antiforgery token could not be decrypted 🟪 .NET

ASP.NET Core: The antiforgery token could not be decrypted / The required antiforgery cookie is not present (400 Bad Request)

Form POST failed antiforgery validation — the token is missing, the cookie is missing, or Data Protection keys changed so old tokens can’t be decrypted.

Seen on: .NET

Meaning

Load-balanced or containerised apps need shared, persisted Data Protection keys; otherwise each instance/restart creates new keys and tokens from other instances fail. AJAX calls must send the token header.

Common causes

  • Data Protection keys not persisted/shared across instances or restarts
  • Form missing @Html.AntiForgeryToken / Razor tag helpers
  • AJAX request without the RequestVerificationToken header
  • Cookie blocked (SameSite/HTTPS)

⚡ Quick fix

  1. Persist keys (file share, Redis, Azure Blob) and set a common application name
  2. Include the token in forms and AJAX headers
  3. Ensure cookies are sent (HTTPS, SameSite)

Detailed fix by platform

C#

  1. csharp
    builder.Services.AddDataProtection()
        .PersistKeysToFileSystem(new DirectoryInfo("/keys"))
        .SetApplicationName("myapp");

How to diagnose

  1. Instances — More than one/restarts?
  2. Keys — Persisted?
  3. Request — Token present?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.