Changelog
Reference

Antiforgery (CSRF) rules

Which AuthEndpoints routes require an antiforgery token, when the check is skipped, and what a failure returns.

AuthEndpoints adds the EnforceAntiforgeryEndpointFilters endpoint filter through RequireAntiforgery(). The filter validates the request with ASP.NET Core IAntiforgery.

Token

ItemValue
Token routesGET /identity/csrfToken (cookie sign-in), GET /auth/csrfToken (JWT)
Token response{ "csrfToken": "..." } plus the antiforgery cookie
Request headerRequestVerificationToken (the ASP.NET Core default)
Failure400 with the plain-text body Invalid or missing CSRF token.

MapBearerAuthEndpoints maps no token route.

When the filter skips the check

The filter skips validation when both conditions are true:

  1. The request is not authenticated by the Identity.Application or Identity.External cookie.
  2. The request is authenticated by the Identity.Bearer scheme or the JWT bearer scheme.

An anonymous request is always checked. A request with an application cookie is always checked, even with a bearer token or a ReAuth cookie.

Routes that require a token

ModuleRoutes
Identity managementPOST /resendConfirmationEmail, POST /confirmIdentity, POST /confirmIdentity/passkeyOptions, POST /manage/2fa, POST /manage/info
Cookie sign-inPOST /logout
PasskeysPOST /passkeys/creationOptions, POST /passkeys/requestOptions, POST /passkeys/register/options, POST /passkeys/register, POST /passkeys/login, POST /passkeys/, PATCH /passkeys/, DELETE /passkeys/{credentialIdUrl}
JWTPOST /refresh, POST /logout
External OAuthDELETE /logins/{loginProvider}/{providerKey}

MapIdentityManagementApi maps the two confirmIdentity routes with requireAntiforgery: true. MapReAuthEndpoints called on its own defaults to requireAntiforgery: false.

Routes without a token check

  • Identity management: POST /register, GET /confirmEmail, POST /forgotPassword, POST /resetPassword, and the GET routes.
  • Cookie sign-in: POST /login.
  • Identity bearer sign-in: POST /login, POST /refresh, POST /logout.
  • Passkeys: GET /passkeys/.
  • JWT: POST /create, GET /verify.
  • External OAuth: the login and link routes and their callbacks. The OAuth correlation and state cookies protect the callbacks.

Middleware

RequireAntiforgery() attaches only the endpoint filter. It does not add ASP.NET Core antiforgery metadata, so UseAntiforgery() does not reject the request before the filter's bearer check runs. AntiforgeryEnforcementMiddleware is optional. It rejects requests that UseAntiforgery() already marked as invalid.