dotnet/aspnetcore · error · AntiforgeryValidationException
The required antiforgery request token was not provided in…
Error message
The required antiforgery request token was not provided in either form field "{0}" or header value "{1}". What it means
Thrown when both lookup channels are configured (HeaderName is set) and the request IS a form request, but neither the form field nor the header contains a request token. This is the fallback 'we looked everywhere and found nothing' message after HasFormContentType is true yet form[FormFieldName] and the header are both empty.
Solutions
- Add the antiforgery hidden field to the form (asp-antiforgery form tag helper or @Html.AntiForgeryToken()) so FormFieldName is populated.
- Or send the token in the configured HeaderName on the client.
- Confirm FormFieldName and HeaderName in AntiforgeryOptions match what the client emits.
- Inspect the actual request body/headers in the browser to confirm which channel the client is using and align it with configuration.
Example fix
// before: form tag helper missing <form method="post"> ... </form> // after: tag helper emits token field <form method="post" asp-antiforgery="true"> ... </form>
Defensive patterns
Strategy: validation
Validate before calling
// Client: confirm at least one channel carries a token before submit.
const hasForm = !!document.querySelector('input[name="__RequestVerificationToken"]')?.value;
const hasHeader = !!headers[configuredHeaderName];
if (!hasForm && !hasHeader) { /* attach a token */ } Try / catch
try { await antiforgery.ValidateRequestAsync(httpContext); }
catch (AntiforgeryValidationException) { return Results.BadRequest(); } Prevention
- Decide on one channel (form or header) per endpoint family and stick to it.
- Audit forms and AJAX calls to ensure the chosen channel always emits the token.
- Lock FormFieldName/HeaderName in shared config and reference it from client code.
When it happens
Trigger: AntiforgeryOptions.HeaderName is non-null, the request has a form content type, GetRequestTokensAsync returned a non-null cookie token, but both the form field (FormFieldName) and the header (HeaderName) are null/empty.
Common situations: Form posts that were built without the antiforgery tag helper while the server also accepts header-based tokens; a partial view that forgot the hidden field; client middleware that strips unknown form fields; FormFieldName renamed on one side only.
Related errors
- The required antiforgery form field
- The required antiforgery cookie
- The required antiforgery header value
- The antiforgery system has the configuration value
- The provided identity of type
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/ead0bdca906c7cad.
Report an issue: GitHub.
Appendix: source
Thrown at src/Antiforgery/src/Internal/DefaultAntiforgery.cs:169
if (tokens.RequestToken == null)
{
if (_options.HeaderName == null)
{
var message = Resources.FormatAntiforgery_FormToken_MustBeProvided(_options.FormFieldName);
throw new AntiforgeryValidationException(message);
}
else if (!httpContext.Request.HasFormContentType)
{
var message = Resources.FormatAntiforgery_HeaderToken_MustBeProvided(_options.HeaderName);
throw new AntiforgeryValidationException(message);
}
else
{
var message = Resources.FormatAntiforgery_RequestToken_MustBeProvided(
_options.FormFieldName,
_options.HeaderName);
throw new AntiforgeryValidationException(message);
}
}
ValidateTokens(httpContext, tokens);
_logger.ValidatedAntiforgeryToken();
}
private void ValidateTokens(HttpContext httpContext, AntiforgeryTokenSet antiforgeryTokenSet)
{
Debug.Assert(!string.IsNullOrEmpty(antiforgeryTokenSet.CookieToken));
Debug.Assert(!string.IsNullOrEmpty(antiforgeryTokenSet.RequestToken));
// Extract cookie & request tokens
AntiforgeryToken deserializedCookieToken;
AntiforgeryToken deserializedRequestToken;
DeserializeTokens(View on GitHub (pinned to 3600ca084e)