dotnet/aspnetcore · error · AntiforgeryValidationException

The required antiforgery cookie

Error message

The required antiforgery cookie "{0}" is not present.

What it means

DefaultAntiforgery.ValidateRequestAsync obtains the request tokens via the token store and requires a cookie token to be present. If the antiforgery cookie (named per options.Cookie.Name) is absent from the request, validation fails before a request/form token is even checked, throwing AntiforgeryValidationException.

Solutions

  1. Ensure the client first obtains the antiforgery cookie - issue a GET that calls GetAndStoreTokensAsync (or rely on the auto-validation flow which sets the cookie) before the unsafe verb.
  2. Send credentials cross-origin: fetch/Ajax with credentials:'include' / HttpClient with cookies, and set proper CORS + SameSite.
  3. Confirm options.Cookie.Name matches the cookie actually issued and that Secure/SameSite allow transmission.

Example fix

// before - client POSTs with no antiforgery cookie
await antiforgery.ValidateRequestAsync(HttpContext); // throws
// after - mint+set the cookie first (e.g. on a prior GET)
var tokens = antiforgery.GetAndStoreTokens(httpContext);
// client then sends the cookie + token on the POST
Defensive patterns

Strategy: try-catch

Validate before calling

// Make sure the cookie exists before validating an unsafe verb
if (!httpContext.Request.Cookies.ContainsKey(antiforgeryOptions.Cookie.Name)) {
    // mint+store the cookie (e.g. on a prior GET via GetAndStoreTokensAsync)
    return Results.BadRequest("Missing antiforgery cookie.");
}

Type guard

bool hasCookieToken(HttpContext ctx, AntiforgeryOptions opt) =>
    ctx.Request.Cookies.ContainsKey(opt.Cookie.Name);

Try / catch

try {
    await antiforgery.ValidateRequestAsync(httpContext);
} catch (AntiforgeryValidationException ex) when (ex.Message.Contains("not present")) {
    // cookie/token missing - return 400 / challenge the client to obtain tokens
    return Results.BadRequest(ex.Message);
}

Prevention

When it happens

Trigger: A POST/PUT/PATCH (or manual ValidateRequestAsync) request reaches validation but the client did not send the antiforgery cookie token - tokens.CookieToken is null (DefaultAntiforgery.cs:145-150). The cookie normally accompanies the request token pair issued by GetAndStoreTokensAsync.

Common situations: The client never received/echoed the antiforgery cookie (no GET to mint it, or SameSite/Secure blocked it); cross-origin requests where credentials/cookies are not sent; cookie expired or was cleared; a different Cookie.Name configured than what the client holds.

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/4742b82751d3917e. Report an issue: GitHub.

Appendix: source

Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:148

        else
        {
            _logger.ValidationFailed(message!);
        }

        return result;
    }

    /// <inheritdoc />
    public async Task ValidateRequestAsync(HttpContext httpContext)
    {
        ArgumentNullException.ThrowIfNull(httpContext);

        CheckSSLConfig(httpContext);

        var tokens = await _tokenStore.GetRequestTokensAsync(httpContext);
        if (tokens.CookieToken == null)
        {
            throw new AntiforgeryValidationException(
                Resources.FormatAntiforgery_CookieToken_MustBeProvided(_options.Cookie.Name));
        }

        if (tokens.RequestToken == null)
        {
            if (_options.HeaderName == null)
            {
                var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
                throw new AntiforgeryValidationException(message);
            }
            else if (!httpContext.Request.HasFormContentType)
            {
                var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
                throw new AntiforgeryValidationException(message);
            }
            else
            {
                var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(

View on GitHub (pinned to 3600ca084e)