ASP.NET Core: The antiforgery token could not be decrypted / The required antiforgery cookie is not present (400 Bad Request)
Form POST failed antiforgery validation — the token is missing, the cookie is missing, or Data Protection keys changed so old tokens can’t be decrypted.
Seen on:
.NET
Meaning
Load-balanced or containerised apps need shared, persisted Data Protection keys; otherwise each instance/restart creates new keys and tokens from other instances fail. AJAX calls must send the token header.
Common causes
- Data Protection keys not persisted/shared across instances or restarts
- Form missing @Html.AntiForgeryToken / Razor tag helpers
- AJAX request without the RequestVerificationToken header
- Cookie blocked (SameSite/HTTPS)
⚡ Quick fix
- Persist keys (file share, Redis, Azure Blob) and set a common application name
- Include the token in forms and AJAX headers
- Ensure cookies are sent (HTTPS, SameSite)
Detailed fix by platform
C#
- csharp
builder.Services.AddDataProtection() .PersistKeysToFileSystem(new DirectoryInfo("/keys")) .SetApplicationName("myapp");
How to diagnose
- Instances — More than one/restarts?
- Keys — Persisted?
- Request — Token present?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 0x800704EC 0x800704EC: This program is blocked by group policy (Windows Defender)
- 1005 Cloudflare Error 1005: Access denied — The owner of this website has banned the autonomous system number (ASN) your IP address is in
- 1006 Cloudflare Error 1006 / 1007 / 1008: Access denied — Your IP address has been banned
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026