dotnet/aspnetcore · error · AntiforgeryValidationException
The required antiforgery form field
Error message
The required antiforgery form field "{0}" is not present. What it means
Thrown during antiforgery validation when the request token is missing and the application has NOT configured a header name (HeaderName == null), meaning antiforgery expects the token only as a form field. The validator already confirmed the cookie token exists, but the form field named in FormFieldName was absent. It is an AntiforgeryValidationException surfaced to the request pipeline as a 400.
Solutions
- Ensure the form is generated with the asp-antiforgery-enabled form tag helper or @Html.AntiForgeryToken() so the hidden field matching FormFieldName (default __RequestVerificationToken) is emitted.
- For AJAX/fetch, read the hidden field from the DOM and include it in the submitted FormData or request body under the same field name.
- If your client sends the token via an HTTP header instead, configure AntiforgeryOptions.HeaderName (e.g. options.HeaderName = "RequestVerificationToken") so validation looks in the header rather than the form.
- Verify AntiforgeryOptions.FormFieldName on the server matches the field name the client actually sends.
Example fix
// before: fetch missing token
await fetch('/submit', { method:'POST', body: JSON.stringify(data), headers:{'Content-Type':'application/json'} });
// after: include antiforgery field in FormData
const token = document.querySelector('input[name="__RequestVerificationToken"]').value;
const fd = new FormData();
fd.append('__RequestVerificationToken', token);
fd.append('payload', JSON.stringify(data));
await fetch('/submit', { method:'POST', body: fd }); Defensive patterns
Strategy: validation
Validate before calling
// Before calling an endpoint protected by antiforgery, confirm the token field exists and is non-empty.
const field = document.querySelector('input[name="__RequestVerificationToken"]');
if (!field || !field.value) { /* regenerate form or fetch token */ } Try / catch
try { await antiforgery.ValidateRequestAsync(httpContext); }
catch (AntiforgeryValidationException) { return Results.BadRequest("Antiforgery token missing."); } Prevention
- Always render forms with the form tag helper or @Html.AntiForgeryToken().
- For AJAX, read the hidden field or cookie and send it on every unsafe verb.
- Keep FormFieldName consistent across server config and client code.
- Add an integration test that posts a form without the token and asserts a 400.
When it happens
Trigger: Calling ValidateAsync(httpContext) or letting the [ValidateAntiForgeryToken] filter run, when _options.HeaderName is null and the posted form does not contain the FormFieldName key (e.g. a form rendered without @Html.AntiForgeryToken() / <form> tag helper with asp-antiforgery, or a fetch POST that did not include the token field).
Common situations: Razor form rendered manually without the antiforgery tag helper; AJAX/fetch POST sending JSON or FormData that omits the hidden __RequestVerificationToken; a form field name misconfiguration between client and server; SPA posting to an MVC endpoint without copying the token into the body.
Related errors
- The required antiforgery request token was not provided in…
- The required antiforgery cookie
- The required antiforgery header value
- The antiforgery system has the configuration value
- The provided identity of type
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/2d2072a272979b62.
Report an issue: GitHub.
Appendix: source
Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:157
public async Task ValidateRequestAsync(HttpContext httpContext)
{
ArgumentNullException.ThrowIfNull(httpContext);
CheckSSLConfig(httpContext);
var tokens = await _tokenStore.GetRequestTokensAsync(httpContext);
if (tokens.CookieToken == null)
{
throw new AntiforgeryValidationException(
Resources.FormatAntiforgery_CookieToken_MustBeProvided(_options.Cookie.Name));
}
if (tokens.RequestToken == null)
{
if (_options.HeaderName == null)
{
var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
throw new AntiforgeryValidationException(message);
}
else if (!httpContext.Request.HasFormContentType)
{
var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
throw new AntiforgeryValidationException(message);
}
else
{
var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(
_options.FormFieldName,
_options.HeaderName);
throw new AntiforgeryValidationException(message);
}
}
ValidateTokens(httpContext, tokens);
_logger.ValidatedAntiforgeryToken();View on GitHub (pinned to 3600ca084e)