dotnet/aspnetcore · error · AntiforgeryValidationException
The required antiforgery cookie
Error message
The required antiforgery cookie "{0}" is not present. What it means
DefaultAntiforgery.ValidateRequestAsync obtains the request tokens via the token store and requires a cookie token to be present. If the antiforgery cookie (named per options.Cookie.Name) is absent from the request, validation fails before a request/form token is even checked, throwing AntiforgeryValidationException.
Solutions
- Ensure the client first obtains the antiforgery cookie - issue a GET that calls GetAndStoreTokensAsync (or rely on the auto-validation flow which sets the cookie) before the unsafe verb.
- Send credentials cross-origin: fetch/Ajax with credentials:'include' / HttpClient with cookies, and set proper CORS + SameSite.
- Confirm options.Cookie.Name matches the cookie actually issued and that Secure/SameSite allow transmission.
Example fix
// before - client POSTs with no antiforgery cookie await antiforgery.ValidateRequestAsync(HttpContext); // throws // after - mint+set the cookie first (e.g. on a prior GET) var tokens = antiforgery.GetAndStoreTokens(httpContext); // client then sends the cookie + token on the POST
Defensive patterns
Strategy: try-catch
Validate before calling
// Make sure the cookie exists before validating an unsafe verb
if (!httpContext.Request.Cookies.ContainsKey(antiforgeryOptions.Cookie.Name)) {
// mint+store the cookie (e.g. on a prior GET via GetAndStoreTokensAsync)
return Results.BadRequest("Missing antiforgery cookie.");
} Type guard
bool hasCookieToken(HttpContext ctx, AntiforgeryOptions opt) =>
ctx.Request.Cookies.ContainsKey(opt.Cookie.Name); Try / catch
try {
await antiforgery.ValidateRequestAsync(httpContext);
} catch (AntiforgeryValidationException ex) when (ex.Message.Contains("not present")) {
// cookie/token missing - return 400 / challenge the client to obtain tokens
return Results.BadRequest(ex.Message);
} Prevention
- Issue the antiforgery cookie via GetAndStoreTokensAsync on a GET before unsafe verbs.
- Send credentials cross-origin (credentials:'include') and set CORS + SameSite appropriately.
- Ensure options.Cookie.Name/Secure/SameSite allow the cookie to travel with the request.
When it happens
Trigger: A POST/PUT/PATCH (or manual ValidateRequestAsync) request reaches validation but the client did not send the antiforgery cookie token - tokens.CookieToken is null (DefaultAntiforgery.cs:145-150). The cookie normally accompanies the request token pair issued by GetAndStoreTokensAsync.
Common situations: The client never received/echoed the antiforgery cookie (no GET to mint it, or SameSite/Secure blocked it); cross-origin requests where credentials/cookies are not sent; cookie expired or was cleared; a different Cookie.Name configured than what the client holds.
Related errors
- The required antiforgery form field
- The required antiforgery header value
- The required antiforgery request token was not provided in…
- Unable to find the required services. Please add all the…
- The antiforgery system has the configuration value
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/4742b82751d3917e.
Report an issue: GitHub.
Appendix: source
Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:148
else
{
_logger.ValidationFailed(message!);
}
return result;
}
/// <inheritdoc />
public async Task ValidateRequestAsync(HttpContext httpContext)
{
ArgumentNullException.ThrowIfNull(httpContext);
CheckSSLConfig(httpContext);
var tokens = await _tokenStore.GetRequestTokensAsync(httpContext);
if (tokens.CookieToken == null)
{
throw new AntiforgeryValidationException(
Resources.FormatAntiforgery_CookieToken_MustBeProvided(_options.Cookie.Name));
}
if (tokens.RequestToken == null)
{
if (_options.HeaderName == null)
{
var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
throw new AntiforgeryValidationException(message);
}
else if (!httpContext.Request.HasFormContentType)
{
var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
throw new AntiforgeryValidationException(message);
}
else
{
var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(View on GitHub (pinned to 3600ca084e)