Antiforgery (CSRF) rules
AuthEndpoints adds the EnforceAntiforgeryEndpointFilters endpoint filter through RequireAntiforgery(). The filter validates the request with ASP.NET Core IAntiforgery.
Token
| Item | Value |
|---|---|
| Token routes | GET /identity/csrfToken (cookie sign-in), GET /auth/csrfToken (JWT) |
| Token response | { "csrfToken": "..." } plus the antiforgery cookie |
| Request header | RequestVerificationToken (the ASP.NET Core default) |
| Failure | 400 with the plain-text body Invalid or missing CSRF token. |
MapBearerAuthEndpoints maps no token route.
When the filter skips the check
The filter skips validation when both conditions are true:
- The request is not authenticated by the
Identity.ApplicationorIdentity.Externalcookie. - The request is authenticated by the
Identity.Bearerscheme or the JWT bearer scheme.
An anonymous request is always checked. A request with an application cookie is always checked, even with a bearer token or a ReAuth cookie.
Routes that require a token
| Module | Routes |
|---|---|
| Identity management | POST /resendConfirmationEmail, POST /confirmIdentity, POST /confirmIdentity/passkeyOptions, POST /manage/2fa, POST /manage/info |
| Cookie sign-in | POST /logout |
| Passkeys | POST /passkeys/creationOptions, POST /passkeys/requestOptions, POST /passkeys/register/options, POST /passkeys/register, POST /passkeys/login, POST /passkeys/, PATCH /passkeys/, DELETE /passkeys/{credentialIdUrl} |
| JWT | POST /refresh, POST /logout |
| External OAuth | DELETE /logins/{loginProvider}/{providerKey} |
MapIdentityManagementApi maps the two confirmIdentity routes with requireAntiforgery: true. MapReAuthEndpoints called on its own defaults to requireAntiforgery: false.
Routes without a token check
- Identity management:
POST /register,GET /confirmEmail,POST /forgotPassword,POST /resetPassword, and theGETroutes. - Cookie sign-in:
POST /login. - Identity bearer sign-in:
POST /login,POST /refresh,POST /logout. - Passkeys:
GET /passkeys/. - JWT:
POST /create,GET /verify. - External OAuth: the
loginandlinkroutes and their callbacks. The OAuth correlation and state cookies protect the callbacks.
Middleware
RequireAntiforgery() attaches only the endpoint filter. It does not add ASP.NET Core antiforgery metadata, so UseAntiforgery() does not reject the request before the filter's bearer check runs. AntiforgeryEnforcementMiddleware is optional. It rejects requests that UseAntiforgery() already marked as invalid.