dotnet/aspnetcore · error · AntiforgeryValidationException

The required antiforgery form field

Error message

The required antiforgery form field "{0}" is not present.

What it means

Thrown during antiforgery validation when the request token is missing and the application has NOT configured a header name (HeaderName == null), meaning antiforgery expects the token only as a form field. The validator already confirmed the cookie token exists, but the form field named in FormFieldName was absent. It is an AntiforgeryValidationException surfaced to the request pipeline as a 400.

Solutions

  1. Ensure the form is generated with the asp-antiforgery-enabled form tag helper or @Html.AntiForgeryToken() so the hidden field matching FormFieldName (default __RequestVerificationToken) is emitted.
  2. For AJAX/fetch, read the hidden field from the DOM and include it in the submitted FormData or request body under the same field name.
  3. If your client sends the token via an HTTP header instead, configure AntiforgeryOptions.HeaderName (e.g. options.HeaderName = "RequestVerificationToken") so validation looks in the header rather than the form.
  4. Verify AntiforgeryOptions.FormFieldName on the server matches the field name the client actually sends.

Example fix

// before: fetch missing token
await fetch('/submit', { method:'POST', body: JSON.stringify(data), headers:{'Content-Type':'application/json'} });

// after: include antiforgery field in FormData
const token = document.querySelector('input[name="__RequestVerificationToken"]').value;
const fd = new FormData();
fd.append('__RequestVerificationToken', token);
fd.append('payload', JSON.stringify(data));
await fetch('/submit', { method:'POST', body: fd });
Defensive patterns

Strategy: validation

Validate before calling

// Before calling an endpoint protected by antiforgery, confirm the token field exists and is non-empty.
const field = document.querySelector('input[name="__RequestVerificationToken"]');
if (!field || !field.value) { /* regenerate form or fetch token */ }

Try / catch

try { await antiforgery.ValidateRequestAsync(httpContext); }
catch (AntiforgeryValidationException) { return Results.BadRequest("Antiforgery token missing."); }

Prevention

When it happens

Trigger: Calling ValidateAsync(httpContext) or letting the [ValidateAntiForgeryToken] filter run, when _options.HeaderName is null and the posted form does not contain the FormFieldName key (e.g. a form rendered without @Html.AntiForgeryToken() / <form> tag helper with asp-antiforgery, or a fetch POST that did not include the token field).

Common situations: Razor form rendered manually without the antiforgery tag helper; AJAX/fetch POST sending JSON or FormData that omits the hidden __RequestVerificationToken; a form field name misconfiguration between client and server; SPA posting to an MVC endpoint without copying the token into the body.

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/2d2072a272979b62. Report an issue: GitHub.

Appendix: source

Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:157

    public async Task ValidateRequestAsync(HttpContext httpContext)
    {
        ArgumentNullException.ThrowIfNull(httpContext);

        CheckSSLConfig(httpContext);

        var tokens = await _tokenStore.GetRequestTokensAsync(httpContext);
        if (tokens.CookieToken == null)
        {
            throw new AntiforgeryValidationException(
                Resources.FormatAntiforgery_CookieToken_MustBeProvided(_options.Cookie.Name));
        }

        if (tokens.RequestToken == null)
        {
            if (_options.HeaderName == null)
            {
                var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
                throw new AntiforgeryValidationException(message);
            }
            else if (!httpContext.Request.HasFormContentType)
            {
                var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
                throw new AntiforgeryValidationException(message);
            }
            else
            {
                var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(
                    _options.FormFieldName,
                    _options.HeaderName);
                throw new AntiforgeryValidationException(message);
            }
        }

        ValidateTokens(httpContext, tokens);

        _logger.ValidatedAntiforgeryToken();

View on GitHub (pinned to 3600ca084e)