mark the identity as not authenticated for that resource so the username requirement is bypassed.
Example fix
// before: identity with no Name claim var id = new ClaimsIdentity(claims, "MyAuth"); // Name is null // after: declare the unique claim as the name source var id = new ClaimsIdentity(claims, "MyAuth", ClaimTypes.NameIdentifier, ClaimTypes.Role);
Defensive patterns
Strategy: validation
Validate before calling
var identity = httpContext.User.Identity as ClaimsIdentity;
if (identity?.IsAuthenticated == true && string.IsNullOrEmpty(identity.Name)) { /* ensure a Name claim or register an IAntiforgeryAdditionalDataProvider before generating the token */ } Type guard
static bool HasAntiforgeryIdentity(IIdentity? id) => !(id?.IsAuthenticated == true && string.IsNullOrEmpty(id.Name));
Prevention
- Set NameClaimType on custom ClaimsIdentity to a claim that is always present.
- Register an IAntiforgeryAdditionalDataProvider when you cannot guarantee a Name claim.
- Add a unit test that signs in a claimless principal and asserts token generation succeeds.
When it happens
Trigger: A signed-in ClaimsIdentity reaches the token generator with IsAuthenticated==true, but Name claim is unset, the claim used to build ClaimUid is missing, and no IAntiforgeryAdditionalDataProvider is registered to fill AdditionalData.
Common situations: Custom authentication that sets IsAuthenticated without a Name claim (or without ClaimTypes.NameIdentifier); cookie/auth configured without setting a NameClaimType; a federated login that doesn't map a unique id claim; upgrading to a claims identity without configuring UniqueClaimTypeIdentifier.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- The antiforgery system has the configuration value
- The required antiforgery cookie
- The required antiforgery form field
- The required antiforgery header value
- The required antiforgery request token was not provided in…
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/015fc69e41b7cb32.
Report an issue: GitHub.
Appendix: source
Thrown at src/Antiforgery/src/Internal/DefaultAntiforgeryTokenGenerator.cs:86
if (requestToken.ClaimUid == null)
{
requestToken.Username = authenticatedIdentity.Name;
}
}
// populate AdditionalData
if (_additionalDataProvider != null)
{
requestToken.AdditionalData = _additionalDataProvider.GetAdditionalData(httpContext);
}
if (isIdentityAuthenticated
&& string.IsNullOrEmpty(requestToken.Username)
&& requestToken.ClaimUid == null
&& string.IsNullOrEmpty(requestToken.AdditionalData))
{
// Application says user is authenticated, but we have no identifier for the user.
throw new InvalidOperationException(
Resources.FormatAntiforgeryTokenValidator_AuthenticatedUserWithoutUsername(
authenticatedIdentity?.GetType() ?? typeof(ClaimsIdentity),
nameof(IIdentity.IsAuthenticated),
"true",
nameof(IIdentity.Name),
nameof(IAntiforgeryAdditionalDataProvider),
nameof(DefaultAntiforgeryAdditionalDataProvider)));
}
return requestToken;
}
/// <inheritdoc />
public bool IsCookieTokenValid(AntiforgeryToken? cookieToken)
{
return cookieToken != null && cookieToken.IsCookieToken;
}
View on GitHub (pinned to 3600ca084e)