InvalidOperationException: Session has not been configured for this application or request
Code used HttpContext.Session, but session services/middleware aren’t registered — or UseSession runs after the endpoint that needs it.
Seen on:
.NET
Meaning
Sessions require AddDistributedMemoryCache (or another IDistributedCache), AddSession, and app.UseSession() before endpoints/MVC. In multi-instance deployments use a shared cache (Redis/SQL).
Common causes
- AddSession or UseSession missing
- UseSession placed after MapControllers/endpoints
- No IDistributedCache registered
⚡ Quick fix
- Register AddDistributedMemoryCache + AddSession
- Call app.UseSession() before mapping endpoints
- Use Redis/SQL cache when scaled out
Detailed fix by platform
C#
- csharp
builder.Services.AddDistributedMemoryCache(); builder.Services.AddSession(o => o.IdleTimeout = TimeSpan.FromMinutes(30)); var app = builder.Build(); app.UseSession(); app.MapControllers();
How to diagnose
- Registration — Services added?
- Order — Middleware order
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 401 HTTP 401 Unauthorized
- antiforgery token could not be decrypted ASP.NET Core: The antiforgery token could not be decrypted / The required antiforgery cookie is not present (400 Bad Request)
- CORS wildcard with credentials ASP.NET Core: The CORS protocol does not allow specifying a wildcard (any) origin and credentials at the same time
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026