dotnet/aspnetcore · error · AntiforgeryValidationException

The required antiforgery request token was not provided in…

Error message

The required antiforgery request token was not provided in either form field "{0}" or header value "{1}".

What it means

Thrown when both lookup channels are configured (HeaderName is set) and the request IS a form request, but neither the form field nor the header contains a request token. This is the fallback 'we looked everywhere and found nothing' message after HasFormContentType is true yet form[FormFieldName] and the header are both empty.

Solutions

  1. Add the antiforgery hidden field to the form (asp-antiforgery form tag helper or @Html.AntiForgeryToken()) so FormFieldName is populated.
  2. Or send the token in the configured HeaderName on the client.
  3. Confirm FormFieldName and HeaderName in AntiforgeryOptions match what the client emits.
  4. Inspect the actual request body/headers in the browser to confirm which channel the client is using and align it with configuration.

Example fix

// before: form tag helper missing
<form method="post"> ... </form>

// after: tag helper emits token field
<form method="post" asp-antiforgery="true"> ... </form>
Defensive patterns

Strategy: validation

Validate before calling

// Client: confirm at least one channel carries a token before submit.
const hasForm = !!document.querySelector('input[name="__RequestVerificationToken"]')?.value;
const hasHeader = !!headers[configuredHeaderName];
if (!hasForm && !hasHeader) { /* attach a token */ }

Try / catch

try { await antiforgery.ValidateRequestAsync(httpContext); }
catch (AntiforgeryValidationException) { return Results.BadRequest(); }

Prevention

When it happens

Trigger: AntiforgeryOptions.HeaderName is non-null, the request has a form content type, GetRequestTokensAsync returned a non-null cookie token, but both the form field (FormFieldName) and the header (HeaderName) are null/empty.

Common situations: Form posts that were built without the antiforgery tag helper while the server also accepts header-based tokens; a partial view that forgot the hidden field; client middleware that strips unknown form fields; FormFieldName renamed on one side only.

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/ead0bdca906c7cad. Report an issue: GitHub.

Appendix: source

Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:169

        if (tokens.RequestToken == null)
        {
            if (_options.HeaderName == null)
            {
                var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
                throw new AntiforgeryValidationException(message);
            }
            else if (!httpContext.Request.HasFormContentType)
            {
                var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
                throw new AntiforgeryValidationException(message);
            }
            else
            {
                var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(
                    _options.FormFieldName,
                    _options.HeaderName);
                throw new AntiforgeryValidationException(message);
            }
        }

        ValidateTokens(httpContext, tokens);

        _logger.ValidatedAntiforgeryToken();
    }

    private void ValidateTokens(HttpContext httpContext, AntiforgeryTokenSet antiforgeryTokenSet)
    {
        Debug.Assert(!string.IsNullOrEmpty(antiforgeryTokenSet.CookieToken));
        Debug.Assert(!string.IsNullOrEmpty(antiforgeryTokenSet.RequestToken));

        // Extract cookie & request tokens
        AntiforgeryToken deserializedCookieToken;
        AntiforgeryToken deserializedRequestToken;

        DeserializeTokens(

View on GitHub (pinned to 3600ca084e)